Microsoft Edge’s News Feed ads abused for tech support scams

Gandalf_The_Grey

Level 83
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,223
An ongoing malvertising campaign is injecting ads in the Microsoft Edge News Feed to redirect potential victims to websites pushing tech support scams.

Microsoft Edge is currently the default web browser on computers running the Windows operating system and it currently has a 4.3% market share worldwide, according to Statcounter's Global Stats.

This scam operation has been running for at least two months, according to Malwarebytes' Threat Intelligence Team, who said this is one of the most extensive campaigns at the moment based on the amount of telemetry noise it generates.

This is not surprising considering its scale, with the attackers switching between hundreds of ondigitalocean.app subdomains to host their scam pages within a single day.

The several malicious ads they're injecting into the Edge News Feed timeline are also linked to more than a dozen domains, at least one of them (tissatweb[.]us) also known for hosting a browser locker in the past.

The redirection flow used to send Edge users starts with a check of the targets' web browsers for several settings, such as timezone, to decide if they are worth their time. If not, they'll send them to a decoy page.

To redirect to their scam landing pages, the threat actors use the Taboola ad network to load a Base64 encoded JavaScript script designed to filter the potential victims.

"The goal of this script is to only show the malicious redirection to potential victims, ignoring bots, VPNs and geolocations that are not of interest that are instead shown a harmless page related to the advert," Malwarebytes explained.

"This scheme is meant to trick innocent users with fake browser locker pages, very well known and used by tech support scammers."
 

oldschool

Level 84
Verified
Top Poster
Well-known
Mar 29, 2018
7,595
Users need to treat these news feeds, etc. from Edge or other browsers like Brave the same way we use adblockers. The answer is to disable all these **** 'features'. I gladly trade off convenience for less invasive, distracting and potentially malicious visual clutter. The word! (y)(y):cool:
 

Gandalf_The_Grey

Level 83
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,223
Users need to treat these news feeds, etc. from Edge or other browsers like Brave the same way we use adblockers. The answer is to disable all these **** 'features'. I gladly trade off convenience for less invasive, distracting and potentially malicious visual clutter. The word! (y)(y):cool:
I always do that, less is more (y)
 

Mystic

Level 4
Verified
Aug 25, 2022
141
That is why I prefer Firefox. Just have a look how clean and minimalistic Firefox is when you disable everything you do not need.

Screenshot (3).png
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top