Hacked advertising platform sent users to the Nuclear exploit kit

The company affected, Mad Ads Media, was quick to investigate, Trend Micro said

A suspected malicious advertising attack turned out to be a much deeper compromise of an online advertising company, according to Trend Micro.

The security company found that advertisements served by Mad Ads Media, based in Mount Laurel, New Jersey, redirected to websites hosting an exploit kit, which probed users' computers for software flaws in order to deliver malware. The number of people affected peaked at 12,500 on May 2, Trend said.

At first, the incident appeared to be another example of malvertising, wrote Joseph Chen, a fraud researcher with Trend. Advertising networks have occasionally seen malicious ads uploaded to their networks that redirect people to other malicious websites.

A closer examination found that a Mad Ads Media server used to deliver advertisements had been modified, specifically a JavaScript library which assigns advertisements to a particular site. Instead, the library was coded to redirect users to servers hosting the Nuclear exploit kit, Chen wrote.

The websites that were targeted for redirection had manga and anime content. Mad Ads Media serves more than 10,000 websites worldwide and delivers eight billion ad impressions, according to its website.

Mad Ads Media officials could not be immediately reached for comment, but Chen wrote the company "was quick to investigate and take action."

If a user is redirected to the Nuclear exploit kit, it attempts to see if their browser is running an outdated version of Adobe Systems' Flash multimedia program. If that attack was successful, the infamous Carberp malware was installed, which is designed to steal authentication credentials.

Although ad companies try to filter malicious ones out, hackers will often swap out ads that have passed a security check for ones that haven't in the hope that the company won't catch it. Such attacks can be very productive, as a malicious ad displayed on several high-profile sites can mean a greater pool of potential victims.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Error: Please check your email address.
Show Comments

Blog Posts

How challenger brands can win at biddable media

Challenger brands, especially in highly competitive markets, generally can’t match established players for media spend.

Chris Pittham

Managing director, Jaywing

The competitive advantage Australian retailers have over Amazon

With all of the hype around Amazon, many online retailers have been trying to understand how they can compete with the American retail giant.

Joel Milligan

Performance manager, Columbus Agency

How to become the customer experience custodian

The number one objective enterprises give for embarking on a digital transformation is to improve customer experiences with new engagement models, according to IDC’s 2017 global study.

Insightful article from an AdTech perspective

Mehdi Partika

Predictions 2018: 5 ways the CMO role will change

Read more

Sounds like a bunch of convoluted business bullshit with no real substance or value. Business people deluding themselves into thinking th...

Bupa Customer

Best CX Companies List profiles: Bupa's Voice of the Customer project

Read more

This partnership seems to bring a lot of benefits.

Uk Driver

Deloitte announces new agency partnership to expand digital reality capabilities

Read more

It's all about the experience and it seems that understanding is finally full tilt!

Danny Mack

Building a robust digital customer experience

Read more

I am going to visit Australia))) nice place ... one of the most attractive

Carly Julia

Tourism Australia aims for youth travel market with dedicated news channel

Read more

Latest Podcast

More podcasts

Sign in