Hacked advertising platform sent users to the Nuclear exploit kit

The company affected, Mad Ads Media, was quick to investigate, Trend Micro said

A suspected malicious advertising attack turned out to be a much deeper compromise of an online advertising company, according to Trend Micro.

The security company found that advertisements served by Mad Ads Media, based in Mount Laurel, New Jersey, redirected to websites hosting an exploit kit, which probed users' computers for software flaws in order to deliver malware. The number of people affected peaked at 12,500 on May 2, Trend said.

At first, the incident appeared to be another example of malvertising, wrote Joseph Chen, a fraud researcher with Trend. Advertising networks have occasionally seen malicious ads uploaded to their networks that redirect people to other malicious websites.

A closer examination found that a Mad Ads Media server used to deliver advertisements had been modified, specifically a JavaScript library which assigns advertisements to a particular site. Instead, the library was coded to redirect users to servers hosting the Nuclear exploit kit, Chen wrote.

The websites that were targeted for redirection had manga and anime content. Mad Ads Media serves more than 10,000 websites worldwide and delivers eight billion ad impressions, according to its website.

Mad Ads Media officials could not be immediately reached for comment, but Chen wrote the company "was quick to investigate and take action."

If a user is redirected to the Nuclear exploit kit, it attempts to see if their browser is running an outdated version of Adobe Systems' Flash multimedia program. If that attack was successful, the infamous Carberp malware was installed, which is designed to steal authentication credentials.

Although ad companies try to filter malicious ones out, hackers will often swap out ads that have passed a security check for ones that haven't in the hope that the company won't catch it. Such attacks can be very productive, as a malicious ad displayed on several high-profile sites can mean a greater pool of potential victims.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Show Comments

Blog Posts

Is artificial intelligence riddled with bias?

The purpose of Artificial Intelligence (AI) has always been to replace the menial and repetitive tasks we do each day in every sector, so that we can concentrate on doing what we do best. Saving time and money has certainly been a decent outcome as AI infiltrates the business landscape, however, now we are starting to see problems that cause major issues in practice.

Katja Forbes

Founder and chief, sfyte

5 things every business can do to drive brand loyalty

If you’re in any customer-centric role, you’ll likely be familiar with the Net Promoter Score (NPS) – one of the most popular tools for brands to measure their customer sentiment.

Catherine Anderson

Chief customer officer, Powershop Australia

What the modern gig economy is doing to customer experience

Most marketing theory was established in the context of stable employment relationships. From front-line staff to marketing strategists and brand managers, employees generally enjoyed job security with classic benefits such as superannuation plans, stable income streams, employment rights, training, sabbaticals and long-service leave.

Dr Chris Baumann

Associate professor, Macquarie University

Thank you! That was useful to know.

Belia Adam

Why your best social marketing brand tool could be hiding in plain sight

Read more

Because you are missing the point of the term "disruption"

Sean

Uber for the truckies: How one Aussie startup is disrupting the freight industry

Read more

Absolutely agree with this ... Facebook doesn't care what adds they show. You report an add for fake news/scam and it just remains "open...

Quasi Carbon

Unilever CMO threatens Facebook, Google with digital advertising boycott

Read more

How to create Pinball game in 4 minshttps://youtu.be/S1bsp7del3M

Alex Atmavan

Rethinking gamification in marketing

Read more

True Local - one of the least credible review sites on the entire internet.

MyNameIsStomp

Former Virgin Mobile CMO and CEO joins oOh! as first customer chief

Read more

Latest Podcast

More podcasts

Sign in