Categories: Cyber CrimeMalware

Malvertising, HuffingtonPost was serving Malware via AOL Ad-Network

Security company Cyphort has discovered a malvertising campaign that targeted several websites via AOL Ad-Network, including the Huffington Post.

Security experts at Cyphort firm discovered a new malvertising campaign that hit numerous websites, including the Huffington Post and LA Weekly. The attackers exploited the AOL ad network to run the malicious campaign, Cyphort detected the attacks for the first time on Dec. 31 against the Canadian version of Huffington Post (huffingtonpost.ca), then on Huffingtonpost.com on Jan. 3. Cyphort notified AOL of the alarming discovery and the attacks stopped on Jan. 5.websites including Huffington Post and LA Weekly. The attackers exploited the AOL ad network to run the malicious campaign, Cyphort detected the attacks for the first time on Dec. 31 against the Canadian version of Huffington Post (huffingtonpost.ca), then on Huffingtonpost.com on Jan. 3. Cyphort notified AOL of the alarming discovery and the attacks stopped on Jan. 5.huffingtonpost.ca), then on Huffingtonpost.com on Jan. 3. Cyphort notified AOL of the alarming discovery and the attacks stopped on Jan. 5.

“In this case all the malicious ads came via advertising networks that belong to AOL,” said Nick Bilogorskiy, director of security research at Cyphort. “We don’t know exactly how it got there. When we consulted our logs we… [saw] the issue started in late October. So, one possibility is that AOL itself has been breached. Another possibility is that attackers are submitting the malicious ads and have AOL approving these ads for use in the ad network.”

According to details provided by Cyphort on the infection, the ad redirected users through multiple hops. The landing page served an exploit kit which uses a Flash exploit  and a VB script that downloads the Kovter Trojan executable to %temp%.

The researchers suspect that the exploit kit served by the cyber criminals could be the Neutrino kit or the Sweet Orange kit.

The experts at Cyphort considered parliculary interesting the use of HTTPs and HTTPS to masquerade the servers used by the attackers, which adopted a specific HTTPS redirector hosted on a Google App Engine page.

“Interestingly attackers used a mix of HTTP and HTTPS redirects to hide the servers involved in this attack. The HTTPS redirector is hosted on a Google App Engine page. This makes analysis based on traffic PCAPs more difficult, because HTTPS traffic is encrypted.” states a blog post published by Cyphort.

In addition to the advertising.com advertising network, the attackers have also used the “adtech.de” platform, both serviceservice

http www.huffingtonpost.ca
http o.aolcdn.com
http atwola.com
http tacoda.net
http advertising.com
https nomadic-proton-777.appspot.com [Google App Engine]
http foxbusness.com
http multiple .PL redirects
http howto.sxcubelabs.nysa.pl:8080/phppgadmin/

Different malicious scripts were executed with different ads from advertising.com.

“When user opens [the] Huffington Post web site, several scripts are executed from the advertising network to show ads. One of these scripts loads an external function through HTTPS from Google AppSpot, and this function loads another redirect through HTTPS. And only then the user receives redirects to malware payload. It makes it harder to analyze the origin of attack because even if a security company has the recorded network traffic it is impossible to decrypt and reconstruct the origin of the malware redirect.” said Bilogorskiy. 

The experts at Cyphort speculate that the hacking crew behind the attack has compromised several .pl domains in Poland, and it used related sub-domains to redirect the traffic.

“The ad networks get millions of ads submitted to them and any one of those could be malvertising,” Bilogorskiy said. “They try to detect and filter malicious ads from their systems, but it is challenging. The potential damage is high, as ad networks have a very deep reach and can infect many people quickly.”

“The attackers are accustomed to tricking the networks by making “armored” malverts, where they use various techniques to appear legitimate to the analysts, but infect the users nonetheless,” he continued. “For instance they will enable the malicious payload after a delay of several days after the ad is approved. Another way is to only serve the exploits to every 10th user, or every 20th user who views the ad. Verifying user agents and IP addresses also is a common strategy to hide from analysts and automated malware detection.  The attackers can implement various targeting strategies for malware infection, which appear normal in the context of advertisement, but in effect evade certain security detection.”

Malversting campaigns rely on compromised machines, to mitigate the threat it is recommended the website administrators to carefully inspect their platforms searching for malicious code or evidence of any suspicious activity (i.e. Traffic redirection).

Pierluigi Paganini

(Security Affairs –  AOL, Malversting campaign)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalog

CISA adds Cisco ASA and FTD and CrushFTP VFS vulnerabilities to its Known Exploited Vulnerabilities…

10 hours ago

CISA adds Microsoft Windows Print Spooler flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA added the Windows Print Spooler flaw CVE-2022-38028 to its Known Exploited Vulnerabilities catalog.…

17 hours ago

DOJ arrested the founders of crypto mixer Samourai for facilitating $2 Billion in illegal transactions

The U.S. Department of Justice (DoJ) announced the arrest of two co-founders of a cryptocurrency mixer…

17 hours ago

Google fixed critical Chrome vulnerability CVE-2024-4058

Google addressed a critical Chrome vulnerability, tracked as CVE-2024-4058, that resides in the ANGLE graphics…

22 hours ago

Nation-state actors exploited two zero-days in ASA and FTD firewalls to breach government networks

Nation-state actor UAT4356 has been exploiting two zero-days in ASA and FTD firewalls since November…

1 day ago

Hackers hijacked the eScan Antivirus update mechanism in malware campaign

A malware campaign has been exploiting the updating mechanism of the eScan antivirus to distribute…

2 days ago

This website uses cookies.