

This malvertising campaign is very widespread, but “targeted” which means that not everyone who’s using the MSN portal pages is seeing it. This template is currently being delivered on MSN portal pages,Īs well as on other high-priority web portals – and it’s being detected by Windows Defender as Trojan:JS/Flafisi.D, which is specifically a detection for the FlashPlayer.hta file associated with the KovCoreG malvertising group:

The buzz isn’t really about the Adobe Flash Player app per se – it’s about the fake Adobe Flash Player update page that’s serving as a malvertising template for the Microsoft web browsers.
