During our investigation of suspicious web pages, our research team came across the Cars – New Tab browser extension. It is promoted as a tool that provides automobile-themed wallpapers for browsers. However, after conducting tests on this extension, we determined that it is actually a browser hijacker. Cars – New Tab modifies browser settings to promote the fake search engine

Once installed on our testing machine, Cars – New Tab changed the default search engine, homepage, and new tab/window URL of the browser to As a result, whenever we opened a new browser tab/window or entered a search query in the URL bar, we were redirected to

Similar to typical browser hijackers, Cars – New Tab utilizes techniques to ensure its persistence and prevent users from easily recovering their browsers.
Fake search engines like usually cannot provide genuine search results, so they often redirect users to legitimate search engines such as Bing or Google at the point in time we did our research. However, the actual redirect destination may vary depending on factors like the user's geolocation and further tweaking on part of the extension developers.

Additionally, Cars – New Tab engages in spying on users' browsing activities. It collects various data of interest, including visited URLs, viewed pages, search queries, internet cookies, login credentials, personally identifiable information, financial data, and more. This sensitive data can be monetized through its sale to third parties.

It's important to be cautious when encountering browser extensions like Cars – New Tab and to regularly review and manage the extensions installed on your browser.

How Can Browser Hijackers Swap Your Usual Browser Settings and Why is This a Potential Security Issue?

Browser hijackers have the capability to swap or modify your usual browser settings, which poses potential security issues for several reasons:

Unauthorized Changes: Browser hijackers can alter your default search engine, homepage, new tab page, or other browser settings without your consent or knowledge. This unauthorized modification disrupts your browsing experience and can lead to frustration and inconvenience.

Promotion of Fake or Malicious Websites: Browser hijackers often promote fake or malicious websites by redirecting your searches or opening new tabs/windows to these sites. These websites may contain misleading information, phishing attempts, malware downloads, or other malicious content. Visiting such sites can compromise your system's security and expose you to various online threats.

Increased Exposure to Advertisements: Browser hijackers typically inject excessive and intrusive advertisements into your browsing sessions. These ads can appear as pop-ups, banners, or in-text links, disrupting your online activities and compromising the usability of websites. Clicking on these ads may lead to further malware infections or unwanted software installations.

Data Tracking and Privacy Concerns: Browser hijackers often track your browsing habits, search queries, and other online activities to collect personal information. They may gather data such as visited websites, clicked links, IP addresses, geolocation, and even personally identifiable information. This invasion of privacy raises concerns about data security and the potential misuse of your personal information.

Vulnerability Exploitation: Browser hijackers can exploit vulnerabilities in your browser or its extensions to gain unauthorized access to your system. They can also disable security features or install additional malicious software, further compromising your system's security and stability.

The potential security issues posed by browser hijackers highlight the importance of taking proactive measures to protect your browser and system. Regularly updating your browser and its extensions, practicing safe browsing habits, using reputable security software, and being cautious when installing new software or browser extensions can help mitigate the risks associated with browser hijackers and enhance your overall online security.

May 22, 2023

