Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Hackers manipulate AdWords to redirect users and place malvertising banners

by The Gurus
January 15, 2015
in Editor's News
Share on FacebookShare on Twitter

Recent attacks have seen the AdSense network infected and Google Adwords manipulated by attackers, to create a new type of malvertising attack.
 
According to a blog by Sucuri senior malware researcher Denis Sinegubko, requests were made to the company to scan websites for malware as some randomly redirected to magazine websites, and in all cases, the symptoms were the same.
 
“Some users randomly got redirected when they clicked on links or loaded new pages,” Sinegubko said. “They all reported that the new page would show up for a second or two and then it would redirect them to those magazine websites.”
 
While some visitors regularly saw those redirects and even complained that the websites were barely usable because of them, Sucuri found that the redirect was due to third-party scripts, which looked quite plausible since all the websites ran third-party ads.
 
It revealed that sites with AdSense banners (not text ads) randomly redirected visitors to fake sites that “revealed health secrets”, such as skin care and anti-aging, IQ and brain enhancers and, weight-loss products that pretended to be reputable (although sometimes nonexistent) blogs and magazines.
 
However all of the fake sites are in different subdirectories of domains linked to lemode-mgz, which only contained empty pages. Three of the five domains were registered in December 2014, another in August 2014 and the other in 2013. “In all cases the whois data is protected and all this domains are hosted on Amazon network: EC2 and S3,” Sinegubko said.
 
Jared DeMott, security researcher at Bromium, said that typical “malvertising” would normally just serve up browser exploits or similar, but in this case it seems there was some other click-jacking like scam involved.
 
Jérôme Segura, senior security researcher at Malwarebytes, said that other companies had contacted them wondering if their computers had been infected, and many complained to various site administrators who could not see anything wrong with their own servers.
 
He said: “Typically malvertising is known for redirects that are malicious in nature, for instance a redirection to an exploit kit. Pushing scam pages instead is a little more unusual and typically only done in specific cases.
 
“In this case it appears as though the bad guys hijacked existing accounts, and in particular some that had large spending budgets. This is an interesting new approach for us and it does have some definite advantages [for the attacker]. For one, the criminals can still conduct their activity anonymously, since they are using somebody else’s profile.”
 
Also in the attack, two advertising campaigns were manipulated to feature malicious banners, and both used legitimate AdWords accounts with relevant banners. Sinegubko said: “I guess the scammers somewhow hijacked them — probably stole or guessed their credentials. Most likely those accounts didn’t have active campaigns at the moment, otherwise their owners must have noticed the significantly increased activity.
 
“The other possibility is the scammers created those fake accounts themselves using the legitimate sites as a cover.”
 
Segura called this more important, as a legitimate and approved AdWords account with significant funds was used. “This could explain why it took so long for Google to address the issue and definitely
leaves some questions unanswered,” he said.
 
“To me, this example confirms that malvertising has simply gone out of control and is probably the biggest infection vector we will continue to see in 2015. The bad guys could not hope for anything better to spread either malware or scams: anonymity, instant propagation and effectiveness.”
 
DeMott said: “The attack vector with ad-malware is to compromise one of the ad networks such that an attacker can insert their scripts/redirects into otherwise legitimate ads, which will only get served up to x% of visitors based on normal ad heuristics.”
 
Sinegubko doubted that this campaign is limited to AdSense, as there is no reason why scammers would not use other ad networks, and recommended webmasters to consider any third-party script that they place into their site code as a potential threat.
 
Itsik mantin, security researcher at Imperva, said: “Specifically in this incident the attackers didn’t have real issue with placing high bids, since according to the blog speculation, they were partying on the AdWord account of someone else, probably using stolen credentials.
 
“Once the victim is caught and brought in, the attacker can start phishing. One of the common phishing methods includes impersonating as a legitimate site and using the natural trust the victim has in this site, to convince him to enter his credit card number or any other secrets the attacker needs, for example his credentials to an AdWord account.”

Tags: attackGoogleMalvertising
ShareTweet
Previous Post

Crayola Facebook wall hit by NSFW illustrations

Next Post

FTSE 350 place cyber security on the board’s agenda

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol