OFFICIAL SECURITY BLOG
August 3, 2015 | BY Jérôme Segura
June and July have set new records for malvertising attacks. We have just uncovered a large scale attack abusing Yahoo!’s own ad network.
As soon as we detected the malicious activity, we notified Yahoo! and we are pleased to report that they took immediate action to stop the issue. The campaign is no longer active at the time of publishing this blog.
This latest campaign started on July 28th, as seen from our own telemetry. According to data from SimilarWeb, Yahoo!’s website has an estimated 6.9 Billion visits per month making this one of the largest malvertising attacks we have seen recently.
ads.yahoo.com
-> adslides.rotator.hadj1.adjuggler.net
-> ch2-34-ia.azurewebsites.net/?ekrug=sewr487giviv93=12dvr4g4
-> basestyle.org/?id=1423150231&JHRufu346&camp=URhfn67458&click=UEjd856
-> siege.nohzuespoluprace.net/forums/viewforum.php?f=2sb49&sid=y1yki0
As with the previous reported cases this one also leverages Microsoft Azure websites:
We have observed two main domains being used:
The sequence of redirections eventually leads to the Angler Exploit Kit:
We did not collect the payload in this particular campaign although we know that Angler has been dropping a mix of ad fraud (Bedep) and ransomware (CryptoWall).
Malwarebytes Anti-Exploit users were already protected against this attack.
We would like to thank Yahoo! for their prompt response with this incident. Here’s their official statement:
“Yahoo is committed to ensuring that both our advertisers and users have a safe and reliable experience. As soon as we learned of this issue, our team took action and will continue to investigate this issue.
Unfortunately, disruptive ad behavior affects the entire tech industry. Yahoo has a long history of engagement on this issue and is committed to working with our peers to create a secure advertising experience. We’ll continue to ensure the quality and safety of our ads through our automated testing and through the SafeFrame working group, which seeks to protect consumers and publishers from the potential security risks inherent in the online ad ecosystem.”
Malvertising is a silent killer because malicious ads do not require any type of user interaction in order to execute their payload. The mere fact of browsing to a website that has adverts (and most sites, if not all, do) is enough to start the infection chain.
The complexity of the online advertising economy makes it easy for malicious actors to abuse the system and get away with it. It is one of the reasons why we need to work very closely with different industry partners to detect suspicious patterns and react very quickly to halt rogue campaigns.
Pingback: Yahoo tackles large ‘malvertising’ campaign in its ad network | POPFIX - #Celebrity, #Tech, #Sports News()
Pingback: Tips.com.gr | Yahoo tackles large ‘malvertising’ campaign in its ad network()
Pingback: Yahoo tackles large 'malvertising' campaign in its ad network | BALKANSKI TV KANALI()
Pingback: Yahoo tackles large 'malvertising' campaign in its ad network | Global Wireless Research()
Pingback: Yahoo tackles large 'malvertising' campaign in its ad network - Sys Logic Technology Services, LLC()
Pingback: Yahoo tackles large 'malvertising' campaign in its ad network | IP Pings()
Pingback: Yahoo tackles large ‘malvertising’ campaign in its ad network | Virus / malware / hacking / security news()
Pingback: Yahoo tackles large 'malvertising' campaign in its ad network | fairtechsupport.com()
Pingback: Yahoo! homepage caught spreading CryptoWall malware (again) | LeeFuller.io()
Pingback: Huge malware campaign used Yahoo's ad network | Taiwan NO 01()
Pingback: Huge malware campaign used Yahoo’s ad network | iTruckTV()
Pingback: Huge malware campaign used Yahoo's ad network - Popular Trending | trends.my.id()
Pingback: Huge malware campaign used Yahoo's ad network - Ask a Question and Get Answer Frequently Asked Questions()
