News

Chinese Adware in the Microsoft Store: Malware Analysis Report

Our Malware Lab recently conducted an in-depth analysis on "Wallpapers Engine"an application distributed free of charge through the Microsoft Store.

Although it presents itself as a customisation tool for the Windows environment, the app incorporates within it a number of adware components aimed at distributing potentially unwanted content, such as invasive and potentially fraudulent advertisements, and behaviour that could convey arbitrary code via a C2 server.

During our analysis, it emerged that the application is an advertising campaign vehicle that displays false warnings about problems in the system with the aim of inducing the user to install a PC cleaning application. The final payload is software that follows a pay-as-you-go model on practically every feature required to solve non-existent problems.

The survey showed that a large part of the functionality offered was derived from legitimate open-source softwareintegrated into the app to simulate apparent reliability, but in all likelihood in violation of the relevant licences.

The most striking aspect is that the campaign was orchestrated by a publisher operating through a single account and always using the same unique identifier to sign the final Potentially Unwanted Program (PUP). This is a clear sign of a coordinated and repeated operation, and not an isolated case, aimed at exploiting the Microsoft Store ecosystem for circumvention and profit.

We believe that the invasive techniques used by this app should not be allowed on an official store, which is why Microsoft was warned before the report was published. However, we have not yet received a response, while the app is still available for download.

If you wish to learn more, here is the link to our full report.

In addition, you can subscribe to the Cyber Studios by Tinexta Defence mailing list to receive updates on upcoming reports: 

https://tinextadefence.it/mailing-list-cyber-studios/ 

Share:

Degree in Business Administration from the University of Naples 'Federico II' with an MBA in Business Management achieved with high merit in 2008 by winning a scholarship provided by Invitalia S.p.A. from which she was selected in the first months of attendance as the best MBA profile.

After a brief experience in Invitalia S.p.A., he immediately held increasingly important roles in the management of Administration, Finance and Control of companies operating in the defence sector, theInformation Technology, of Cyber and National Security. In addition, she was Treasury Manager in companies operating in theEnergy.

He obtained an Executive Master in Finance (EMF) at SDA Bocconi in 2020, with a specialisation in Corporate Finance & Control and, in 2022, a further specialisation track in Asset, Wealth Management also at SDA Bocconi.

For over five years it has been the Chief Financial Officer of the Defence Tech Group, whose listing process he followed on the Euronext Growth Milan segment of Borsa Italiana.

From 2017 to 2024, she was a member of the boards of directors of all the legal entity of the Defence Tech Group with delegated powers over their financial management and from October 2021 to October 2024 was a Board Member of the Holding Company.

It is currently also Investor Relations Manager of the listed Defence Tech and follows all ESG issues of the Group.

In July 2021, she was recognised by Federmanager as one of the best talents under 44 at national level, receiving an important award as Young Manager 2020.