Thursday, March 30, 2017

AdGholas Malvertising Campaign

What is Malvertising Campaign?

Term Malvertising is meant to online ads for malware spreading. Injecting or embedding the malicious code in the legitimate webpages and online advertisement is the way how malvertising works. Most of the cases, we seen attackers or hackers use the legitimate websites and find the loopholes in those sites then add their malicious code in it.  They use several exploit kits to find the exploits and use to compromise the websites. We observed that Several popular websites and news sources have been victims to malvertising and have had malicious advertisements placed on their webpages or widgets unknowingly, including Horoscope.com, The New York Times, the London Stock Exchange, Spotify, and The Onion. Malvertising campaign is a set of incidents processed by attackers to achieve the spreading of malware using online advertisement. In most of the times, campaign will be used to target particular sector or business.



AdGholas Malvertising Campaign

A group of rogue actors involved in stealthy attacks was exposed by security giants like eset, proofpoints, and Trend micro. According malwarebytes telemetry, AdGholas hackers are the largest malvertising attacks in the end of 2016. This operation has been running since at least October 2015. According to security vendor Proofpoint, this gang managed to distribute malicious advertisements through more than 100 ad exchanges, attracting between 1 million and 5 million page hits per day.




Please refer our article on windows zeroday exploit used by AdGholas hackers:


Post created by


No comments:

Operating system - Part 1:

 In our blog, we published several articles on OS concepts which mostly on the perspective for malware analysis/security research. In few in...