Thursday, July 18, 2024

CeidPageLock Malware that Monitors User’s Browsing Data and Redirects Fake Pages

CeidPageLock RootKit evolves again with more improved features, this times it has been distributed by the RIG Exploit kit. The latest version contains functionalities such as monitoring user browsing activities, replace websites with fake pages and ability to redirect victims to fake pages.

The CeidPageLock is a browser hijacker which manipulates the victim’s browser and turns their homepage site appears to be – a Chinese web directory.

Fake page

Researchers from checkpoint observed the malware is particularly targeting Chinese victims, in particular, it uses various hijacking tricks to gather user data such as websites user’s visiting and the time spent on the site.


CeidPageLock Malware Dropper

The dropper was signed with an expired Thawte Code Signing certificate and its main function is to extract the driver that reside’s with it. Once the driver executed it send’s the infected system details to the C&C server.

Threat actors made the driver stealthy to evade endpoint’s and its main function is to connect with the C&C hard-coded domains to download the encrypted homepage configuration that used to tamper the browser.

The hijacked homepage is 111[.]l2345[.]cn and it pretends to be and it gathers victims stats on each and every search query and makes a profit by redirecting the victims to search engines that share ad revenue.

The rootkit uses AfdFastIoDeviceControl method to check every outgoing HTTP message to see if it matches to certain strings if it matches the rootkit adds the process to a redirected processes list.


The rootkit uses to check for every to find it is associated with recv() method. If it presents it modifies the webpage contents of the fake page that hosted in 111[.]l2345[.]cn.

when compared to the first version the new version adds VMProtect which adds protection against reversing and cracking which makes the unpacking and analysis difficult.

According to 360 safe security analysis, the CEIDPageLock blocks browser files from accessing anti-virus files and the new version add’s a number of files to it.

“CEIDPageLock might seem merely bothersome and hardly dangerous, the ability to execute code on an infected device while operating from the kernel, coupled with the persistence of the malware, makes it a potentially perfect backdoor.” researchers said.




C7A5241567B504F2DF18D085A4DDE559 – packed dropper
F7CAF6B189466895D0508EEB8FC25948 – houzi.sys
1A179E3A93BF3B59738CBE7BB25F72AB – unpacked dropper

Also Read

Multiple Malware Campaigns Distributing Remcos RAT Via Malicious Excel and Word Documents

AdvisorsBot Malware Attack on Hotels, Restaurants, and Telecommunications Via Weaponized Word Document

Lazarus APT Group Attack Cryptocurrency Exchange using macOS Malware Under the Operation AppleJeus


Latest articles

Volcano Demon Group Attacking Organizations With LukaLocker Ransomware

The Volcano Demon group has been discovered spreading a new ransomware called LukaLocker, which...

Resonance Security Launches Harmony to Monitor and Detect Threats to Web2 and Web3 Apps

Quick take:Harmony is the fourth cybersecurity application Resonance developed to address the disconnect in...

Beware! of New Phishing Tactics Mimic as HR Attacking Employees

Phishing attacks are becoming increasingly sophisticated, and the latest strategy targeting employees highlights this...

MirrorFace Attacking Organizations Exploiting Vulnerabilities In Internet-Facing Assets

MirrorFace threat actors have been targeting media, political organizations, and academic institutions since 2022,...

HardBit Ransomware Using Passphrase Protection To Evade Detection

In 2022, HardBit Ransomware emerged as version 4.0. Unlike typical ransomware groups, this ransomware...

New Poco RAT Weaponizing 7zip Files Using Google Drive

The hackers weaponize 7zip files to pass through security measures and deliver malware effectively.These...

New ShadowRoot Ransomware Attacking Business Via Weaponized PDF’s

X-Labs identified basic ransomware targeting Turkish businesses, delivered via PDF attachments in suspicious emails...
Guru baran
Guru baran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles