Hacked advertising platform sent users to the Nuclear exploit kit

The company affected, Mad Ads Media, was quick to investigate, Trend Micro said

A suspected malicious advertising attack turned out to be a much deeper compromise of an online advertising company, according to Trend Micro.

The security company found that advertisements served by Mad Ads Media, based in Mount Laurel, New Jersey, redirected to websites hosting an exploit kit, which probed users' computers for software flaws in order to deliver malware. The number of people affected peaked at 12,500 on May 2, Trend said.

At first, the incident appeared to be another example of malvertising, wrote Joseph Chen, a fraud researcher with Trend. Advertising networks have occasionally seen malicious ads uploaded to their networks that redirect people to other malicious websites.

A closer examination found that a Mad Ads Media server used to deliver advertisements had been modified, specifically a JavaScript library which assigns advertisements to a particular site. Instead, the library was coded to redirect users to servers hosting the Nuclear exploit kit, Chen wrote.

The websites that were targeted for redirection had manga and anime content. Mad Ads Media serves more than 10,000 websites worldwide and delivers eight billion ad impressions, according to its website.

Mad Ads Media officials could not be immediately reached for comment, but Chen wrote the company "was quick to investigate and take action."

If a user is redirected to the Nuclear exploit kit, it attempts to see if their browser is running an outdated version of Adobe Systems' Flash multimedia program. If that attack was successful, the infamous Carberp malware was installed, which is designed to steal authentication credentials.

Although ad companies try to filter malicious ones out, hackers will often swap out ads that have passed a security check for ones that haven't in the hope that the company won't catch it. Such attacks can be very productive, as a malicious ad displayed on several high-profile sites can mean a greater pool of potential victims.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Show Comments

Latest Videos

Conversations over a cuppa with CMO: Craig Davis

​Leadership resilience, startups scaling up, marketing best practices, customer insights - these are just a few of the topics we manage to explore in the latest episode of Conversations over a Cuppa with CMO featuring Craig Davis.

More Videos

Was really informative. Customer retention is very important for companies as retaining customers are simpler compared to making new ones...

Bhooshan Shetty

What lies ahead for the future of marketing post-AI

Read more

Good day sir / madamWe CLOSED JOINT-STOCK COMPANY AO KAYUM NEFT OIL COMPANY is one of theleading Oil & Gas trading companies in Russi...

BARYBKIN ALEXANDER ALEXANDROVI

3-pronged marketing approach for property disruptor Brickx

Read more

Good day sir / madamWe CLOSED JOINT-STOCK COMPANY AO KAYUM NEFT OIL COMPANY is one of theleading Oil & Gas trading companies in Russi...

BARYBKIN ALEXANDER ALEXANDROVI

Oath to fully acquire Yahoo7 from Seven West Media

Read more

Thank you for sharing your knowledge. Definitely bookmarked for future reading! Check this website https://a2designlab.com/ with lots of ...

Ryota Miyagi

Brene Brown: What it takes to be a brave leader right now

Read more

Well said! It is high time to look into the cultural values and beliefs of the audience before serving with the ads. If it is against the...

Praveen Kumar

The X factor in multicultural media planning and buying - Digital advertising - CMO Australia

Read more

Blog Posts

Life beyond the cookie: 5 steps to mapping the future of marketing measurement

​There’s no denying there’s been a whirlwind of response to the imminent demise of the third-party cookie from all parts of the industry. But as we’ve collectively come to better understand the implications, it’s clear this change is giving the digital advertising industry the opportunity to re-think digital marketing to support core industry use cases, while balancing consumer privacy.

Natalie Stanbury

Director of research, IAB Australia

Ensuring post-crisis success

The COVID-19 pandemic has exposed brands’ CX shortcomings and a lack of customer understanding. Given ongoing disruption, customer needs, wants and expectations are continually changing, also causing customers to behave in different ways. Just look at hoarding toilet paper, staple and canned food, medicinal and cleaning products.

Riccardo Pasto

senior analyst, Forrester

A few behavioural economics lesson to get your brand on top of the travel list

Understanding the core principles of Behavioural Economics will give players in the travel industry a major competitive advantage when restrictions lift and travellers begin to book again. And there are a few insights in here for the rest of the marketing community, too.

Dan Monheit

Co-founder, Hardhat

Sign in