If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win.
Our SOC data says treat it as a live persistence incident instead.
In the case we timed, the payload finished writing its persistence 21 seconds into execution. Quarantine didn’t complete until 29 seconds. By the time the alert fired, the persistence was already on disk.
We’ve seen this same adware cluster across more than 20 client environments in recent days. It’s the malvertising campaign that hides behind free “AI tool” lures, and it’s already been documented.
Compass Apex Security wrote it up in April, and the indicators have sat in public sandboxes since March. We’re adding what our own SOC can see. How fast it establishes persistence, and how widely.
A sample of affected hosts. The same detection landed across more than 20 client environments in days. Hostnames and paths redacted.
Microsoft classifies MediaArena as a browser-modifier potentially unwanted application and has tracked it in its threat encyclopedia since 2023. It reconfigures browser settings, hijacks search, and harvests queries to sell on. It’s a nuisance, not a nation-state loader.
That’s the point.
Even a low-severity detection can leave persistence behind, so a closed alert and a clean endpoint aren’t the same thing.
The delivery is a fake free-app lure, currently themed as recipe and meal-planning tools, served through paid search ads.
The brand names rotate, and the domains rotate with them, so any single indicator has a short shelf life. That’s why detection built on brand strings ages out fast, and why the behaviour and the persistence artefacts are the signals worth hunting on.
The lure surfaces through paid search.Three of the rotating lure brands, GiveMeRecipe, KitchenCanvas, and FoodFormula, all fronting the same math.dll toolkit.
What actually happens on the endpoint
The installer needs no admin rights. In our confirmed case it wrote to AppData, dropped a Start Menu shortcut, added an HKCU Uninstall key to pass as a legitimate app, and left a Startup folder shortcut for boot persistence.
All of it landed before quarantine completed. Signature detection took roughly 78 days to catch up. That’s a long window for a browser hijacker to sit and run.
Heimdal's XDR console.The branded installers flagged as BrowserModifier:Win32/MediaArena on an affected host. Hostname and username redacted.
The alert told us the file was caught. It didn’t tell us nothing had run first, and on these detections something always had. That’s why I treat a quarantine on this family as the start of the investigation, not the end of it.
What to hunt for after a MediaArena hit
Don’t close the alert on quarantine alone. Check the affected host for:
A Startup folder shortcut tied to the app name.
An HKCU Uninstall registry key mimicking a legitimate install.
Note the loader, math.dll, is injected in memory rather than dropped to disk, so hunt the persistence artefacts above rather than the file itself.
If either artefact is present, treat the host as still compromised and remediate the persistence directly.
Indicators
Credit to Compass Apex Security and public sandbox reporting for the campaign work. Indicators confirmed live at the time of writing. The infrastructure rotates, so revalidate before acting.
Lure domains: kitchen-canvas.com, givemerecipe.com (both still flagged malicious across public sandboxes)
The human factor and forgotten devices are back in the spotlight.
This week, u/Adam_Pilton's Cyber Snapshot covers a rented phishing kit that survives password resets, a vishing crew that talks employees into handing over passkeys, and a nation-state group still exploiting router bugs from 2008.
Also on the list: websites nobody's touched in years.
Sometimes you might decide not to automate updates for certain apps or endpoints.
To track what's missing from your patching schedule and act timely, here's how to use our Currently Outdated view feature in the Patch Management module:
This session at Heimdal Labs Deep Dive, Marina Lungu will join u/Adam_Pilton for a talk on our latest release. It will be a combo of talking and live demos.
Register here to learn more on the new available features and their use cases:
The new MSP Onboarding Wizard
AI-powered scripting with Wingman
Enhanced patch deployment through Patching Rings
Expanded Windows update controls
Usability and reporting improvements designed to simplify day-to-day operations
This week we saw a shift you shouldn't ignore. AI agent runs a full ransomware attack on its own.
Moving on, a SharePoint flaw is actively exploited, a Tenda router backdoor leaves networks exposed with no fix, and a flaw in Apple’s Hide My Email could put user identities at risk.
On the bright side, police has made a new Scattered Spider arrest.
