Forum Moderators: open

Message Too Old, No Replies

Ad Malware: MSN, BBC.com, the New York Times, AOL, Newsweek, and more

         

engine

12:48 pm on Mar 16, 2016 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Ads with a payload have been carried on major sites, including MSN, BBC.com, the New York Times, AOL, Newsweek and several others.
It seems its stems from a failure to renew a domain name which was originally a carrier of legitimate adverts. The domain was snapped up and used to deliver malware loaded ads to these networks.

The ad networks involved have been informed about the malicious adverts they are inadvertently supplying. Some have already taken steps to stop the malicious adverts popping up.

Anyone clicking on a malicious advert was taken to a separate page that attempted to infect them with either a variant of ransomware known as Cryptowall, or a trojan that gave attackers remote access to their computer. Both attacks only worked against Windows computers. Ad Malware: MSN, BBC.com, the New York Times, AOL, Newsweek, and more [bbc.co.uk]

RhinoFish

5:26 pm on Mar 16, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Because somebody didn't auto-renew a domain name, sheesh, let's make it a little harder for the bad guys to win.

tangor

12:02 am on Mar 17, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Sounding like a broken record: Install an ad blocker. (sigh)

mcneely

3:03 am on Mar 17, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Microsoft Windows


*rolls eyes real hard*

engine

9:28 am on Mar 17, 2016 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



The domain name issue, if it's as simple as forgetting to renew, is a stupid one.

It's typical that the target was Microsoft's OS, and it's popularity makes it an instant target. The vulnerability comes through add ons, such as Flash.

As i'd said previously, the sooner Flash is ditched the better, imho.

tangor

10:14 am on Mar 17, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



a domain name which was originally a carrier of legitimate adverts


Key issue. Can't trust the advert guys and gals (or all those other trans not sexual many sexual etc).

Grow your own. Do it yourself. VET ALL ADS and serve those YOURSELF. Make more bucks, avoid ad blockers, and NEVER serve malvertising. G and the like are not going to do the grunt work. Takes dollars off their bottom line.

We live in a new world, kiddies.