Researchers Uncover Lucrative ‘Stantinko’ Adware Campaign

Security researchers have discovered a large-scale adware campaign that has been operating since 2012 and affected nearly half a million users.

According to researchers at ESET Security, the sophisticated Stantinko campaign primarily targets Russia and Ukraine and has utilised a combination of code encryption and rapid adaptation techniques to stay out of sight of anti-malware tools.

Once installed, Stantinko generates revenue for its operators in several different ways, including through ad injection and click fraud.

Adware threat

“To infect a system, they trick users looking for pirated software into downloading executable files sometimes disguised as torrents,” explain Frederic Vachon and Matthieu Faou on the Eset blog. “FileTour, Stantinko’s initial installation vector, then loudly installs a lot of software to distract the user while it covertly installs Stantinko’s first service in the background.”

Once installed, it avoids detection by concealing the malicious code inside an encrypted component that resides either on the disk or in the Windows registry. This makes it hard for anti-malware tools to detect the infection as malicious behaviours remain hidden.

Stantinko is also highly resilient, as is installs two malicious Windows services that each have the ability to reinstall the other, meaning both services need to be deleted at the same time in order to fully remove it from the system.

Its main role is to install malicious browser extensions called The Safe Surfing and Teddy Protection, as the researchers explain: “Both extensions were available on the Chrome Web Store during our analysis. At first sight, they look like legitimate browser extensions that block unwanted URLs.

“However, when installed by Stantinko, the extensions receive a different configuration containing rules to perform click fraud and ad injection.” This generates revenue for the operators as they are paid for the traffic they provide to advertisers.

But it doesn’t stop there: “The malicious Windows services they install enable them to execute anything on the infected host.

“We’ve seen them being used to send a fully featured backdoor, a bot performing massive searches on Google, and a tool performing brute-force attacks on Joomla and WordPress administrator panels in an attempt to compromise and potentially resell them.”

Although not noticeable to the user, Stantinko is certainly a major threat, providing a large source of income for its creators and putting user’s privacy at risk.

Quiz. Are you a security guru?

Sam Pudwell

Sam Pudwell joined Silicon UK as a reporter in December 2016. As well as being the resident Cloud aficionado, he covers areas such as cyber security, government IT and sports technology, with the aim of going to as many events as possible.

Recent Posts

Meta Adds ‘Live AI’ To Ray-Ban Smart Glasses

Facebook parent Meta adds AI voice chat, live translation to Ray-Ban Meta smart glasses as…

19 hours ago

US Senate Criticises Amazon Over Warehouse Safety

Senate study finds Amazon did not implement protections recommended by internal studies over risk they…

19 hours ago

US Lawmaker Calls For Drone Detection Tech After Runway Closure

US senate majority leader calls for federal deployment of drone detection technology after drone sightings…

20 hours ago

TikTok Shop US Sales Surpass Shein, Sephora

After launching in September 2023, TikTok Shop rises to broad popularity with US sales surpassing…

20 hours ago

China Chip Investment Plummets Amidst US Restrictions

Investment in China's semiconductor industry falls by one-third this year as US tightens restrictions, state…

21 hours ago

Bitcoin Hits New High Over $107,000 On Trump Comments

Bitcoin surges more than 5 percent after Trump reaffirms plans for national strategic crypto reserve,…

21 hours ago