Adrozek is a malware family and large-scale browser modifier active since at least May 2020. Microsoft reported it infected hundreds of thousands of Windows systems and, at its August 2020 peak, was observed on more than 30,000 devices per day. It targets multiple browsers, including Google Chrome, Microsoft Edge, Mozilla Firefox, and Yandex Browser, modifying browser components and settings to inject unauthorized advertisements into search engine results pages for affiliate fraud.
Adrozek is distributed through drive-by downloads via a large infrastructure that Microsoft tracked across 159 unique domains hosting tens of thousands of URLs and polymorphic installer samples. Victims may be redirected from legitimate sites to malicious domains and tricked into installing boobytrapped software; some reports also note installation via software vulnerabilities. Installer samples drop an executable into the Windows %temp% folder, which installs the main payload into Program Files under names resembling legitimate software such as Audiolava.exe, QuickAudio.exe, and converter.exe.
On infected hosts, Adrozek establishes persistence by registering itself as an installed program and service, and by storing configuration in the registry under HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node<programName>; a service named "Main Service" is specifically mentioned. It force-installs malicious browser extensions by modifying browser AppData and extension paths, adding malicious JavaScript and manifest.json files, and registering the extensions so they load automatically. On Chromium-based browsers it modifies or creates extension folders using legitimate-looking extension IDs; on Firefox it appends a GUID-named folder to the extension path and alters extensions.json.
Adrozek also tampers with browser binaries and preferences to disable protections and preserve its modifications. Reported targets include MsEdge.dll, chrome.dll, browser.dll, and Firefox omni.ja, along with associated preference files. Microsoft reported that on Edge it patches integrity checks protecting Secure Preferences, and on Chrome and Edge it changes Secure Preferences to hide the malicious extension, allow scripting on all URLs, enable incognito execution, and disable Safe Browsing. It also disables browser updates and other security safeguards so modified components are not restored, and can alter the default homepage and search engine.
Its primary observed purpose was ad injection: inserting malicious or unauthorized ads alongside legitimate search ads and monetizing traffic through affiliate advertising and referral programs. On Firefox, Adrozek has an additional credential theft capability. Microsoft reported that it can download an additional executable, collect device information and the active username, locate logins.json, decrypt stored encryptedUsername and encryptedPassword values using PK11SDR_Decrypt(), and upload stolen credentials to attacker-controlled servers.
Observed victim concentrations were highest in Europe, South Asia, and Southeast Asia. Microsoft stated that Windows Defender can detect and block Adrozek and advised affected users to reinstall their browsers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
It stores its configuration parameters at the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\<programName>. The ‘tag’ and ‘did’ entries contain the command-line arguments that it uses to launch the main payload.
If any of these browsers are found on infected hosts, the malware will attempt to force-install an extension by modifying the browser's AppData folders.
The malware is installed like a usual program that can be accessed through Settings>Apps & features, and registered as a service with the same name... To maintain persistence, the malware creates a service named “Main Service”.
The boobytrapped software installs the Androzek malware, which then proceeds to obtain reboot persistence with the help of a registry key.
The Secure Preferences file is similar in structure to the Preferences file except that the former adds hash-based message authentication code (HMAC) for every entry in the file... Adrozek goes one step further and patches the function that launches the integrity check.
Each of these files is heavily obfuscated and uses a unique file name that follows this format: setup_<application name>_<numbers>.exe.
All in all, due to its prolific use of polymorphism to constantly rotate its malware payloads and distribution infrastructure, Microsoft expects the Adrozek operation to grow even more in the coming months.
It stores its configuration parameters at the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\<programName>. The ‘tag’ and ‘did’ entries contain the command-line arguments that it uses to launch the main payload.
The Secure Preferences file is similar in structure to the Preferences file except that the former adds hash-based message authentication code (HMAC) for every entry in the file... Adrozek goes one step further and patches the function that launches the integrity check.
But the real threat is how the malware can also steal login credentials from the Firefox browser, and potentially give hackers a launching pad for more damaging crimes.
On Mozilla Firefox, the said file... stores user credentials in encrypted form... The malware looks for specific keywords like encryptedUsername and encryptedPassword to locate encrypted data. It then decrypts the data using the function PK11SDR_Decrypt() within the Firefox library and sends it to attackers.
The Secure Preferences file is similar in structure to the Preferences file except that the former adds hash-based message authentication code (HMAC) for every entry in the file... Adrozek goes one step further and patches the function that launches the integrity check.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Adrozek is a malware family that modifies browser DLLs and settings to inject unauthorized ads into search results, disable security safeguards and automatic updates, and steal login credentials from Firefox.
Adrozek is a browser-targeting malware strain distributed via drive-by downloads that establishes persistence, modifies browser files and settings, force-installs malicious extensions, disables security protections, changes homepage and search engine settings, injects ads into search results for monetization, and on Firefox can also steal stored credentials.
Adrozek is a browser-modifying malware family distributed via drive-by downloads that injects unauthorized ads into search engine results across Edge, Chrome, Yandex Browser, and Firefox. It modifies browser extensions, patches browser components to disable integrity checks, changes security settings, maintains persistence as a service, and on Firefox also steals and decrypts stored credentials for exfiltration.
Browser malware referenced in the context of abusing browser extensions to modify browser settings and security controls for defense evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.