Pingback: Huge malware campaign used Yahoo's ad network — Cath News India()
Pingback: Huge malware campaign used Yahoo’s ad network | My Power Health()
Pingback: BlackHat 2015: RiskIQ reports huge spike in malvertising | OFF THE BLOCK NEWS()
Pingback: Huge malware campaign used Yahoo's ad network | insurance()
Pingback: Yahoo tackles large malicious ad campaign in its network | POPFIX - #Celebrity, #Tech, #Sports News()
Pingback: Fast Forward: Flash-Malware, WordPress 4.2.4 und das Scheitern von Google+ - entwickler.de()
Pingback: Хакеры эксплуатируют Flash-уязвимость в рекламе Yahoo! | IT News()
Pingback: Huge malware campaign used Yahoo’s ad network | Thalaippu()
Pingback: Yahoo malvertising attack leaves 900 million at risk of ransomware - seekape()
Pingback: Huge malware campaign used Yahoo’s ad network()
Pingback: Reklamy Yahoo! przekierowywały internautów na CryptoWalla()
Pingback: Yahoo tackles large malicious ad campaign in its network - Brisbane Computer Repairs()
Pingback: Yahoo tackles large malicious ad campaign in its network – PCWorld | Everyday News Update()
Pingback: A Yahoo! saját rendszerével támadtak | SystPro()
Pingback: Hackers habrían utilizado un()
Pingback: Yahoo ads compromised by hackers for a week in record attack - reFLIPd()
Pingback: Yahoo tackles large ‘malvertising’ campaign in its ad network | Templar Shield()
Pingback: Hackers habrían utilizado una vulnerabilidad de Flash en Yahoo Ads para atacar a millones - Misiongeek()
Pingback: Yahoo ads accidentally spewed malware | News For The Blind()
Pingback: Hackers exploit flash adverts - Breaking Ads()
Pingback: Have you visited Yahoo lately? You may have malware on your computer - **** on Heels()
Pingback: Have you visited Yahoo lately? You may have malware on your computer » Rand0m Stuff()
Pingback: Have you visited Yahoo lately? You may have malware on your computer - DailyScene.comDailyScene.com()
Pingback: Hackers habrían utilizado una vulnerabilidad de Flash en Yahoo Ads para atacar a millones | Blog Textual()
Pingback: Have you visited Yahoo lately? You may have malware on your computer | Bain Daily()
Pingback: Have you visited Yahoo lately? You may have malware on your computer - News()
Pingback: Yahoo Squashes Ads Infected by Malware – PC Magazine | Your Common Newspaper()
Pingback: Yahoo Squashes Ads Infected by Malware | Laptop Charger Canada()
Pingback: Yahoo! website! ads! spaff! CryptoWall! ransomware! AGAIN! | TechDiem.com()
Pingback: Yahoo Squashes Ads Infected by Malware | Laptop Charger USA()
Pingback: Flash… Example of how your employees with old Adobe Flash can unintentionally invite a bad actors in through your firewall… | Defensative()
Pingback: Malvertising Attack On Yahoo Is Another Reminder To Disable Flash | Gizmodo Australia()
Pingback: Yahoo Squashes Ads Infected by Malware - 4PC News()
Pingback: Hackers hijacked Yahoo ads for a full week | The Cyber Law Library()
Pingback: ياهو تعترف بثغرة في اعلاناتها هددت الاف الزوار لموقعها - مركز اخبار مصر | مركز اخبار مصر()
Pingback: Yahoo Ads Network Was Serving Malware | Security Zap()
Pingback: Yahoo opět zasaženo malvertisingem » Kyber bezpečnost()
Pingback: Huge malware campaign used Yahoo’s ad network | GoldenZine()
Pingback: Yahoo users hit by 'malvertising' campaign | New Feeds UK()
Pingback: Yahoo Squashes Ads Infected by Malware | Christmas Hot Deals()
Pingback: No se imagina lo que le pasó a algunos que visitaron el sitio de Yahoo! « Vida Tech « TECHcetera()
Pingback: Yahoo ad network targeted by ‘malvertising’ hackers | M&M Global()
Pingback: Utilizan de nuevo Yahoo! Ads para distribuir malware()
Pingback: Yahoo visitors hit by week-long malware attack | BW:NET | UK & USA VPS Servers | Shared Hosting | UK Dedicated Servers | Domain Registration | Freelance Webhosting()
Pingback: Ad Blockers Are Security Tools at A Geek With Guns()
