Listed players
SST2.44▼ -7.58%TIG40.00▲ +3.90%TEAD0.56▲ +3.77%PERI8.50▼ -2.97%TBLA3.23▼ -2.71%INUV0.57▼ -1.74%AV10.06▼ -1.59%GOOGL343.50▲ +1.56%SNAP5.58▼ -1.24%PINS19.26▼ -1.03%MSFT517.53▲ +0.92%PPLI41.28▲ +0.81%IOS32.24▲ +0.44%META728.08▲ +0.30%GDDY97.21▲ +0.24%DV13.49▲ 0.00%MCHX1.29▲ 0.00%
Ticker byClearTrust

Hijacking

Browser hijackers, forced-search extensions and adware

Software changes a person's browser so their searches go through a monetised search page they never chose, or injects extra ads into the pages they visit.

The short answer, from The Arbitrage Desk fraud map

How it works

A browser hijacker arrives bundled with a free program or as an extension that promised something else. It changes the default search engine, home page or new-tab page to a look-alike search site. Every search the person makes now passes through that site, which shows feed ads and earns from the clicks. Adware goes a step further and inserts ads into pages, including on top of real search results.

To a feed, this traffic looks superb: real people typing real searches with real intent. That is why search hijacking has been the cash-out method for some of the largest botnets on record. The flaw is consent. The user did not choose that search provider, so the "query" was taken, not earned. Legitimate browser extension search monetisation exists, but it depends on clear disclosure, a single stated purpose and easy removal.

Who pays for it

Users lose control of their browser and are often tracked. The search engine they meant to use loses the search. Advertisers pay a middleman for a customer who was already looking for them. Feed partners with hijacked distribution face termination when it is found.

Who does it, and why

Software bundlers, extension developers and malware groups. Search traffic is the best-paid traffic on the web, so diverting it is more profitable than showing banners.

Warning signs

  • Search traffic from an extension, toolbar or installer whose install flow is not clearly disclosed.
  • Users reaching the search page only via changed browser settings, never by choice.
  • Antivirus products flagging the software as potentially unwanted.
  • High uninstall rates and user complaints about being unable to change search settings.
  • Queries that mirror what users typed for another search engine.

Defences

  • Before accepting extension or software traffic, walk through the install as a user would.
  • Require plain disclosure of the search change, an opt-in, and one-click removal.
  • Check the software's reputation with security vendors and browser stores.
  • Monitor for query patterns copied from other engines, a mark of interception.

An example

Real cases: Microsoft said the Bamital botnet attacked more than 8 million computers over two years, diverting search clicks. ZeroAccess, with nearly 2 million machines, cost advertisers upwards of $2.7 million a month by Microsoft's estimate. Check Point attributed the 2017 Fireball hijacker, which pushed searches through fake engines to Yahoo and Google, to a marketing agency and estimated 250 million infections.

Documented cases

Sources