London Daily

Focus on the big picture.
Wednesday, Jan 14, 2026

Microsoft Warns 'Adrozek' Malware is Infecting Thousands of PCs to Insert Ads

Microsoft Warns 'Adrozek' Malware is Infecting Thousands of PCs to Insert Ads

'We recorded hundreds of thousands of encounters of the Adrozek malware across the globe, with heavy concentration in Europe and in South Asia and Southeast Asia,' Microsoft said.

A new malware strain has been spreading to hundreds of thousands of Windows PCs in an effort to inject unauthorized ads into users’ search results, according to Microsoft.

The company has been tracking "Adrozek," a malware family capable of modifying multiple browsers including Google’s Chrome, Microsoft’s Edge and Mozilla’s Firefox in order to insert the ads into search result pages.

“At its peak in August, the threat was observed on over 30,000 devices every day,” Microsoft warned in a blog post on Thursday.

Inserting the ads into your search results is certainly annoying. But the real threat is how the malware can also steal login credentials from the Firefox browser, and potentially give hackers a launching pad for more damaging crimes.

Adrozek works by modifying a browser’s Dynamic Link Libraries or DLL files to change the settings, including turning off the security safeguards and the automatic updates. The result can place links to ads alongside legitimate ads, as the example below shows.



“The intended effect is for users, searching for certain keywords, to inadvertently click on these malware-inserted ads, which lead to affiliated pages,” Microsoft said. “The attackers earn through affiliate advertising programs, which pay by amount of traffic referred to sponsored affiliated pages.”

To deliver the malware, the hackers have been resorting to drive-by downloads. This can occur when a user clicks on a malicious link or visits a website that’s been tampered with. The PC will trigger the malware to download, which can sometimes install itself on the computer by exploiting a software vulnerability.

Hence, it’s a good idea to always keep your browser up to date. In other cases, the user will install the malware from a drive-by download, believing it to be a safe program.



In this case, Adrozek will drop an .exe file in the PC’s “temp” folder. The .exe file will then deliver the main malware payload in the “Programs Files” folder using a file name such as “Audiolava.exe, QuickAudio.exe, and converter.exe,” Microsoft said.

The company tracked Adrozek’s distribution to 159 unique domains, which hosted tens of thousands of URLs to try and spread the malware.

“In total, from May to September 2020, we recorded hundreds of thousands of encounters of the Adrozek malware across the globe, with heavy concentration in Europe and in South Asia and Southeast Asia,” Microsoft added. “As this campaign is ongoing, this infrastructure is bound to expand even further.



Although the malware is so far aimed at inserting unauthorized ads, Microsoft is concerned Adrozek could one day be used for more malicious crimes, such as redirecting users to scam websites. The good news is that the company’s built-in Windows Defender antivirus can detect and block Adrozek.

“End users who find this threat on their devices are advised to re-install their browsers,” the company added.


