Malware News Malvertising Campaign on Adult Sites Spreads Ramnit Trojan

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Security researchers from Malwarebytes have discovered a new malvertising campaign targeting visitors of several adult websites, spreading the Ramnit trojan and focusing on users from Canada and the UK.

According to the security firm, the malicious ads included in this malvertising campaign belonged to advertising network ExoClick, who was notified and promptly identified and terminated the rogue advertiser's account and ads.
Malwarebytes researcher Jérôme Segura said the malvertising campaign hit mainly adult portals, but did not specify which ones, except See.xxx.

Malvertising campaign leveraged pop-under ads
According to Segura, the malvertising campaign didn't leverage classic advertising banners, but pop-under ads. These are adverts that load in a new, unfocused browser window, while the original browser window remains focused.

Malicious code contained in those fullscreen pop-under ads redirected users to a TDS (Traffic Distribution System), which then, through multiple other redirections, sent users to the landing page of an instance of the RIG exploit kit.

Geolocation filters were in place, as only certain users were selected, mainly from Canada and the UK.

Malvertising led users to RIG EK spreading Ramnit
......
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top