< ciso
brief />
Tag Banner

All news with #malvertising tag

61 articles

DecryptAds reveals who’s tracking you online

🔍 DecryptAds is a free service that scrapes and correlates public adtech files (ads.txt, app-ads.txt, buyers.json, sellers.json) to reveal which companies can run ads or harvest data from websites and apps. The site presents consolidated profiles, legal dossiers, and geo-risk warnings to help researchers and security teams trace malvertising, ad fraud, and opaque ad-supply chains. Its API and quiet-removals feed enable automation and visibility into removed sellers and reseller relationships.
read more →

Adform ad platform compromise enabled crypto theft

🛡️ Adform, a major ad-serving platform, was compromised for about 24 hours from late July 26 to the evening of July 27, allowing attackers to inject malicious JavaScript into ads that monitored clipboard contents and swapped copied cryptocurrency wallet addresses with the attacker’s addresses. The injected code collected site and IP data and targeted Bitcoin, Ethereum, and Tron addresses. Adform remediated the issue, and the incident highlights the persistent risk of malvertising and the need for users to block ads and use layered protections. The company has not disclosed how the breach occurred or how many users were affected.
read more →

Adform ad script tampering swaps crypto wallet addresses

🔍 Attackers modified Adform's JavaScript advertising resource to rewrite cryptocurrency wallet addresses in visitors' browsers. Adform discovered the issue on July 27, 2026, removed the malicious code, notified clients, and urged users to clear caches and verify wallet addresses before sending funds. The compromised file, trackpoint-async.js served from s2.adform.net, contained two appended payloads that intercepted clipboard and form input events to replace Bitcoin, Ethereum, and Tron addresses.
read more →

Ad fraud and proxy risk in generic TV streaming sticks

🛡️ Security researchers uncovered that inexpensive, off‑brand TV streaming sticks not only run residential proxy software but also impersonate mobile phones to click ads on AI‑generated sites. Bitsight TRACE researcher Pedro Falé analyzed telemetry from an expired domain tied to H96 devices and found apps linked to Zhejiang Fengwo IoT Technology that coordinate ad‑fraud campaigns. These devices switch roles between proxying traffic when in use and executing ad‑clicking jobs when idle, enabling large‑scale monetization and deceptive marketing claims.
read more →

Malvertising group builds malware inside victim browsers

🛡️ SourTrade, an active malvertising operation since 2024, is concealing its malware assembly inside victim browsers to evade detection. Researchers at Confiant found the campaign impersonates trading and crypto platforms to lure victims with tips and giveaways. Rather than delivering a complete binary, SourTrade sends assembly instructions and clean components that the browser combines in memory to form the final infostealer payload. This in-memory build avoids network fingerprinting and appears as legitimate downloads to security tools.
read more →

Malvertising builds malware in browser memory

🛡️ A widespread malvertising campaign uses fake Solana, Luno, and TradingView pages with malicious JavaScript that assembles malware directly in the browser's memory. The operation, active since late 2024 across 12 countries, filters out researchers and scanners while delivering customized payloads to retail traders and crypto investors. Confiant found the pages register service and shared workers to piece together a unique executable from remote components and local bytes, avoiding transmission of a finished file to evade detection.
read more →

Insurance Phishing Evolves into Real-Time Account Hijacks

🔍 Recent research shows insurance-targeted phishing has shifted from credential harvesting to real-time session hijacking. Attackers use paid Google Ads and disposable hosting to lure victims to realistic portals and then relay OTPs and credentials to authenticate on the legitimate service while the victim is logged in. CTM360 identified a bespoke kit, InsureOTP Kit, and exposed backend infrastructure revealing live session management and operator workflows. Defenders must expand detection beyond malicious pages to include ad monitoring, infrastructure analysis, and attacker workflow intelligence.
read more →

OnlyFans DMCA Requests Reveal Compromised Domains

🔎 Armed with copyright law and internet scanning, OnlyFans creators and specialized vendors have been using DMCA takedowns to identify and remove unauthorized adult-content listings that appear on high-authority government and education websites. By tracking requests in Google’s Transparency Report and the Lumen database, researchers mapped thousands of compromised .gov and .edu domains used by traffic distribution systems (TDS) and parasite SEO. This trend has grown rapidly since 2020 as decentralized content ownership increased detection coverage and vendor capabilities.
read more →

Malicious Steam Workshop wallpapers used to deliver malware

🛡️ Researchers at Kaspersky report threat actors abusing Steam Workshop to distribute malware via the Wallpaper Engine app. Attackers upload malicious application-type wallpapers that execute payloads when installed, leading to account theft, backdoors, miners, and information stealers. Valve removed the identified items, but users are advised to only download from trusted creators and scan Workshop content with up-to-date antivirus.
read more →

Sniper Dz phishing scam targets MENA users

🛡️ Group-IB disclosed a large-scale fraud campaign using fake Facebook accounts to lure Middle East and North Africa users with offers like free mobile internet and government subsidies. Victims were routed via link-aggregation services to pages that abused browser notifications, back-button hijacks, and tab-under redirects to enroll users in a push-notification ecosystem. The operation monetized victims through premium SMS, premium-rate calls, investment scams, and ad fraud tied to a Sniper Dz PhaaS infrastructure.
read more →

