{"id":15570,"date":"2019-06-13T11:10:12","date_gmt":"2019-06-13T19:10:12","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/06\/13\/news-9319\/"},"modified":"2019-06-13T11:10:12","modified_gmt":"2019-06-13T19:10:12","slug":"news-9319","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/06\/13\/news-9319\/","title":{"rendered":"Adware and PUPs families add push notifications as an attack vector"},"content":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Thu, 13 Jun 2019 18:36:14 +0000<\/strong><\/p>\n<p>Some existing families of potentially unwanted programs and adware have added browser push notifications to their weapons arsenal. Offering themselves up as browser extensions on Chrome and Firefox, these threats pose as useful plugins then haggle users with notifications.<\/p>\n<h3>A family of search hijackers<\/h3>\n<p>The first I would like to discuss is a large family of Chrome extensions that were already active as search hijackers, but have now added a notifications service from a provider hailing from a domain blocked for fraud by Malwarebytes. What that means is you can now expect browser notifications inviting you to come gamble at an online casino or advertisements selling you get-rich schemes that use pictures of celebrities to gain your trust.<\/p>\n<p>This family is detected under the <a rel=\"noreferrer noopener\" aria-label=\"PUP.Optional (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/detections\/pup-optional\/\" target=\"_blank\">PUP.Optional<\/a> umbrella, meaning that Malwarebytes flags them for misconduct but recognizes they offer some kind of functionality and are upfront about the fact that they will change your search settings. The third part of Malwarebytes\u2019 detection name usually refers to the name of the extension. So this one is called <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"http:\/\/forums.malwarebytes.com\/topic\/241530-removal-instructions-for-stream-all\/\" target=\"_blank\">PUP.Optional.StreamAll<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"39046\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/stream-all_permissions\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_permissions.png\" data-orig-size=\"450,242\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"stream-all_permissions\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_permissions-300x161.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_permissions.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_permissions.png\" alt=\"permissions for the StreamAll extension\" class=\"wp-image-39046\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_permissions.png 450w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_permissions-300x161.png 300w\" sizes=\"(max-width: 450px) 100vw, 450px\" \/><\/figure>\n<\/div>\n<p>The extensions in this family are search hijackers\u2014they redirect users to Yahoo! search results when searching from the address bar. The websites behind all the extensions in this family are presented in three different styles that are completely interchangeable:<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39047\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/website1-4\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website1.png\" data-orig-size=\"761,504\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"website1\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website1-300x199.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website1-600x397.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website1-600x397.png\" alt=\"version 1\" class=\"wp-image-39047\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website1-600x397.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website1-300x199.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website1.png 761w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<p>Version 1 is a basic design kindly guiding you through the steps of installing the Chrome extension.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39048\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/website2-2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website2.png\" data-orig-size=\"909,681\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"website2\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website2-300x225.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website2-600x450.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website2-600x450.png\" alt=\"version 2\" class=\"wp-image-39048\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website2-600x450.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website2-300x225.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website2.png 909w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<p>Version 2 shows a circle that fills with color until it reaches 100 percent and then tells you it is ready to install the extension.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39049\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/website3-2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website3.png\" data-orig-size=\"739,467\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"website3\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website3-300x190.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website3-600x379.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website3-600x379.png\" alt=\"version 3\" class=\"wp-image-39049\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website3-600x379.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website3-300x190.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/website3.png 739w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<p>Version 3 is a bit more \u201cin your face\u201d and lets you know you really shouldn\u2019t miss out on this extension. It does come in a few slightly different color schemes.<\/p>\n<p>The three websites posted above all lead to StreamAll, the same Chrome extension that I have used as an example for this family. In fact, they all redirect to this extension in Chrome&#8217;s web store at some point:<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39050\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/webstore-4\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/webstore.png\" data-orig-size=\"668,296\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"webstore\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/webstore-300x133.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/webstore-600x266.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/webstore-600x266.png\" alt=\"streamall in webstore\" class=\"wp-image-39050\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/webstore-600x266.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/webstore-300x133.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/webstore-195x85.png 195w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/webstore.png 668w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><figcaption><em>A stunning lot of users, which never ceases to amaze me.