As publishers recognize the true cost of malvertising, recent cases highlight the damage

By Trevor Grigoruk

Malvertising — the use of ad tech by malicious actors to attack end users at scale — has been a silent but insidious aspect of digital advertising in recent years. Now, however, the extent of the damage, both real and potential, is expanding.

And it should, according to experts, as approximately $1 billion revenue was lost last year. Even so, publishers are often missing the evidence. Only when an aggregate of data ultimately tells them they’re losing traffic do they take notice, and those moments are becoming more frequent.

“One thing that publishers are very much aware of is the redirect, when the page gets hijacked, the user journey on the page is interrupted, and they’re sent to some scam or to some malware,” said Jerome Dangu, co-founder and CTO of Confiant, a company that works with publishers and brands to deter and mitigate malvertisers. “For publishers, it’s terrible, because they lost that user for that session, and maybe the user will not come back because they don’t trust that the site is safe.

“And then there are [more complex] cycles in security as attackers iterate,” Dangu continued, “and they’re pushing the limits of what can be done to continue to exploit an environment.”

Malvertising is an increasingly sophisticated threat

Malvertising attacks are becoming more sophisticated, moving away from simple redirects to a more complex pathway that involves malicious clickbait. For example, some ads target older people with offers featuring celebrities such as Paul McCartney and Mel Gibson.

With a click, recipients are redirected to a fake Bitcoin opportunity, which connects them to a call center, typically in Eastern Europe. The unsuspecting victim is set up with a fake portal that shows their bitcoin investment doing well, and so the victim is coaxed into “investing” more money. They are, of course, being scammed out of every cent they spend.

“In the UK, just two weeks ago, we found 20 million ads like this on our publisher clients’ sites,” said Dangu.

Some celebrities have filed or threatened to file lawsuits against malicious advertising agencies. But it’s not clear if these lawsuits are discouraging advertisers from using a familiar face to propagate convincing Bitcoin scams.

Other cases, globally, include bad actors in China, where malvertisers have leveraged Javascript to create a notification that appears on victims’ mobile devices, usually a convincing carrier-branded scam. The interface convinces the victim that they have won a smartphone, prompting them to input their payment information and resulting in a data-theft transaction.

In some cases, scammers leverage client-side fingerprinting to inspect the user’s environment in real time and evade quality controls. They lure users onto a cloaked landing page that may look innocuous — if simple or slightly pointless — and then gathers information to send back to their malicious server. The scammer scrutinizes the collected data and decides what to do next. As time has progressed, the fake ads have gotten more sophisticated, too, mimicking blog and platform-specific social-media ads with increasing polish.

A problem rooted in organized crime

Publishers and …read more

Source:: Digiday

      

Aaron
Author: Aaron

Related Articles