Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Malvertising Campaigns - Who can you trust? current page
Link copied

Malvertising Campaigns - Who can you trust?

Oct 20, 2017
Author:
James Maude Headshot 2024
James Maude
Field Chief Technology Officer
Blog banner default
Malvertising Campaigns - Who can you trust?
James Maude Headshot 2024
James Maude
Field Chief Technology Officer

Malware is an ever evolving field and as such security should be seen as a journey not a destination. One of the latest malware evolutions is the practice of Malvertising where attackers place malicious content in seemingly innocent adverts. When the user views the page the advert is loaded and the malware attempts to exploit the machine.

Why Malvertising?

There are a few advantages for the attacker over phishing emails or websites. As the adverts are often displayed on well-known websites the attackers can wait for victims to come to them. They can also exploit the users in the popular website to push fake updates and malware to the user. The attackers can remain anonymous, hiding behind the 3rd party ad-networks that buy and sell advertising space on websites. In more recent cases attackers use the marketing tools created by ad-networks to target specific demographics or industries.

Where are the attacks?

Throughout 2014 several major websites including yahoo.com, java.com and youtube.com have all been hit by malvertising campaigns.

Huffington post targeted by malvertising campaign

One recent high profile example targeted the popular news site The Huffington Post. On the 31st of December researchers noticed the Canadian version of the site www.huffingtonpost.ca was infected, this was followed in early January by the main US site www.huffingtonpost.com. The source of the infection was traced to an advert on the AOL ad-network (advertising.com) which redirected to a Flash exploit and VB Script that silently downloaded and ran malware on the victim's machine.

Your computer has been locked

In this case the malware dropped was Kovter a type of ransomware that attempts to lock the computer until a "fine" has been paid for viewing illegal material. The malware uses geolocation to tailor the ransom message to the local law enforcement using FBI and police logos.

This recent campaign was estimated to be generating upwards of $25,000 of revenue per day for the attackers, with little chance of retribution. With this kind of revenue we can expect to see many more of these attacks throughout 2015.

What's the answer?

From the website owners point of view this is tricky, they rely on the income that advertising generates in order to survive. Ultimately the ads served up on their pages are out of their control and they are at the mercy of ad-networks. The ad-networks do attempt to screen content, however as they don't host the adverts criminals can redirect or swap out the ad after it has been screened.

As the problem will ultimately land on the endpoint we should start there. Keeping endpoints fully patched and using modern browsers can help prevent common attacks that exploit known vulnerabilities. However this only works against known threats, to deal with 0 days and more advanced attackers we need to look to a proactive defense in depth strategy.

Evidence suggests that to combat increasingly complex attack vectors, organizations need to adopt a layered strategy that prioritizes high-impact solutions, such as privilege management, application control and sandboxing. This proactive approach means you mitigate the risk of being caught out by the next malware campaign.

To find out more about proactive Defense in Depth solutions visit www.avecto.com or talk to one of our advisors.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • IoT Bots Cause Massive Internet Outage October 21st, 2016
    Oct 24, 2016 IoT Bots Cause Massive Internet Outage October 21st, 2016
    Blog
    1m
  • IT Security Conferences Showcase a Sea of Vendors--But How Do You Cut Through the Hype?
    Mar 28, 2019 IT Security Conferences Showcase a Sea of Vendors--But How Do You Cut Through the Hype?
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.