惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
Hugging Face - Blog
Hugging Face - Blog
M
MIT News - Artificial intelligence
T
Tailwind CSS Blog
Webroot Blog
Webroot Blog
S
Secure Thoughts
N
News and Events Feed by Topic
月光博客
月光博客
TaoSecurity Blog
TaoSecurity Blog
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
N
News | PayPal Newsroom
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
小众软件
小众软件
Recent Commits to openclaw:main
Recent Commits to openclaw:main
P
Privacy & Cybersecurity Law Blog
GbyAI
GbyAI
K
Kaspersky official blog
WordPress大学
WordPress大学
P
Proofpoint News Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
博客园 - 叶小钗
W
WeLiveSecurity
Jina AI
Jina AI
The Cloudflare Blog
Project Zero
Project Zero
Simon Willison's Weblog
Simon Willison's Weblog
V
Vulnerabilities – Threatpost
L
LangChain Blog
Forbes - Security
Forbes - Security
PCI Perspectives
PCI Perspectives
Engineering at Meta
Engineering at Meta
Google DeepMind News
Google DeepMind News
Recorded Future
Recorded Future
博客园 - 【当耐特】
H
Heimdal Security Blog
A
About on SuperTechFans
Cisco Talos Blog
Cisco Talos Blog
T
Threat Research - Cisco Blogs
云风的 BLOG
云风的 BLOG
Spread Privacy
Spread Privacy
L
LINUX DO - 最新话题
L
Lohrmann on Cybersecurity
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
I
Intezer
Martin Fowler
Martin Fowler
S
Securelist
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint

Heimdal Security Blog

The 4 best managed EDR service suppliers (and how to choose) How to choose the best SOC platform in 2026 (and our top 4) Top 6 Managed Detection and Response Providers Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors How to scale your patches without scaling your team (the patch wave) AI didn't break patching. It showed us patching was already broken. Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes How Dynamic Defense shuts an attacker out without shutting down the business Static security has run out of road. The case for Dynamic Defense Breaking the MSP Echo Chamber: The Power of Community How attackers built a RAT on a Windows machine using its own .NET compiler Attacker enables RDP, creates admin, erases evidence in ten seconds Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It Your Next Insider Threat May Be an AI Coworker The OSI Model and Its Two Missing Layers Heimdal® Marks Six Years of Consecutive ISAE 3000 SOC 2 Type II Certification The State of AI Risk Management in 2026 AI Will Absorb 99.98% of SOC Triage Within a Year, as 79% of IT teams brace for AI-driven workload shift Top 10 Cybersecurity Companies in Europe Heimdal Expands AI Strategy with AI Wingman and Third-Party AI Containment You Only Know What You’ve Got When Its Gone Nordic MSPs Can Now Access Heimdal’s Unified Security and Compliance Platform Through Elovade OpenClaw Incidents Show Why AI Adoption Pressure Puts Companies at Risk Heimdal Claims Industry First With a Cyber Essentials Control Mapping for PEDM to Help Organisations Prove Least Privilege Five Predictions for Cyber Security Trends in 2026 Heimdal Achieves OPSWAT Gold Certification for Anti-Malware How to Avoid Holiday Shopping Scams (From a Former Cyber Detective) ITDR Best Practices: How to Detect, Prevent, and Contain Critical Identity Threats When Buyers Discount MSPs With One Big Customer You’re Not Technical? That Excuse Just Expired! Tool Sprawl Taxes Your Business More Than You Think Heimdal 5.1.0 RC Dashboard: Smarter Automation, Stronger Compliance, and Smoother Control Can Generative AI Be Weaponized for Cyberattacks? Digital Warfare and the New Geopolitical Frontline Nearly 40% of 2024 Ransomware Payouts May Have Gone to Russia, China & North Korea
MediaArena malvertising: why a quarantine isn't the end of the incident
Alexandru Gurgu · 2026-07-17 · via Heimdal Security Blog

If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win.

Our SOC data says treat it as a live persistence incident instead.

In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didn’t complete until 29 seconds. By the time the alert fired, the persistence was already on disk.

We’ve seen this same adware cluster across more than 20 client environments in recent days. It’s the malvertising campaign that hides behind free “AI tool” lures, and it’s already been documented.

Compass Apex Security wrote it up in April, and the indicators have sat in public sandboxes since March. We’re adding what our own SOC can see. How fast it establishes persistence, and how widely.

 A sample of affected hosts. The same detection landed across more than 20 client environments in days. Hostnames and paths redacted.

A sample of affected hosts. The same detection landed across more than 20 client environments in days. Hostnames and paths redacted.

Microsoft classifies MediaArena as a browser-modifier potentially unwanted application and has tracked it in its threat encyclopedia since 2023. It reconfigures browser settings, hijacks search, and harvests queries to sell on. It’s a nuisance, not a nation-state loader.

That’s the point.

Even a low-severity detection can leave persistence behind, so a closed alert and a clean endpoint aren’t the same thing.

The delivery is a fake free-app lure, currently themed as recipe and meal-planning tools, served through paid search ads.

The brand names rotate, and the domains rotate with them, so any single indicator has a short shelf life. That’s why detection built on brand strings ages out fast, and why the behaviour and the persistence artefacts are the signals worth hunting on.

Paid search result for kitchen-canvas.com, a fake free AI recipe app for Windows used as a malvertising lure.

The lure surfaces through paid search.

GiveMeRecipe landing page, a fake free AI recipe app for Windows delivering MediaArena adware.

KitchenCanvas landing page, a fake free AI recipe app fronting the same MediaArena malvertising campaign.

FoodFormula app interface, another rotating lure brand distributing the MediaArena browser hijacker.

Three of the rotating lure brands, GiveMeRecipe, KitchenCanvas, and FoodFormula, all fronting the same math.dll toolkit.

What actually happens on the endpoint

The installer needs no admin rights. In our confirmed case it wrote to AppData, dropped a Start Menu shortcut, added an HKCU Uninstall key to pass as a legitimate app, and left a Startup folder shortcut for boot persistence.

All of it landed before quarantine completed. Signature detection took roughly 78 days to catch up. That’s a long window for a browser hijacker to sit and run.

Heimdal Next-Gen Antivirus flagging fake recipe-app installers as BrowserModifier:Win32/MediaArena on an infected host, details redacted.

Our console. The branded installers flagged as BrowserModifier:Win32/MediaArena on an affected host. Hostname and username redacted.

The alert told us the file was caught. It didn’t tell us nothing had run first, and on these detections something always had. That’s why I treat a quarantine on this family as the start of the investigation, not the end of it.

What to hunt for after a MediaArena hit

Don’t close the alert on quarantine alone. Check the affected host for:

  • A Startup folder shortcut tied to the app name.
  • An HKCU Uninstall registry key mimicking a legitimate install.

Note the loader, math.dll, is injected in memory rather than dropped to disk, so hunt the persistence artefacts above rather than the file itself.

If either artefact is present, treat the host as still compromised and remediate the persistence directly.

Indicators

Credit to Compass Apex Security and public sandbox reporting for the campaign work. Indicators confirmed live at the time of writing. The infrastructure rotates, so revalidate before acting.

  • Lure domains: kitchen-canvas.com, givemerecipe.com (both still flagged malicious across public sandboxes)
  • Payload hosting: d3pth7js01bstg.cloudfront.net (AWS CloudFront)
  • Loader: math.dll (in-memory)
  • Detection: BrowserModifier:Win32/MediaArena
  • Hashes: GiveMeRecipe.exe SHA256 3c1dbc3f…eccc, MD5 273FD232…7CEC; FoodFormula.exe SHA256 b179bec7…fb53; KitchenCanvas.exe MD5 d749e0f8…4121 [KitchenCanvas SHA256 pending, see production note]