<\/em> <\/figcaption><\/figure>\n<p>Another thing the members of this family have in common is a &#8220;thank you&#8221; screen after installing one of their extensions, already busy pushing promotional deals. This one has a blue background but can also be fully white.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39057\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/stream-all_thanks\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_thanks.png\" data-orig-size=\"583,332\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"stream-all_thanks\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_thanks-300x171.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_thanks.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_thanks.png\" alt=\"Thank you page\" class=\"wp-image-39057\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_thanks.png 583w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/stream-all_thanks-300x171.png 300w\" sizes=\"(max-width: 583px) 100vw, 583px\" \/><\/figure>\n<p>Their offer to receive notifications is made as soon as you reach one of their sites:<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39051\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/notifications-3\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/notifications.png\" data-orig-size=\"322,132\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"notifications\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/notifications-300x123.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/notifications.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/notifications.png\" alt=\"\" class=\"wp-image-39051\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/notifications.png 322w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/notifications-300x123.png 300w\" sizes=\"(max-width: 322px) 100vw, 322px\" \/><\/figure>\n<p>These prompts have also been added to member sites of this family that didn&#8217;t promote push notifications earlier on.<\/p>\n<p>If you accept this offer you can find the resulting permission in the <strong>Settings<\/strong> menu &gt; click on <strong>Advanced<\/strong> &gt; under <strong>Privacy and Security<\/strong> &gt; select <strong>Site settings<\/strong> &gt; select <strong>Notifications<\/strong>.<\/p>\n<p>The number of extensions in this family is rather large, but here is a list of removal guides I created for the most active ones at the moment of writing:<\/p>\n<ul>\n<li><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/forums.malwarebytes.com\/topic\/247637-removal-instructions-for-get-live-news\/\" target=\"_blank\">https:\/\/forums.malwarebytes.com\/topic\/247637-removal-instructions-for-get-live-news\/<\/a><\/li>\n<li><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/forums.malwarebytes.com\/topic\/247223-removal-instructions-for-giph-it\/\" target=\"_blank\">https:\/\/forums.malwarebytes.com\/topic\/247223-removal-instructions-for-giph-it\/<\/a><\/li>\n<li><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/forums.malwarebytes.com\/topic\/214129-removal-instructions-for-speedomizer\/\" target=\"_blank\">https:\/\/forums.malwarebytes.com\/topic\/214129-removal-instructions-for-speedomizer\/<\/a><\/li>\n<li><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/forums.malwarebytes.com\/topic\/240233-removal-instructions-for-convertowiz\/\" target=\"_blank\">https:\/\/forums.malwarebytes.com\/topic\/240233-removal-instructions-for-convertowiz\/<\/a><\/li>\n<li><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/forums.malwarebytes.com\/topic\/244958-removal-instructions-for-movie-goat-default-search\/\" target=\"_blank\">https:\/\/forums.malwarebytes.com\/topic\/244958-removal-instructions-for-movie-goat-default-search\/<\/a><\/li>\n<li><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/forums.malwarebytes.com\/topic\/240624-removal-instructions-for-streaming-time\/\" target=\"_blank\">https:\/\/forums.malwarebytes.com\/topic\/240624-removal-instructions-for-streaming-time\/<\/a><\/li>\n<li><a href=\"https:\/\/forums.malwarebytes.com\/topic\/245234-removal-instructions-for-sd-app\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">https:\/\/forums.malwarebytes.com\/topic\/245234-removal-instructions-for-sd-app\/<\/a><\/li>\n<\/ul>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" data-attachment-id=\"39052\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/popular\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/popular.png\" data-orig-size=\"199,202\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"popular\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/popular.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/popular.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/popular.png\" alt=\"open tabs\" class=\"wp-image-39052\"\/><\/figure>\n<\/div>\n<p>By active I mean they are being heavily promoted by some of the popular <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/ad-rotator\/\">ad-rotators<\/a>. To achieve this, they are probably paying a pretty penny and you can be sure they want to make good on that\u2014at your expense.<\/p>\n<h3>A Facebook spammer<\/h3>\n<p>The second threat family I want to discuss is into far more serious business. This family of Firefox extensions is detected by Malwarebytes as <a rel=\"noreferrer noopener\" aria-label=\"Trojan.FBSpammer (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/detections\/trojan-fbspammer\/\" target=\"_blank\">Trojan.FBSpammer<\/a>.<\/p>\n<p>These extensions can be found at sites that try to convince users they need a Flash player update.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39053\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/flashupdate\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FlashUpdate.png\" data-orig-size=\"800,447\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"FlashUpdate\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FlashUpdate-300x168.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FlashUpdate-600x335.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FlashUpdate-600x335.png\" alt=\"notications and flash update\" class=\"wp-image-39053\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FlashUpdate-600x335.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FlashUpdate-300x168.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FlashUpdate.png 800w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><figcaption>Prompts and links everywhere. What to do first?<\/figcaption><\/figure>\n<p>They also ask for permission to send you notifications and\u2014just like StreamAll\u2014they use a provider that is blocked by Malwarebytes for fraud. But in this case, annoying push notifications are the least of users&#8217; worries. As our <a rel=\"noreferrer noopener\" aria-label=\"friends at BleepingComputer (opens in a new tab)\" href=\"https:\/\/twitter.com\/BleepinComputer\/status\/1134227276101554176\" target=\"_blank\">friends at BleepingComputer<\/a> figured out, this extension checks users&#8217; Facebook connection and, if the user is logged in, the extension will join some Facebook groups on their behalf and start spamming them.