FakeAdBlocker
Malware⚠️ Overview
FakeAdBlocker is a browser extension‑based trojan that masquerades as legitimate ad‑blocking software but functions as a downloader and information stealer. It was first documented in 2021 by Proofpoint’s threat research team, who observed it distributed through malvertising chains and fake software update prompts. The malware is attributed to a financially motivated criminal cluster using a malware‑as‑a‑service model, and it falls under the categories of adware, trojan downloader, and infostealer (MITRE ATT&CK technique T1204.002 – User Execution via Malicious File).
🔧 Technical Capabilities
FakeAdBlocker propagates primarily through malvertising that redirects users to fake ad‑blocker landing pages and through drive‑by downloads from compromised websites. Once installed, the extension abuses Chrome and Edge extension APIs to inject intrusive advertisements, log keystrokes, and exfiltrate browsing history and saved credentials via HTTPS beaconing to command‑and‑control (C2) servers. Persistence is achieved by writing a registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunFakeAdBlocker) and by enrolling the extension for automatic updates that can silently deploy additional payloads. Evasion techniques include obfuscation of JavaScript code using base64 and AES encryption, domain generation algorithms (DGAs) to rotate C2 endpoints, and checks for sandbox environments or debugger presence (MITRE ATT&CK T1497 – Virtualization/Sandbox Evasion). The malware also uses steganography to hide configuration data inside image files retrieved from the C2.
📜 History & Notable Incidents
FakeAdBlocker first appeared in early 2021 and saw a major campaign in March 2022, where it compromised over 500,000 users globally according to a Zscaler ThreatLabz report (July 2022). No high‑profile corporate victims have been publicly named, but the malware has been linked to the distribution of secondary payloads such as the RedLine Stealer and Bumblebee loader. Law enforcement actions have not been reported, though multiple browser vendors have removed the malicious extensions from their stores after vendor notifications.
🔍 Detection Indicators
Known file hashes for the malicious extension CRX packages include MD5: 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d (from a 2022 sample) and SHA‑256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (Kaspersky threat report). Behavioral indicators include illicit modifications to browser homepage settings, injection of
☠️ Risk & Impact
FakeAdBlocker poses significant risk by exfiltrating sensitive personal data, including login credentials, cookies, and financial account numbers, leading to identity theft and account takeover. The ad‑fraud component generates revenue for operators at the expense of user bandwidth and system performance. While no specific industry has been singled out, the malware primarily affects individual consumers and small businesses that rely on free ad‑blocker tools downloaded from unofficial sources.
🛡️ Mitigation
Mitigation strategies include enforcing browser extension allow‑lists through Group Policy, disabling sideloaded extensions, and deploying endpoint detection rules that flag the registry keys and network IOCs listed above. Regular security awareness training should emphasize that legitimate ad‑blockers are only available through official browser stores (Chrome Web Store, Edge Add‑ons) and never via third‑party download sites. No specific CVE is associated with FakeAdBlocker as it exploits extension permissions rather than software vulnerabilities.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.