












Heimdal’s SOC flagged a surge in detections tied to a program called Shift Browser on 2 September 2026.
Our team confirmed activity on more than 50 client environments in a single day. The installers we captured trace to a malvertising lure.
Shift Browser also runs a documented paid creator and affiliate marketing operation, though we haven’t been able to draw a confirmed line between that channel and this specific wave of detections.
Shift Browser markets itself as a security-focused productivity browser.
Malwarebytes has flagged the installer as PUP.Optional.ShiftBrowser since October 2024, and PCrisk and GridinSoft both track it as an unwanted application with browser-hijacking behaviour.
Shift Technologies disputes the malware label directly Its own guidance page calls the product “designed to improve your productivity without compromising your security” and states plainly, “It is not malware.”
User reports back this up.
People describe Shift Browser auto-starting with Windows, hijacking default browser settings, and resisting standard uninstall attempts.
One Microsoft support thread walks a user through a two-step removal process. Uninstall the app, then strip its auto-start entries by hand, since the standard uninstaller leaves them behind.
Distribution follows a malvertising pattern that other vendors have documented independently. Malwarebytes describes the same lure. Ads placed where people search for manuals, recipes, and document templates.
Heimdal’s SOC saw the identical pattern and blocks the downloader responsible for fetching the real installer. This lure explains the installer names our SOC captured on 2 September.
Each one presents itself as a PDF tool, but none are.
Shift also runs a formal creator affiliate programme, advertised to prospective creators as offering transparent rates, and at least one independent review we checked carries a tracked affiliate link back to Shift’s site.
That’s a real, separate channel for Shift generally.
We haven’t confirmed it as the delivery path for any install in this specific wave, so treat it as context, not as a second proven vector for the 2 September detections. The malvertising lure on its own is what’s producing 50-plus client environments in one day.
Heimdal’s SOC ran the captured samples through dynamic analysis.
Our sandbox returns a Malicious verdict, with four warnings raised on a single process.
That is Heimdal’s own behavioural read of what the installer does on a machine, and it sits ahead of where most of the industry has landed.
Malwarebytes, PCrisk, and GridinSoft all classify Shift as a potentially unwanted program rather than malware outright. Our sandbox data doesn’t contradict that. It adds to it. This is what the behaviour looks like once you actually run it.

Behaviourally, the installer maps to three MITRE ATT&CK techniques.
This combination is fingerprinting. Before Shift Browser drops its payload, the installer profiles the machine it landed on.
YARA rules on the sample flag a Borland Delphi compile and confirm an InnoSetup installer wrapper.
Inside, the installer drops chrome.packed.7z, a packed Chromium build that becomes the browser engine once unpacked. That’s the pattern you’d expect from any Chromium fork.

Past the drop, the process reaches out to known malware and adware domains and writes registry changes tied to persistence and configuration.
Every sample Heimdal captured carries a digital signature from Shift Technologies Inc. Treat this signature as a fact about the file, not a verdict on it.
A valid code signing certificate lowers the odds of SmartScreen or a signature-based control blocking the install. It says nothing about what the software does after that.
Adware and PUP families lean on legitimately obtained certificates for this exact reason. The signature buys trust, and trust buys reach.
Heimdal’s SOC keeps tracking this campaign as new samples land.
Expect the outstanding hash to land as we process the rest of the 2 September detections. Domain data will keep evolving rather than settling into a fixed list.
Shift markets through a mix of official brand accounts and a paid creator programme. The company runs verified accounts on TikTok, YouTube, and Instagram, and its Shift Creator Program page advertises transparent rates and partnerships to prospective creators.
The YouTube review we checked carries a tracked affiliate link back to Shift’s own site. That confirms the programme is active, not just advertised.
We can document that channel in general. We can’t draw a line from it to this specific campaign.
Our SOC found no correlation between any individual piece of social content and the actual installs in this wave, so treat the marketing channel as context for how Shift grows its user base, not as a confirmed delivery mechanism for the 2 September detections specifically.
If you liked this article, follow us on LinkedIn, Reddit, X, Facebook, and Youtube for more cybersecurity news and topics.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。