Showing posts with label DoubleClick. Show all posts
Showing posts with label DoubleClick. Show all posts

Tuesday, 15 September 2015

Infected Advertisements On EBay Weeks Remain Unnoticed


Cyber criminals are recent weeks managed to commonly-used ad networks like DoubleClick and AppNexus a large number of infected ads on popular websites such as eBay, Drudge Report and Answers.com get without that were noticed initially.

Which claims anti-malware company Malwarebytes. The attackers pretended to be legitimate advertisers and offered their ads through various real-time auctions to. Several ad networks allow advertisers bidding through auctions on the available ad space. To convincingly come across criminals used the companies that were registered with the US Chamber of Commerce, whose websites were sometimes recorded years ago.

According to analyst Jerome Segura was enough to fool most ad networks. The ads themselves were not provided with malware, but visitors were redirected to a page via an abbreviated URL that contained the Angler-exploitkit. This exploitkit uses vulnerabilities in Flash Player, among others. In the case the attack was successful Bedep the Trojan was installed on computers.

This Trojan can install additional malware on the computers, as malware, ad fraud and ransomware. The ads appeared on the UK eBay site, which receives 139 million monthly visitors and Drudgereport.com, which receives 61 million monthly visitors. All affected websites monthly gain of about 500 million. In total, the infected ads would have turned nearly three weeks undisturbed. Internet users whose software is up to date ran no risk in this attack.

Wednesday, 8 April 2015

Scale Attack Through Infected Google Ads


Last night there was a large-scale attack on Internet via infected Google ads place. Advertisements and the website of Engage Lab, a Bulgarian company that clients advertising space offered by Google, including through DoubleClick, were found to contain malicious code, as discovered the Delft security firm Fox-IT .

The malicious code sent visitors who see the ads were unnoticed through to another website. This website was exploitkit placed that visitors through known vulnerabilities in Adobe Flash Player, Java Oracle and Microsoft Silverlight tried to infect.In case users up-to-date were unsuccessful attack. Users who had forgotten to install the available security updates could become infected with malware.

After about two hours there were no ads found infected through the ad network Engage Lab. To prevent attacks via infected ads advises Fox-IT updating software like Java, Silverlight and Flash Player and the use of a AdBlocker.