Threat Scorecard

Ranking: 7,646
Threat Level: 50 % (Medium)
Infected Computers: 151
First Seen: October 13, 2022
Last Seen: September 25, 2023
OS(es) Affected: Windows

Despite the popularity and momentum of NFTs (Non-Fungible Tokens) being severely diminished, the creators and operators of dubious applications are still targeting this sector. For example, the NFT Tab browser extension is presented to users as a convenient way to get early access to currently trending NFTs and relevant news about them. However, when installed on the user's device, the NFT Tab makes it clear rather quickly that it also is a browser hijacker.

Indeed, affected users will notice that their browsers are now frequently redirecting to an unfamiliar address at '' Redirects will occur every time users launch the browser, start a new tab or initiate a search via the URL tab. The explanation is quite simple - the NFT Tab browser hijacker modifies browsers' homepage, new tab page, and default search engine. In turn, will redirect the launched search queries to the legitimate Bing search engine and show the results it produces. While present on the device, NFT Tab's persistence mechanisms will prevent users from reverting the modified settings to their original states.

Browser hijackers, adware, and PUPs (Potentially Unwanted Programs) often spy on users' browsing activities. Information such as their browsing history, search history, and clicked URLs could be collected and transmitted to the PUP's operators. In some cases, even device details or sensitive data extracted from browsers' autofill data may be included in the exfiltrated data.


Most Viewed
