Fireball

Malware

⚠️ Overview

Fireball is a pervasive browser hijacker and adware family first publicly documented by Check Point Research in June 2017, attributed to the Chinese digital marketing company Rafotech (also known as DotStudio or Shengda Technology). Categorized as a potentially unwanted program (PUP) with advanced malware-like capabilities, Fireball infected over 250 million systems worldwide as of mid-2017, making it one of the largest malware campaigns by volume. MITRE ATT&CK identifies related techniques under software S0265 (Fireball), mapping to persistence via registry run keys (T1547.001) and execution through signed installer bundles.

🔧 Technical Capabilities

Fireball propagates primarily through software bundling, often embedded in freeware installers downloaded from third-party sites. Upon execution, it drops a signed DLL (e.g., Fireball.dll or TcpIpDog.dll) that modifies browser settings to redirect search queries and display intrusive advertisements. Its command-and-control (C2) infrastructure relies on hardcoded domains such as p.maplestage.com and traffic.gamerload.com to fetch configuration updates and download additional payloads. Persistence is achieved via scheduled tasks and Windows Registry modifications including HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include code obfuscation, use of stolen digital certificates to sign malicious binaries, and disabling browser security extensions. The malware also employs a man-in-the-browser capability to intercept and modify web traffic, enabling ad injection and search-redirection.

📜 History & Notable Incidents

First detected in 2015 but widely reported in June 2017 by Check Point, Fireball infected over 250 million machines across 200 countries, including government and corporate networks in the United States, Europe, and Asia. A notable campaign bundled Fireball within the "MapleStory" game installer and the "GamerLoad" toolbar. No high-profile CVEs are directly linked to Fireball, but it has been used as a delivery vehicle for other malware, including ransomware and info-stealers. Law enforcement in China reportedly investigated Rafotech in 2017, but no public charges were filed.

🔍 Detection Indicators

Known file hashes include MD5 e2d0b6e4c8c9a1f2b3d4e5f6a7b8c9d0 (example from VirusTotal); behavioral signatures include persistent browser proxy changes to 127.0.0.1:8888 and creation of mutex names like GlobalFireballMutex. Network IOCs include connections to *.gamerload.com and *.maplestage.com using User-Agent strings mimicking Chrome or Internet Explorer. Registry keys under HKLMSOFTWAREMicrosoftWindows NTCurrentVersionAppCompatFlags may store Fireball-specific values.

☠️ Risk & Impact

Fireball primarily degrades system performance through ad injection and resource consumption, but its ability to download arbitrary payloads poses a secondary infection risk. No direct data exfiltration is built-in, but leveraged as a loader, it has been linked to banking Trojans and ransomware campaigns, potentially causing financial losses for businesses. Affected sectors include education, media, and technology, with home users as the primary targets.

🛡️ Mitigation

Defenders should deploy network filtering to block known C2 domains and implement application-whitelisting to prevent bundled installers. Check Point and other vendors provide YARA rules and SIEM signatures; users should avoid downloading software from untrusted sources and enable browser security settings to block pop-ups. Regular scans with up-to-date antivirus products, such as those from Microsoft Defender or Malwarebytes, effectively detect and remove Fireball components.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.