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39054\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/facebookcheck\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/Facebookcheck.png\" data-orig-size=\"738,97\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Facebookcheck\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/Facebookcheck-300x39.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/Facebookcheck-600x79.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/Facebookcheck-600x79.png\" alt=\"\" class=\"wp-image-39054\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/Facebookcheck-600x79.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/Facebookcheck-300x39.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/Facebookcheck.png 738w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><figcaption>  The extension performs a check to see whether the user is connected to Facebook every two seconds. <\/figcaption><\/figure>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39055\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/facebookjoingroup\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FacebookJoinGroup.png\" data-orig-size=\"952,236\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"FacebookJoinGroup\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FacebookJoinGroup-300x74.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FacebookJoinGroup-600x149.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FacebookJoinGroup-600x149.png\" alt=\"\" class=\"wp-image-39055\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FacebookJoinGroup-600x149.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FacebookJoinGroup-300x74.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/FacebookJoinGroup.png 952w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><figcaption>The extension adds users to some Facebook groups if they are logged in.<\/figcaption><\/figure>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"39056\" data-permalink=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/attachment\/facebookpostcampaign\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/facebookpostcampaign.png\" data-orig-size=\"1075,561\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"facebookpostcampaign\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/facebookpostcampaign-300x157.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/facebookpostcampaign-600x313.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/facebookpostcampaign-600x313.png\" alt=\"\" class=\"wp-image-39056\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/facebookpostcampaign-600x313.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/facebookpostcampaign-300x157.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/facebookpostcampaign-630x330.png 630w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/facebookpostcampaign.png 1075w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><figcaption>Then it fetches a campaign and starts spamming those groups in the user&#8217;s name.<\/figcaption><\/figure>\n<h3>Lesson learned<\/h3>\n<p>While browser push notifications can be annoying, they are easy to resolve, as I explained in detail in my blog <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/security-world\/technology\/2019\/01\/browser-push-notifications-feature-asking-abused\/\" target=\"_blank\">Browser push notifications: a feature asking to be abused<\/a>. But we have seen from the examples above that there are worse things. <\/p>\n<p>Choose carefully which extensions you decide to install, as well as which programs you allow to send push notifications. The extensions in these cases are up to no good\u2014especially the Trojan that will give your Facebook reputation a quick shove into the cellar. And if you have trouble determining which extensions are benign and which are taking advantage of users, you can always count on Malwarebytes to point you in the right direction.<\/p>\n<p>Stay safe, everyone!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/\">Adware and PUPs families add push notifications as an attack vector<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Thu, 13 Jun 2019 18:36:14 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/' title='Adware and PUPs families add push notifications as an attack vector'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/06\/double_headed_dragon.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Push notifications are being added to the arsenal of PUPs, adware, and even a Trojan browser extension that spams Facebook groups.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/adware\/\" rel=\"category tag\">Adware<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/adware\/\" rel=\"tag\">adware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/browser-extensions\/\" rel=\"tag\">browser extensions<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/extensions\/\" rel=\"tag\">extensions<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/facebook\/\" rel=\"tag\">facebook<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/facebook-spammer\/\" rel=\"tag\">Facebook spammer<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fbspammer\/\" rel=\"tag\">fbspammer<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/notifications\/\" rel=\"tag\">notifications<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/plugin\/\" rel=\"tag\">plugin<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/plugins\/\" rel=\"tag\">plugins<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/pup\/\" rel=\"tag\">PUP<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/pups\/\" rel=\"tag\">PUPs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/push-notifications\/\" rel=\"tag\">push notifications<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/search-hijackers\/\" rel=\"tag\">search hijackers<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/trojan\/\" rel=\"tag\">trojan<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/trojans\/\" rel=\"tag\">Trojans<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/' title='Adware and PUPs families add push notifications as an attack vector'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/adware\/2019\/06\/adware-and-pups-families-add-push-notifications-as-an-attack-vector\/\">Adware and PUPs families add push notifications as an attack vector<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10468,19414,11058,3589,22039,22040,12351,11536,17346,10566,2130,20991,22041,10833,12269],"class_list":["post-15570","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-adware","tag-browser-extensions","tag-extensions","tag-facebook","tag-facebook-spammer","tag-fbspammer","tag-notifications","tag-plugin","tag-plugins","tag-pup","tag-pups","tag-push-notifications","tag-search-hijackers","tag-trojan","tag-trojans"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15570"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15570\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15570"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15570"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}