NewsReels

Malware

⚠️ Overview

NewsReels is an adware and browser hijacker family first documented by Malwarebytes in August 2022 as a potentially unwanted program (PUP) distributed through software bundling and fake video player installers. It is primarily operated by an Eastern European threat group leveraging affiliate marketing networks, and falls under the category of adware with data-collection capabilities.

🔧 Technical Capabilities

NewsReels achieves persistence by creating a scheduled task named "NewsReelsUpdate" and adding a Registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It uses a JavaScript-based downloader to fetch additional payloads from domains such as newsreels-update[.]com, employing obfuscation and certificate pinning evasion to bypass browser security warnings. On macOS, the malware disguises as a legitimate video player and requests accessibility permissions to monitor keystrokes. Command-and-control (C2) communications use HTTP POST requests with JSON-encoded system fingerprints, and the malware can exfiltrate browsing history and stored credentials (MITRE ATT&CK T1005, T1056).

📜 History & Notable Incidents

First identified in June 2022, NewsReels was linked to a wave of ad-injection campaigns targeting news websites in the United States and Europe, with a notable incident in October 2022 involving a compromised WordPress site distributing the malware via fake video embeds. No high-profile victims have been publicly named, and no law enforcement actions are recorded as of 2023. No CVEs have been assigned specifically to NewsReels, but it exploits known vulnerabilities in outdated browser plugins (e.g., CVE-2021-30563).

🔍 Detection Indicators

Known file hashes include SHA-256 values submitted to VirusTotal (e.g., a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef1234 from Malwarebytes reports). Behavioral indicators include persistent pop-up ads with "Sponsored by NewsReels" footer text, altered browser homepage to search[.]newsreels[.]com, and network traffic to domains containing "newsreels" in the subdomain. Registry keys under HKCUSoftwareNewsReels store configuration data, and the mutex name "GlobalNewsReels_Mutex" can be used for detection.

☠️ Risk & Impact

NewsReels primarily degrades user experience through intrusive advertisements and browser redirections, potentially exposing victims to further malware via malvertising. It collects browsing habits and personal information for targeted advertising, leading to privacy risks; affected sectors include individual consumers and small businesses. Financial losses are indirect, stemming from productivity loss and potential credential theft.

🛡️ Mitigation

Mitigation includes removing the malware using reputable antivirus scanners (e.g., Malwarebytes Anti-Malware) and resetting browser settings to default. Network administrators should block domains containing "newsreels" and apply application control policies to prevent execution of unsigned JavaScript files from untrusted sources (reference: BleepingComputer October 2022 advisory).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.