‘Stegano’ Malvertising Exposes Millions To Hacking
December 13, 2016 by admin
Filed under Around The Net
Comments Off on ‘Stegano’ Malvertising Exposes Millions To Hacking
Since October, millions of internet users have been exposed to malicious code embedded in the pixels from tainted banner ads designed to install Trojans and spyware, according to security firm ESET.
The attack campaign, called Stegano, has been spreading from malicious ads in a “number of reputable news websites,” ESET said in a Tuesday blog post. It’s been preying on Internet Explorer users by scanning for vulnerabilities in Adobe Flash and then exploiting them.
The attack is designed to infect victims with malware that can steal email password credentials through its keylogging and screenshot grabbing features, among others.
The attack is also hard to detect. To infect their victims, the hackers were essentially poisoning the pixels used in the tainted banner ads, ESET said in a separate post.
The hackers concealed their malicious coding in the parameters controlling the pixels’ transparency on the banner ad. This allowed their attack to go unnoticed by the legitimate advertising networks.
Victims will typically see a banner ad for a product called “Browser Defense” or “Broxu.” But in reality, the ad is also designed to run Javascript that will secretly open a new browser window to a malicious website designed to exploit vulnerabilities in Flash that will help carry out the rest of the attack.
Hackers have used similar so-called malvertising tactics to secretly serve malicious coding over legitimate online advertising networks. It’s an attack method that has proven to be a successful at quickly spreading malware to potentially millions.
The makers behind the Stegano attack were also careful to create safeguards to prevent detection, ESET said. For instance, the banner ads will alternate between serving a malicious version or a clean version, depending on the settings run on the victim’s computer. It will also check for any security products or virtualization software on the machine before proceeding with the attack.
ESET declined to name the news websites that were found unknowingly displaying the malicious ads, but cautioned that the attack was widespread, and could have been hosted through other popular sites as well.
Source-http://www.thegurureview.net/aroundnet-category/stegano-malvertising-ads-expose-millions-of-online-users-to-hacking.html
Facebook Is Display Advertising King
Facebook’s U.S. advertising revenue will reach roughly $2.2 billion in 2011, toppling Yahoo Inc to collect the biggest portion of online display advertising dollars, according to a new study.
Facebook’s U.S. advertising revenue will give it a 17.7 percent share of the market for graphical display ads that appear on websites, according to a report released on Monday by research firm eMarketer.
Last year Facebook garnered 12.2 percent share of the U.S. market.
The figures highlights the growing clout of Facebook, the world’s No.1 Internet social network. It has seen its valuation soar to roughly $80 billion in recent transactions for its shares on the private markets as some investors anticipate it could have an initial public offering next year.
While Facebook has grabbed the top ranking, eMarketer analyst David Hallerman said the overall market for display ads, which include banner ads, video ads and Web page sponsorships, is growing robustly enough that it is benefiting numerous companies.