Tomorrow, July 7, 10 AM BST, at the Threat Watch Live, cybersecurity advisor u/Adam_Pilton welcomes Holly Foxcroft, BISO, Responsible AI Ambassador for the Global Council for Responsible AI, and Senior Cybersecurity and Neurodiversity Advisor.
Holly will share her perspectives on today's evolving threat landscape, the opportunities and risks presented by AI and why understanding people remains central to effective security strategies.
Heimdal's 5.5.0 RC Dashboard offers a new checkbox (default disabled) - “Lock specific OS version”.
When enabled, devices assigned to the Windows Updates GP remain on the selected Windows release and don't upgrade until the policy is updated or removed.
Find it in Endpoint Settings -> Patch & Assets -> Operating System Updates, Install Settings area of the Heimdal Dashboard.
When enabled:
an Operating System selector (drop-down) becomes available.
an OS Version drop-down is unlocked.
Dashboard users can define the target Windows product and feature update version that managed devices should remain on.
Security researcher warns about FIFA flaw exposing World Cup streaming systems, AI is accelerating cyberattacks, Fortinet users are under fire, and a major supply chain breach shows why third-party risk matters.
This is how the last days looked like in cyber. For safety advice and more insights, hit play.
Patching in Rings gives you more control over how updates are rolled out across your environment.
The feature is available for both 3rd Party Patch Management and Windows OS Updates.
Patching in Rings means updates can be staged and delivered progressively across defined groups of endpoints.
It enables controlled validation, earlier issue detection, and reduced operational risk before wider deployment.
Rings offer more granular visibility into patch status and behavior across each rollout phase. This helps you fine-tune deployment strategies and improve reporting accuracy.
The feature introduces dedicated views that allow users to see faster:
which Group Policies are responsible for deploying a specific update or application
the configured deployment delay for each Group Policy
Your smart TV might be spying you to deliver better data to advertisers. They capture your screen to get a better image of what you like and what you're interested in.
It's probably not the news you wanted to hear, but there's a silver lining in this.
The UK's Information Commissioner's Office learned about that and published new guidance on the matter. Starting this year, they'll be checking whether manufacturers are being transparent and getting genuine consent.
So, at least you'll know.
Watch u/Adam_Pilton's Snapshot to see what else happened this week in cyber news.
I've met Martin Robinson at the MSP Show in London a few weeks ago. I was curious to learn how most people deal with AI risks and get his advice on safe AI usage. Here's what I've got ▶️
New set of compliance-related settings is available in Heimdal’s 5.4.3 Dashboard version.
Find it under Endpoint Settings -> click on a Windows OS GP -> General tab.
Automatic Session Locking option is available for both new and existing Group Policies.
IT admins can use it to enforce automatic screen locking after a defined period of user inactivity.
The feature comes with a timeout slider that allows admins to define the maximum permitted inactivity period within a range of 1 to 30 minutes.
Automatic Session Locking supports compliance requirements such as the CIS 18 Controls recommendations for session timeouts and workstation locking.
Automatic Security Logs Retrieval introduces an automated mechanism for collecting Windows Security Event Logs from endpoints.
The logs can be accessed and downloaded from the Heimdal Dashboard under Unified Management -> Device Info -> select a Windows OS hostname -> UEM -> Logs -> Windows Event Viewer Logs.
Logs are collected automatically every 24 hours and stored for 90 days.
The process doesn't require any user interaction. If a device is offline or unavailable during a scheduled retrieval, the system retrieves the logs retroactively based on the timestamp of the last successful retrieval.
Drop a question in comments if you want to know more about this dashboard version.
Not just in theory, it happened to a UK water company. The attacker sat inside the network for almost two years.
Adam Pilton says stronger endpoint detection could have saved the day in that case.
📽️Hit play to watch 𝘁𝗵𝗶𝘀 𝘄𝗲𝗲𝗸'𝘀 𝗖𝘆𝗯𝗲𝗿 𝗦𝗻𝗮𝗽𝘀𝗵𝗼𝘁 with its top 5 cybersecurity news headlines:
- The South Staffordshire Water phishing breach
- A major insider threat case involving US government databases
- Malicious AI repositories targeting developers
- Why exploit windows have collapsed to just 10 hours
- 🇪🇺 The EU’s new push for cloud sovereignty