Hacked advertising platform sent users to the Nuclear exploit kit

The company affected, Mad Ads Media, was quick to investigate, Trend Micro said

A suspected malicious advertising attack turned out to be a much deeper compromise of an online advertising company, according to Trend Micro.

The security company found that advertisements served by Mad Ads Media, based in Mount Laurel, New Jersey, redirected to websites hosting an exploit kit, which probed users' computers for software flaws in order to deliver malware. The number of people affected peaked at 12,500 on May 2, Trend said.

At first, the incident appeared to be another example of malvertising, wrote Joseph Chen, a fraud researcher with Trend. Advertising networks have occasionally seen malicious ads uploaded to their networks that redirect people to other malicious websites.

A closer examination found that a Mad Ads Media server used to deliver advertisements had been modified, specifically a JavaScript library which assigns advertisements to a particular site. Instead, the library was coded to redirect users to servers hosting the Nuclear exploit kit, Chen wrote.

The websites that were targeted for redirection had manga and anime content. Mad Ads Media serves more than 10,000 websites worldwide and delivers eight billion ad impressions, according to its website.

Mad Ads Media officials could not be immediately reached for comment, but Chen wrote the company "was quick to investigate and take action."

If a user is redirected to the Nuclear exploit kit, it attempts to see if their browser is running an outdated version of Adobe Systems' Flash multimedia program. If that attack was successful, the infamous Carberp malware was installed, which is designed to steal authentication credentials.

Although ad companies try to filter malicious ones out, hackers will often swap out ads that have passed a security check for ones that haven't in the hope that the company won't catch it. Such attacks can be very productive, as a malicious ad displayed on several high-profile sites can mean a greater pool of potential victims.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Show Comments

Blog Posts

Non-linear transformation: The internal struggle

Let’s face it, transformation is messy. Every business is different, with a set of specific challenges based on a mixture of external (the market, competitors, regulation) and internal factors (technology, people and process investments over time).

Neil Kelly

Partner, transformation, Wunderman Thompson

7 ways to champion a human centred design culture

Human Centred Design (HCD) has come a long way in the last decade with many forward-thinking organisations now asking for HCD teams on their projects. It’s increasingly seen as essential to unlocking innovation, driving superior customer experiences and reducing delivery risk.

Shane Burford

Head of research and design, RXP Group

Building a human-curated brand

If the FANG (Facebook, Amazon, Netflix, Google) sector and their measured worth are the final argument for the successful 21st Century model, then they are beyond reproach. Fine-tuning masses of algorithms to reduce human touchpoints and deliver wild returns to investors—all with workforces infinitesimally small compared to the giants of the 20th Century—has been proven out.

Will Smith

Co-founder and head of new markets, The Plum Guide

It's a useful info for small businesses owners. We can't live without mobile apps. They are so helpful! It's hard to deny that.

Mae Davis

7 ways small businesses can benefit from mobile apps

Read more

Hi Jennifer,Fascinating read about design-led companies!If you would like to learn more, our Design Thinking and Innovation programme mig...

Andrea Foster

How to spot a ‘design-led’ versus ‘design-fed’ company

Read more

ABC web-site not easy to use/navigate. Even getting this far in sign-on to ABC My Space was problematic - it was asking for my password,...

Vee.

How the ABC used an online community to help build a movement

Read more

Thank you for your feedback, Astha! Always appreciated.

Vanessa Skye Mitchell

5 things marketers should know about data privacy in 2020

Read more

Hey Vanessa, thanks for providing us the things marketers should know about data privacy. This was really an informative post.

astha sharma

5 things marketers should know about data privacy in 2020

Read more

Latest Podcast

More podcasts

Sign in