Download.com and Other Sites Bundling Superfish-Style Adware: Report

Advertisement
By Hitesh Arora | Updated: 25 February 2015 16:59 IST
Despite new security features being added on an almost daily basis, we are certainly not moving towards a more secure Internet - at least, this is what can be derived from recent findings.

After Lenovo was found to be installing the malicious adware Superfish in consumer machines, another report on Monday came out suggesting that it is not the only one doing it. It reported two names of the security firms that have added similar man-in-the-middle code in their software platforms. While one software is being said to be using vulnerable SSL-interception technology sold by Komodia, similar to what Superfish employed, the other using different technology achieves the same effect of bypassing SSL and HTTPS protection.

All this seems to have created panic in consumers, and researchers are taking concerns seriously. According to a new report by How to Geek on Monday, several freeware and software sites (including CNET's Download.com) are bundling HTTPS-breaking-adware nowadays.

The report notes that the adware like Wajam, Geniusbox, Content Explorer, and many others are following the same trend as seen with Superfish in Lenovo. These companies are installing their own certificates and forcing all your browsing (including HTTPS encrypted browsing sessions) to go through their proxy server. Not just that, the report claims that your machine can just get infected "by installing two [KMPlayer and YTD] of the top 10 apps on CNET Downloads." The two apps reportedly feature two different types of "HTTPS-hijacking adware".

Advertisement

Once the adware is installed and is proxying all the traffic, users start to see ads all over even on the secure sites, like on Google, "replacing the actual Google ads, or they show up as popups all over the place, taking over every site."

Advertisement

These adware essentially install their fake root certificates into the Windows Certificates store and then use proxies to connect to secure sites with the fake certificates, explains report.

While it is not exactly clear whether the Download.com team or the app developers are bundling the adware, the distribution sites are obligated to ensure the content they host is safe.

Advertisement

So in short, the HTTPS websites are also not secure if any adware is installed on your machine knowingly or unknowingly.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Ray-Ban Meta Gen 2 Glassses Are Now Available in India
  2. Apple Adds iPhone SE (First Generation), More Products to Obsolete List
  3. Mrs Deshpande OTT Release: When, Where to Watch Madhuri Dixit's Serial Killer Mystery
  4. Poco C85 5G Teased to Launch in India Soon With These Features
  5. Samsung Galaxy S26 vs Galaxy S25: Here Are the Anticipated Upgrades
  6. Just Corseca Skywatch Pro Review: A Budget Offering
  1. Redmi 15C 5G Launching Today: Know Price in India, Features and Specifications
  2. Gemini App to Get a Major Design Upgrade, Could Soon Be Launched on macOS
  3. NASA’s Perseverance Records First-Ever Mini-Lightning on Mars
  4. Germany to Send First European Astronaut Around the Moon on Artemis Mission
  5. Indian Team Finds 53 Massive Quasars Blasting Jets Millions of Light-Years Long
  6. Mrs Deshpande OTT Release: When, Where to Watch Madhuri Dixit's Serial Killer Mystery
  7. Wake Up Dead Man: A Knives Out Mystery OTT Release: When, Where to Watch the Daniel Craig Whodunit
  8. Fire Force Season 3 Release Date: When, Where to Watch the Shonen Anime's Final Arc
  9. Thamma Is Now Available on Amazon Prime: How to Watch Ayushmann Khurrana's Horror Comedy
  10. The Great Shamsuddin Family OTT Release: When, Where to Watch the Peepli Live Director's Comedy Drama
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.