Malvertising - Now Available on your Computer

12426632300?profile=RESIZE_400xThe term "malvertising" (or "malicious advertising") suggests an overlap with ads, and not good ones. Therefore, it fuels the fallacy that its impact hardly goes beyond frustration. As a result, those who are unfamiliar might get the impression that it is no big deal, but this is a far cry from the case.

Malvertising acts as a vessel for malware propagation.  To set such a stratagem in motion, cybercriminals poison legitimate websites with ads that lead to shady URLs or download malicious code camouflaged as something harmless.  At its core, this tactic revolves around gaming the trust users put in reputable internet services, including search engines, and the familiarity they have with online advertising per se.

See:  https://redskyalliance.org/xindustry/new-malvertising-campaign

Just to illustrate the scope of the issue, the Malwarebytes Threat Intelligence team spotted more than 800 malvertising campaigns in only the first six months of 2023, noting that the number of attacks that flew under researchers' radar was likely much higher.  Some of the unearthed hoaxes delivered info stealers, such as Aurora Stealer, Bootloader, and IceID, with the latter having gained notoriety for facilitating Quantum ransomware distribution.[1]

One of the biggest pitfalls with malvertising is how difficult it can be to detect. Scammers and malware operators are increasingly adept at mimicking popular brands in their ad snippets, which makes it problematic for the average user to tell the wheat from the chaff.  Understating the very anatomy of this foul play can offer actionable clues on the ways to be a moving target.  Threat actors tend to abuse legitimate advertising networks or websites to disseminate their malicious content that may appear as banners, pop-ups, or embedded scripts on trusted web pages.  These ads often target specific demographics or interests to increase the likelihood of clicks.  If a user gets on the hook, they are redirected to a landing page or prompted to download an ostensibly innocuous file.  This ends up executing sketchy code that installs viruses, ransomware, spyware, or adware behind the victim's back.

Cybercriminals can then exploit the compromised device for various purposes, such as stealing personal information, conducting financial fraud, recruiting it into a botnet, or encrypting data and holding it for ransom. The IP addresses of the malicious Command and Control (C2) infrastructure are changed according to the fast-flux logic to prevent the attack from being traced back to its operators.

This tactic has tangible real-world implications. In one of the extortion campaigns seen in mid-2023, the infamous BlackCat/ALPHV ransomware hinged on malvertising to gain a foothold in computer networks.  Its authors created cloned web pages that offer the download of popular free software, such as the WinSCP file manager.  These fake sites were promoted on Google and Bing search results.

The infection chain starts when the user downloads and runs an ISO file, only to execute a malware dropper that installs a trojanized DLL object containing an instance of Cobalt Strike.  The attackers then mishandle this well-known adversary simulation tool to harvest information about the operating system, exfiltrate data, and locate directories and services with weak access control settings. This interference is a significant catalyst for double extortion that involves both a breach and data encryption.  Again, a raid as harmful as that commences with what appears to be garden-variety deceptive advertising trickery.

Placing an advertisement in web search results is relatively straightforward; all it takes is paying a fee and passing a pre-screening procedure.  However, these security checks often fail to identify black hat schemes.  The world's most trusted search services are fertile ground for rogue ads that give momentum to massive malvertising attacks.

Here is some evidence for those who consider the risk far-fetched.  In November 2022, cybercriminals somehow acquired the right to run ads on Google for the popular open-source graphics editor GIMP.  The ad above the fold specified the correct URL (gimp.org), but with the caveat that it directed users to a carbon copy of the original page at "gilimp.org."  The clever misspelling in the domain name was inconspicuous enough for many would-be victims to overlook.

The knock-off landing site was serving an executable that would download an infostealer trojan called Vidar onto visitors' devices.  It remains unclear how the bad actors manipulated Google's ad platform to give the green light to this malvertising campaign.  A particularly unsettling thing is that the mismatch between the display URL and the landing URL didn't raise any red flags.  One way or another, the fact persists that search engine abuse can amplify the problem.

In light of the escalating threat, the US Cybersecurity and Infrastructure Security Agency (CISA) published an advisory encouraging all government agencies to leverage ad-blocking solutions in their day-to-day work.  However, the agency immediately noted that such tools require high levels of privilege to operate, which potentially allows them to amass sensitive data.  Another pitfall is that some of these browser extensions may "accept payment from advertisers to ensure their ads are allowlisted from blocking."

Ad blockers are worthwhile as long as proper ethics and DevOps security best practices back them.  These apps do pull the plug on advertisements triggered by bad scripts and macros on websites, but they aren't a complete solution.  In addition to the risks outlined by CISA, these add-ons don't sift out dubious advertisements on search engines that are increasingly common.

One alternative mechanism for being resilient against malvertising is to create an "air gap" between web browsers and operating systems. This tactic reduces the attack surface by limiting harmful code execution to a specific environment.

If an ad reads too good to be true, think twice before clicking it.  It is also imperative to verify website authenticity before interacting with its content.  Look for HTTPS encryption, check the site's domain name for misspellings and irregularities (as was the case with the "gilimp.org" versus "gimp.org" story above), and steer clear of unfamiliar web pages with questionable reputation.

A DNS firewall and a classic antivirus are somewhat underused yet effective security tools that will come in handy.  The former helps block dangerous internet content, and the latter pinpoints malware payloads in real time to form a robust layer of protection in malvertising scenarios.

Malvertising tends to be eclipsed by scourges like ransomware and info-stealing campaigns that cause direct harm.  However, that seems to be a misconception because these cyberattacks often overlap.  Not only can ads be irritating, but they can also be launchpads for much more severe compromises. A mix of social engineering, hacking, and abuse of legitimate services makes this style of online crime incredibly effective.

The silver lining is that such scams are relatively easy to avoid. Be reasonably paranoid about ads that convey unrealistic promises, contain spelling mistakes, and don't align with your recent searches.  Double-check the URLs of landing pages that load after you click advertisements.  Turn off autoplay for video content in your browser. Consider using an ad-blocking extension.  And don't underestimate the effectiveness of reputable antivirus software, as it can stop most malvertising attacks in their tracks.

 

This article is presented at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.     For questions, comments, or assistance, please get in touch with the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

Reporting: https://www.redskyalliance.org/
Website: https://www.redskyalliance.com/
LinkedIn: https://www.linkedin.com/company/64265941

Weekly Cyber Intelligence Briefings:

REDSHORTS - Weekly Cyber Intelligence Briefings

https://attendee.gotowebinar.com/register/5993554863383553632

 

[1] https://www.secureworld.io/industry-news/malvertising-cybercrime-heavyweight/

E-mail me when people leave their comments –

You need to be a member of Red Sky Alliance to add comments!