Microsoft: “Adrozek” malware campaign is distributing an ad-injecting browser modifier which changes security settings; Chrome, Firefox, Edge, Yandex at risk
what to do now Luke Jones / WinBuzzer : Microsoft Edge, Chrome, and Firefox Being Hit By “Adrozek” Attacks Usama Jawad / Neowin : Microsoft issues warning about malware campaign infecting Chrome, Edge, and Firefox Joel Khalili / TechRadar : Microsoft warns of nasty malware campaign targeting almost all major browsers Catalin Cimpanu / ZDNet : Microsoft exposes Adrozek, malware that hijacks Chrome, Edge, and Firefox Zeljka Zorz / Help Net Security : Ad-injecting malware hijacks Chrome, Edge, Firefox Tweets: @sonicwall : A new #malware strain, #Adrozek, that infects a user's device and modifies its browsers and settings has been exposed by @Microsoft. Europe, followed by South and Southeast Asia is expected to have the most victims from this #cyberattack. via @ZDNet https://www.zdnet.com/... Sbrc / @sbrc_scotland : Beware of the browser hijacking and credential-stealing malware Adrozak campaign. More details below 🔽 https://twitter.com/... @katebevan : Ugh, this is nasty. I also note that it steals logins from Firefox, which is why I always say it's better to use a password manager rather than let your browser store your passwords: malware can and does target and exfiltrate user details from browsers https://arstechnica.com/... Stephen Shankland / @stshank : Pretty fancy malware takes a lot of actions to hide from browsers it exploits. The payoff: “to allow Adrozek to inject ads into search results pages, ads that allow the malware gang to gain revenue by directing traffic towards ad and traffic referral programs” from @campuscodi https://twitter.com/... Ian Barwise / @z3r0trust : “Adrozek, as the software maker has dubbed the malware family, relies on a sprawling distribution network comprising 159 unique domains with each one hosting an average of 17,300 unique URLs.” 4 major browsers are getting hit in widespread malware attacks https://arstechnica.com/... @msftsecintel : New blog post: Attackers have been actively distributing Adrozek, an evolved browser modifier, at scale. At its peak, the threat was observed on >30K devices every day. The malware injects ads into search results pages and affects multiple browsers. https://www.microsoft.com/... Kevin Beaumont / @gossithedog : This is a fun one - it also does automated credential theft. https://www.microsoft.com/...
Context & Ripple Effects
Adrozek lands a few months after researchers exposed [[a:956542|295 Chrome extensions with more than 80M users quietly inserting ads into Google and Bing results]] — proof that search-page ad injection scales when it hides inside trusted software. Microsoft's disclosure escalates the same playbook one layer down: instead of an extension, Adrozek modifies the browsers themselves across Chrome, Firefox, Edge, and Yandex, changing security settings while it injects ads.
The campaign also revives an old Microsoft position. Back in 2015 the company committed to detecting and removing man-in-the-middle adware like Superfish, confining legitimate adware to browser plugins — yet here its own Edge is among the hijacked targets, alongside the credential theft that distinguishes Adrozek from pure ad fraud.
First-order effects
- Users — concentrated in Europe, then South and Southeast Asia per Microsoft's telemetry — have their browsers silently altered to serve injected search ads while stored credentials are exfiltrated, peaking above 30,000 infected devices per day across 159 distribution domains.
Second-order effects
- Google, Microsoft, and Yandex face polluted ad inventory on their own search results pages, forcing detection and takedown work even though the infection sits below the browser layer their extension policies govern.
- Advertisers end up paying for impressions served by hijacked sessions, pushing ad-verification firms like Confiant — which tracked comparable malicious-ad volume through a Webkit bug redirecting over a billion malicious ads — to extend monitoring from ad creative to browser integrity.
Third-order effects
- If ad injection keeps migrating from extensions to full browser modification, platform vendors will tighten toward locked-down, vendor-signed browser configurations — completing the trajectory Microsoft set in 2015 when it restricted adware to plugins and began removing MITM techniques outright.
- Credential theft bundled with ad fraud blurs the line between adware and info-stealer operations, arguing for regulators and security vendors to treat browser-integrity compromise as a data-breach event rather than a nuisance-ad problem.
The trend: Search-result ad fraud is industrializing beyond extensions into direct browser modification, dragging credential theft along with it and forcing browser vendors to treat the client itself as the attack surface.