Hacked advertising platform sent users to the Nuclear exploit kit

The company affected, Mad Ads Media, was quick to investigate, Trend Micro said

A suspected malicious advertising attack turned out to be a much deeper compromise of an online advertising company, according to Trend Micro.

The security company found that advertisements served by Mad Ads Media, based in Mount Laurel, New Jersey, redirected to websites hosting an exploit kit, which probed users' computers for software flaws in order to deliver malware. The number of people affected peaked at 12,500 on May 2, Trend said.

At first, the incident appeared to be another example of malvertising, wrote Joseph Chen, a fraud researcher with Trend. Advertising networks have occasionally seen malicious ads uploaded to their networks that redirect people to other malicious websites.

A closer examination found that a Mad Ads Media server used to deliver advertisements had been modified, specifically a JavaScript library which assigns advertisements to a particular site. Instead, the library was coded to redirect users to servers hosting the Nuclear exploit kit, Chen wrote.

The websites that were targeted for redirection had manga and anime content. Mad Ads Media serves more than 10,000 websites worldwide and delivers eight billion ad impressions, according to its website.

Mad Ads Media officials could not be immediately reached for comment, but Chen wrote the company "was quick to investigate and take action."

If a user is redirected to the Nuclear exploit kit, it attempts to see if their browser is running an outdated version of Adobe Systems' Flash multimedia program. If that attack was successful, the infamous Carberp malware was installed, which is designed to steal authentication credentials.

Although ad companies try to filter malicious ones out, hackers will often swap out ads that have passed a security check for ones that haven't in the hope that the company won't catch it. Such attacks can be very productive, as a malicious ad displayed on several high-profile sites can mean a greater pool of potential victims.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Show Comments

Blog Posts

How to create profitable pricing

How do we price goods and services? As business leaders, we have asked ourselves this question since the history of trading.

Lee Naylor

Managing partner, The Leading Edge

Sport and sponsorship: The value of event sponsorship

Australia’s cricketers captured the nation’s attention during their recent run to the semi-final of the ICC Men’s World Cup. While the tournament ultimately ended in defeat, for over a month it provoked a sense of belonging, hope and empowerment for millions of people across Australia. Cricket, and sport in general, has a near-unique ability to empower individuals, irrelevant of their background, demographic or nationality.

Nikhil Arora

Vice-president and managing director, GoDaddy India

AI ethics: Designing for trust

As artificial intelligence (AI) becomes much more prevalent and increasingly a way of life, more questions are being asked than answered about the ethical implications of its adoption.

Katja Forbes

Founder and chief, sfyte

I spend a lot of time in my professional life as a provider of marketing solutions trying to persuade customers that CX, UX, UI and Custo...

sketharaman

Gartner VP: Why CMOs and CIOs must band together to make CX a discipline

Read more

I live the best deals at LA Police Gear.

Tyrus Rechs

6 Ways to ramp up Social Media to Your Web Design

Read more

Its absolute over priced acquisition. The CEO, must be fired for this all cash transaction. Absolutely no justification for prospective P...

about_face

Analysts question long-term play of SAP's acquisition of Qualtrics

Read more

Very well written Nikhil! Indeed this is a big ticket investment, but the impact on brand, sales and employee motivation should make it w...

Yugal Sachdeva

Sport and sponsorship: The value of event sponsorship

Read more

As someone with both experience in marketing and working with UiPath both, I can say that I cannot wait to see more marketing processes u...

CiGen RPA

What robotic process automation can do for marketers

Read more

Latest Podcast

More podcasts

Sign in