Malvertising Group Spreading Kovter Malware via Fake Browser Updates

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
A malvertising group nicknamed KovCoreG by security researchers has been using fake browser and Flash updates to trick users into installing the Kovter malware.

Attackers used malicious ads on PornHub to redirect users to a scam site that was advertising an urgent update. Depending on their browser, users got different messages.

For example, users arriving on this page via Chrome and Firefox were asked to download a browser update, while IE and Edge users were asked to download a Flash update.

Malvertising-PornHub.png


The downloadable files were JavaScript (Chrome, Firefox) or HTA (IE, Edge) files that installed Kovter, a multi-purpose malware downloader that can deliver ad fraud malware, ransomware, infostealers, or more.

Campaign focused on UK, US, Canadian, and Australians
Researchers from Proofpoint discovered this malvertising campaign and informed both Pornhub and Traffic Junky — the ad network's whose ads were being abused. Both companies intervened and shut down the ads, but researchers expect the group to pop up somewhere else online.

This particular group fits recent malvertising trends where the malvertisers focus on redirecting users to social engineering (scam, fake download) sites, instead of sending users to exploit kits.

The KovCoreG used ISP and geographical-based filters to separate only the users they wanted to attack. The PornHub campaign targeted US, UK, Canadian, and Australian users.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top