Attackers Use Short-Form Videos to Spread Vidar Stealer

🎯 New research from ReversingLabs reveals threat actors are using TikTok and Instagram Reels to distribute the Vidar infostealer by posing as tutorials for unlocking premium software. Campaigns manipulate platform algorithms to boost saves and shares, driving viewers to lookalike domains that deliver Vidar via PowerShell or gateware-filled download sites. ReversingLabs recommends auditing install privileges and expanding phishing training to include social feeds.
read more →

Threat actors exploit AI branding in social engineering

🛡️ Microsoft Threat Intelligence describes campaigns that impersonate popular AI platforms such as ChatGPT, Copilot, and Claude to lure victims via phishing, malvertising, and SEO abuse. These operations use trusted branding, redirect chains, and urgency-driven messaging to steal credentials, commit fraud, or deliver malware. The blog emphasizes abuse of brand names rather than service compromise and recommends leveraging AI-powered security for detection and response.
read more →

FlutterShell macOS backdoor spreads via malvertising

🛡️ Palo Alto Networks Unit 42 uncovered Operation FlutterBridge, a macOS malvertising campaign distributing a Flutter-built backdoor called FlutterShell. The campaign links to a cluster known as JSCoreRunner/FileRipple and an actor tracked as CL-CRI-1089, active since at least 2023. FlutterShell uses WebView and a JavaScript-to-native bridge to load malicious logic from attacker-controlled sites, supports command execution, file manipulation, and exfiltration, and has multiple evolving variants that passed Apple notarization.
read more →

Typosquatting: Runtime Risks in Third-Party Web Scripts

🛡️ Attackers are embedding AI-generated lookalike domains inside legitimate third-party scripts, transforming typosquatting from a user mistake into a browser-runtime threat that traditional controls miss. Firewalls, WAFs, EDR, and CSPs cannot observe what approved scripts do once executed, enabling silent exfiltration as in the Trust Wallet compromise. Effective detection needs runtime behavioral monitoring that traces script actions, network calls, and deviations from established baselines rather than relying on static vetting.
read more →

Trapdoor Android Ad-Fraud Chain Fuels Malvertising

🔍 Researchers at HUMAN's Satori Threat Intelligence team disclosed "Trapdoor," a multi-stage Android ad fraud and malvertising operation involving 455 malicious apps and 183 threat actor-owned C2 domains. The campaign used utility-like apps to trick users into installing secondary apps that launch hidden WebViews, load HTML5 cashout domains, and perform automated touch-fraud. At its peak Trapdoor generated about 659 million bid requests per day, drove over 24 million app installs—mostly from U.S. traffic—and Google removed the identified apps after disclosure.
read more →

Malvertising: Claude.ai Shared Chats Deliver Mac Malware

⚠️ Attackers are using Google Ads to direct macOS users to malicious instructions hosted inside Claude.ai shared chats. The chats disguise themselves as official installation guides and prompt users to paste Terminal commands that download compressed shell scripts and execute them in memory. Some variants profile victims (including keyboard locale) before running a second-stage payload via osascript, while others immediately steal browser credentials, cookies, and Keychain items. Avoid pasting terminal commands and visit the official site directly.
read more →

Singer Loses Life Savings to Fake Ledger Live App Download

🚨 Garrett Dutton (G. Love) says he downloaded a counterfeit Ledger Live app from Apple's App Store while setting up a new computer and was tricked into entering his seed phrase. Thieves used it to steal 5.9 BTC (about $440,000). Apple removed the fraudulent app on April 12 after investigators linked it to roughly $9.5 million stolen from more than 50 victims. Legitimate wallets never ask for your seed phrase; verify developer names and ratings and be especially cautious when installing apps on new devices.
read more →

Google updates Play policies to tighten contacts, location

🔒 Google announced Play policy updates to restrict contact and location permissions and to strengthen app ownership protections, while reporting it blocked or removed over 8.3 billion ads and suspended 24.9 million accounts in 2025. The update introduces a standardized Contact Picker and a one‑time precise location button in Android 17, and urges developers to remove broad READ_CONTACTS usage. Google also added a native account transfer feature and said its Gemini AI is detecting and preemptively blocking malvertising at scale.
read more →

Google Expands Gemini Use to Combat Malicious Ads at Scale

🛡️ Google says it now relies heavily on Gemini AI to detect and block malicious ads across its advertising platforms, reporting 8.3 billion ads blocked or removed and 24.9 million advertiser account suspensions in 2025, including 602 million scam-related ads. Gemini analyzes billions of signals—beyond simple keywords—such as advertiser behavior, account history, campaign patterns, and intent to identify threats. The company reports faster processing of user reports and an 80% reduction in incorrect advertiser suspensions, and it plans to extend Gemini-driven, submission-time reviews to more ad formats.
read more →

Over 100 Chrome Extensions Steal Accounts and Data

🔒 Researchers at Socket have discovered more than 100 malicious Chrome extensions in the official Web Store that harvest Google OAuth2 bearer tokens, hijack sessions, deploy backdoors, and conduct ad fraud. The extensions were published under multiple publisher identities and span categories such as Telegram sidebars, games, video enhancers, translation tools, and utilities. Socket links the campaign to a centralized command-and-control backend hosted on a Contabo VPS and notes code comments that suggest a Russian malware-as-a-service operation. Users are urged to check installed extensions against the IDs Socket published and remove any matches immediately.
read more →