A new malware is hitting computers globally and has so far infected over 250 million computers, according to cybersecurity researchers in Check Point. Named Fireball, the malware operations are based in China and is said to have infected 20% of corporate networks.
In Check Point’s own words, Fireball “takes over target browsers and turns them into zombies.” It hijacks a browser and allows it to become a malware downloader. Once in, Fireball can execute any code on the victim machines – from stealing credentials to dropping additional malware, as well as manipulating infected users’ web-traffic to generate ad-revenue.
“Currently, Fireball installs plug-ins and additional configurations to boost its advertisements, but just as easily it can turn into a prominent distributor for any additional malware.” Check Point wrote.
The operation is run by Beijing based digital marketing agency Rafotech. Fireball is spread mostly via bundling – where an additional programme is installed on victim machines alongside a wanted program, often without the user’s consent.
Figure 2: Fireball Global Infection Rates (darker pink = more infections)
Check Point estimates over 250 million computers worldwide have been infected, with top 3 countries with highest infection rate being India, Brazil and Mexico. Our neighbours in Indonesia recorded 13.1 million victims. Alarmingly, 20% of global corporate networks are infected – and within that, 60% of corporate infections are in Indonesia.
Rafotech turn default search engines and home-pages into fake search engines. The fake search engines include tracking pixels used to collect the users’ private information. Fireball has the ability to spy on victims, perform efficient malware dropping, and execute any malicious code in the infected machines. What was worrying was how popular the web traffic data is. According to Alexa’s web traffic data, 14 of these fake search engines are among the top 10,000 websites, with some of them occasionally reaching the top 1,000.
Rafotech denies producing browser-hijackers and fake search engines, but does boast to be a “successful marketing agency, reaching 300 million users worldwide”, coinciding with researcher estimates.
“Fireball and similar browser-hijackers are half seemingly legitimate software, and half malware. Although Rafotech uses Fireball only for advertising and initiating traffic to its fake search engines, it can perform any action on the victims’ machines… Fireball displays great sophistication and quality evasion techniques, including anti-detection capabilities, multi-layer structure and a flexible C&C.” Check Point wrote.
They further wrote that Rafotech’s distribution methods appear to be illegitimate. “The malware and the fake search engines don’t carry indicators connecting them to Rafotech, they cannot be uninstalled by an ordinary user, and they conceal their true nature,” suggesting that Rafotech distributed the adware with malicious intent.
Check Point warns that when users install freeware, malware could be dropped at a later date via a backdoor, or performing actions that aren’t immediately obvious, leading to monetary or data loss in the future.
Users can check if they are infected through checking a few settings in their browser.
- Was your home-page set by you?
- Are you able to modify it?
- Are you familiar with your default search engine and can modify that as well?
- Do you remember installing all of your browser extensions?
If the answer to any of these questions is “NO”, this is a sign that you’re infected with adware.
Users are advised to remove the adwares, by removing the application from the Programs and Features list in the Windows Control Panel, as well as removing malicious add-ons, extensions or plug-ins from your browsers. Check Point also advises using anti-malware software and adware cleaner software, as not all applications are immediately obvious.





