Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » DeceptionAds delivers over 1 million impressions daily across 3,000 sites, fake CAPTCHA pages
Global Security

DeceptionAds delivers over 1 million impressions daily across 3,000 sites, fake CAPTCHA pages

AdminBy AdminDecember 16, 2024No Comments3 Mins Read
DeceptionAds
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 16, 2024Ravi LakshmananMalware / Threat Intelligence

Cheat ads

Cybersecurity researchers have shed light on a previously undocumented aspect of ClickFix-style attacks that involve taking advantage of a single ad network service in an ad-driven phishing campaign. Cheat ads.

“This campaign, based entirely on a single ad network for distribution, demonstrates the basic mechanisms of malicious advertising – delivering over 1 million daily ‘ad impressions’ (over the last ten days) and causing thousands of daily victims to lose their accounts and money through a network of 3,000 + content sites that drive traffic” – Nati Tal, Head of Guardio Labs, said in a report shared with The Hacker News.

Cyber ​​security

Hiking, like documented by several cybersecurity companies in recent months, include directing visitors to pirated movie sites and others to fake CAPTCHA pages that tell them to copy and execute a Base64-encoded PowerShell command, ultimately leading to the deployment of information stealers like Lumma.

With Proofpoint, attacks are no longer limited to one actor recently stating that several unattributed threat clusters have used a clever social engineering approach to deliver remote access trojans, stealers, and even post-exploitation frameworks like Brute Ratel C4.

Cheat ads

Guardio Labs said it was able to trace the company’s origins to Monetag, a platform that claims to offer multiple ad formats for “website monetization, social traffic, Telegram mini-apps,” with threat actors also using services such as ad tracking BeMob to hide their evil intentions. Monetag is also tracked by Infoblox under the names Vane Viper and Omnatuor.

Cheat ads

In fact, the campaign boils down to the following: website owners (i.e. threat actors) register with Monetag, after which the traffic is redirected to a traffic distribution system (TDS), which is operated by a malicious ad network, and ultimately leads visitors to a CAPTCHA verification page.

“By feeding a good BeMob URL to Monetag’s ad management system instead of a straight fake captcha page, the attackers took advantage of BeMob’s reputation, complicating Monetag’s content moderation efforts,” Tal explained. “This TDS BeMob finally redirects to a malicious CAPTCHA page hosted on services like Oracle Cloud, Scaleway, Bunny CDN, EXOScale, and even Cloudflare’s R2.”

Cyber ​​security

After responsible disclosure, Monetag removed more than 200 accounts associated with the threat. BeMob similarly removed accounts used for cloaking. However, there are signs that the company has recovered on December 5, 2024.

The findings reiterate the need for content moderation and robust account verification to prevent fraudulent registrations.

“From fraudulent publisher sites that offer pirated content or content bait, to sophisticated redirect chains and cloaking techniques, this campaign highlights how ad networks created for legitimate purposes can be weapons for malicious activity,” Tal said.

“The result is a disjointed chain of responsibility in which ad networks, publishers, ad statistics services and hosting providers play a role, but often avoid responsibility.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.