Pingback: Yahoo Users Hit By Huge Malvertising Attack - SiteProNews()
Pingback: Yahoo visitors hit by week-long malware attack - TechCabin()
Pingback: Hackers habrían utilizado una vulnerabilidad de Flash en Yahoo Ads para atacar a millones | Wizard Security()
Pingback: Yahoo visitors hit by week-long malware attack |()
Pingback: Yahoo visitors hit by week-long malware attack - news plaza()
Pingback: Yahoo Users Hit By Huge Malvertising Attack | Mystical Village()
Pingback: Yahoo visitors hit by week-long malware attack | ALBATARNI()
Pingback: Yahoo Ad Network Targeted In Malvertising Attack Seeking Flash Vulnerability | Advertised Free()
Pingback: Yahoo exposes users to malvertising ... again - IT Manager Daily()
Pingback: Yahoo Website Eclipsed With One of the Largest Malvertising Attack | Poster Waves()
Pingback: ياهو تعترف بثغرة في اعلاناتها هددت الاف الزوار لموقعها | بوابة عمان الرقمية()
Pingback: Yahoo visitors hit by week-long malware attack | Playground || Gopal ||()
Pingback: Yahoo Ad Network Targeted In Malvertising Attack Seeking Flash Vulnerability | Famous Marketing()
Pingback: Malvertising Attack Hits Yaho()
Pingback: AtomTimes » Flash Player nuovo attacco tramite Yahoo()
Pingback: Ad firms are the reason Adobe’s Flash still exists—despite its many, many security flaws - Quartz()
Pingback: Yahoo: Schadcode mehrere Tage lang über Werbenetzwerk verteilt - Servaholics()
Pingback: Yahoo Malvertising Attack Points to More Flash Problems | Forensic News()
Pingback: Engadget | Technology News, Advice and Features | Super Deal Shopper()
Pingback: Huge malware campaign used Yahoo's ad network | Super Deal Shopper()
Pingback: Weekly Industry Roundup()
Pingback: Yahoo Ads Flash Vulnerability Been Exploited By Hackers — Security Gladiators()
Pingback: [MALWAREBYTES] Ιός μέσω των διαφημίσεων της Yahoo μολύνει εκατομμύρια υπολογιστές | S@fer-Internet.Gr()
Pingback: Yahoo Squashes Ads Infected by Malware - Provider Technology()
Pingback: Yahoo Squashes Ads Infected by Malware | WebSetNet()
Pingback: BlackHat 2015: RiskIQ reports huge spike in malvertising | Industry of It()
Pingback: SSL Malvertising Campaign Continues | Malwarebytes Unpacked()
Pingback: Yahoo Ad Network Targeted In Malvertising Attack Seeking Flash Vulnerability - Binary Option News()
Pingback: SSL Malvertising Campaign Continues | vyagers()
Pingback: My browser visited Weather.com and all I got was this lousy malware (Updated) | feedas TNA()
Pingback: Why I won’t browse the web without Adblockers Part XXIII: “I went to Weather.Com and all I got was this lousy malware” | Constantinople (Not Istanbul)()
Pingback: Yahoo Ads Infected With “Malvertisements” | Unicorn Riot()
Pingback: Gone in a Flash? HTML5 Leads the Way for Rich Ads | DAC Group()
Pingback: Hackers Exploit ‘Flash’ Vulnerability in Yahoo Ads - Techwebies()
Pingback: Stop ad injections with HTTPS connections or a VPN | High Tech News()
Pingback: Yahoo Ad Network Targeted In Malvertising Attack Seeking Flash Vulnerability - Binary Option News | Binary Option News()
Pingback: LUXURY ART | Huge malware campaign used Yahoo's ad network()
Pingback: La fin de Flash ? - Mistral Consulting()
Pingback: The end of Flash - Mistral Consulting()
Pingback: The End Of An Advertising Era: The End Of Flash | Dx3 Digest()
Pingback: Yahoo tackles large malicious ad campaign in its network | The Patriot()
Pingback: Angler Exploit Kit Strikes on MSN.com via Malvertising Campaign | Malwarebytes Unpacked()
Pingback: Why advertising can’t quit Flash - Webnesday()
Pingback: My browser visited Drudgereport and all I got was this lousy malware (Updated) | Ad Jet()
Pingback: Stop ad injections with HTTPS connections or a VPN - Q Wealth()
Pingback: Yahoo tackles large ‘malvertising’ campaign in its ad network | سيار - syiar()
Pingback: SSL Malvertising Campaign Targets Top Adult Sites | Malwarebytes Unpacked()
Pingback: Detonation | Riding Free()