Newsletter

Related Articles

0:00
0:00
Close
UK Intensifies Arctic Security Engagement as Trump’s Greenland Rhetoric Fuels Allied Concern
Meghan Markle Could Return to the UK for the First Time in Nearly Four Years If Security Is Secured
Meghan Markle Likely to Return to UK Only if Harry Secures Official Security Cover
UAE Restricts Funding for Emiratis to Study in UK Amid Fears Over Muslim Brotherhood Influence
EU Seeks ‘Farage Clause’ in Brexit Reset Talks to Safeguard Long-Term Agreement Stability
Starmer’s Push to Rally Support for Action Against Elon Musk’s X Faces Setback as Canada Shuns Ban
UK Free School Meals Expansion Faces Political and Budgetary Delays
EU Seeks ‘Farage Clause’ in Brexit Reset Talks With Britain
Germany Hit by Major Airport Strikes Disrupting European Travel
Prince Harry Seeks King Charles’ Support to Open Invictus Games on UK Return
Washington Holds Back as Britain and France Signal Willingness to Deploy Troops in Postwar Ukraine
Elon Musk Accuses UK Government of Suppressing Free Speech as X Faces Potential Ban Over AI-Generated Content
Russia Deploys Hypersonic Missile in Strike on Ukraine
OpenAI and SoftBank Commit One Billion Dollars to Energy and Data Centre Supplier
UK Prime Minister Starmer Reaffirms Support for Danish Sovereignty Over Greenland Amid U.S. Pressure
UK Support Bolsters U.S. Seizure of Russian-Flagged Tanker Marinera in Atlantic Strike on Sanctions Evasion
The Claim That Maduro’s Capture and Trial Violate International Law Is Either Legally Illiterate—or Deliberately Deceptive
UK Data Watchdog Probes Elon Musk’s X Over AI-Generated Grok Images Amid Surge in Non-Consensual Outputs
Prince Harry to Return to UK for Court Hearing Without Plans to Meet King Charles III
UK Confirms Support for US Seizure of Russian-Flagged Oil Tanker in North Atlantic
Béla Tarr, Visionary Hungarian Filmmaker, Dies at Seventy After Long Illness
UK and France Pledge Military Hubs Across Ukraine in Post-Ceasefire Security Plan
Prince Harry Poised to Regain UK Security Cover, Clearing Way for Family Visits
UK Junk Food Advertising Ban Faces Major Loophole Allowing Brand-Only Promotions
Maduro’s Arrest Without The Hague Tests International Law—and Trump’s Willingness to Break It
German Intelligence Secretly Intercepted Obama’s Air Force One Communications
The U.S. State Department’s account in Persian: “President Trump is a man of action. If you didn’t know it until now, now you do—do not play games with President Trump.”
Fake Mainstream Media Double Standard: Elon Musk Versus Mamdani
HSBC Leads 2026 Mortgage Rate Cuts as UK Lending Costs Ease
US Joint Chiefs Chairman Outlines How Operation Absolute Resolve Was Carried Out in Venezuela
Starmer Welcomes End of Maduro Era While Stressing International Law and UK Non-Involvement
Korean Beauty Turns Viral Skincare Into a Global Export Engine
UK Confirms Non-Involvement in U.S. Military Action Against Venezuela
UK Terror Watchdog Calls for Australian-Style Social Media Ban to Protect Teenagers
Iranian Protests Intensify as Another Revolutionary Guard Member Is Killed and Khamenei Blames the West
Delta Force Identified as Unit Behind U.S. Operation That Captured Venezuela’s President
Europe’s Luxury Sanctions Punish Russian Consumers While a Sanctions-Circumvention Industry Thrives
Berkshire’s Buffett-to-Abel Transition Tests Whether a One-Man Trust Model Can Survive as a System
Fraud in European Central Bank: Lagarde’s Hidden Pay Premium Exposes a Transparency Crisis at the European Central Bank
Trump Announces U.S. Large-Scale Strike on Venezuela, Declares President Maduro and Wife Captured
Tesla Loses EV Crown to China’s BYD After Annual Deliveries Decline in 2025
UK Manufacturing Growth Reaches 15-Month Peak as Output and Orders Improve in December
Beijing Threatened to Scrap UK–China Trade Talks After British Minister’s Taiwan Visit
Newly Released Files Reveal Tony Blair Pressured Officials Over Iraq Death Case Involving UK Soldiers
Top Stocks and Themes to Watch in 2026 as Markets Enter New Year with Fresh Momentum
No UK Curfew Ordered as Deepfake TikTok Falsely Attributes Decree to Prime Minister Starmer
Europe’s Largest Defence Groups Set to Return Nearly Five Billion Dollars to Shareholders in Twenty Twenty-Five
Abu Dhabi ‘Capital of Capital’: How Abu Dhabi Rose as a Sovereign Wealth Power
Diamonds Are Powering a New Quantum Revolution
Trump Threatens Strikes Against Iran if Nuclear Programme Is Restarted
×