Pingback: SSL Malvertising Campaign Targets Top Adult Sites - SecuritySlagsSecuritySlags()
Pingback: SSL Malvertising แคมเปญใหม่ พุ่งเป้าเว็บไซต์สำหรับผู้ใหญ่ | TechTalkThai()
Pingback: BILD Dir deine Meinung zu Adblockern - botfrei Blog()
Pingback: Malvertising Hits ‘The Daily Mail,’ One of the Biggest News Sites on the Web - Patriot Rising()
Pingback: Top 5 Recommendations to Avoid Malvertising()
Pingback: Advertising: Backdoor for Malware | Inside PageFair()
Pingback: You can be Hacked By Viewing a Webpage (Blog Post #6) | Cyberfluency()
Pingback: Why Everyone Needs Protection Against Malware()
Pingback: Hackers Exploit ‘Flash’ Vulnerability in Yahoo Ads | litelesite()
Pingback: Yahoo tackles big 'malvertising' campaign in its ad network | Wiki News Tech | Tech Hub For Techgig()
Pingback: Engadget Today » Hacker Lexicon: Malvertising, the Hack That Infects Computers Without a Click()
Pingback: Hacker Lexicon: Malvertising, the Hack That Infects Computers Without a Click | S4mpl3d()
Pingback: Hacker Lexicon: Malvertising, the Hack That Infects Computers Without a Click | Gadgetleader()
Pingback: Hacker Lexicon: Malvertising, the Hack That Infects Computers Without a Click (@wired) | OSINFO()
Pingback: Hacker Lexicon: Malvertising, the Hack That Infects Computers Without a Click - New Egypt()
Pingback: You say promoting, I say block that malware | Xenero()
Pingback: You say advertising, I say block that malware – ○○○○●○○○()
Pingback: You say promoting, I say block that malware | Word Wide News()
Pingback: You say advertising, I say block that malware | Lindauer Mac Consulting()
Pingback: Forbes makes visitors turn off their ad blockers, then infects their computers with malware – Enterprise Security Professional()
Pingback: Malvertising: what is it and how to browse safely - Security Curated()
Pingback: The state of the web 2016 - mobiForge()
Pingback: Ad Blocking: A Primer | TechCrunch()
Pingback: Ad Blocking: A Primer – SHOPATO()
Pingback: Ad Blocking: A Primer | KWOTABLE()
Pingback: Ad Blocking: A Primer | Gulf News Today()
Pingback: Ad Blocking: A Primer - Press TV News()
Pingback: Ad Blocking: A Primer – WeeklyTimesNews.com()
Pingback: Ad Blocking: A Primer -()
Pingback: Ad Blocking: A Primer » Peepstalks!()
Pingback: Ad Blocking: A Primer - Cool Tech Reviews()
Pingback: Ad Blocking: A Primer | mango outlet()
Pingback: Ad Blocking: A Primer | This Viral()
Pingback: Ad Blocking: A Primer | Rep News()
Pingback: Ad Blocking: A Primer | Viral World news()
Pingback: Ad Blocking: A Primer – Nigerian Herald()
Pingback: Ad Blocking: A Primer | Feedlesticks()
Pingback: Ad Blocking: A Primer | The H2O Standard()
Pingback: Ad Blocking: A Primer | World Updates()
Pingback: Ad Blocking: A Primer – pulsebell()
Pingback: » Ad Blocking: A Primer()
Pingback: Ad Blocking: A Primer | AkimoLux.com()
Pingback: Ad Blocking: A Primer | EuroMarket News()
Pingback: Ad Blocking: A Primer | TechPapa()
Pingback: Ad Blocking: A Primer • AppMarsh()
Pingback: 広告ブロック入門 | TechCrunch Japan()
Pingback: 広告ブロック入門 | まっちゃ by MIS()
Pingback: Hacker Lexicon: Malvertising, the Hack That Infects Computers Without a Click - Meta Thrunks Security Blog()
Pingback: Silencing dissent? IAB blocks Adblock Plus from internet advertising conference - Micro Penguin()
Pingback: Silencing dissent? IAB blocks Adblock Plus from internet advertising conference – Computerworld()
Pingback: Silencing dissent? IAB blocks Adblock Plus from internet advertising conference | Website Master Info()
Pingback: Silencing dissent? IAB blocks Adblock Plus from internet advertising conference | Tech News - Latest Tech, Gadgets & Science()
Pingback: Silencing dissent? IAB blocks Adblock Plus from internet advertising conference | All About Tech in News()
Pingback: Silencing dissent? IAB blocks Adblock Plus from internet advertising conference - AdTrustMedia Blog()
Pingback: 广告拦截:广告业美好未来的奠基者 | TechCrunch 中国()
Pingback: 广告拦截:广告业美好未来的奠基者 | 23Seed()