Incidents

Adserver compromised – legitimate sites serving malware

Saturday seemed like a quiet day, apart from the new Sober, however it was far from that. In the morning I received some local reports claiming that some respectable sites were distributing malware.

As it turns out, a popular Adserver had been compromised and scripts were modified in such a way that instead of just ads, malware was also delivered to the visitor. At least dozens of sites have unintentionally ‘distributed’ malware, many of them sites with greatly respected names.

This news comes after reports of other (ad)servers being compromised, all using Exploit.HTML.Iframebof to infect the system with malware.

Seeing that there currently is no patch for Exploit.HTML.Iframebof available, Kaspersky Lab strongly recommends anyone using MS Windows, but not running XP/SP2, to use an alternative browser.

A more detailed article on this subject will be posted soon on viruslist.com.

Adserver compromised – legitimate sites serving malware

Your email address will not be published. Required fields are marked *

 

Reports

BlindEagle flying high in Latin America

Kaspersky shares insights into the activity and TTPs of the BlindEagle APT, which targets organizations and individuals in Colombia, Ecuador, Chile, Panama and other Latin American countries.

APT trends report Q2 2024

The report features the most significant developments relating to APT groups in Q2 2024, including the new backdoor in Linux utility XZ, a new RAT called SalmonQT, and hacktivist activity.

Subscribe to our weekly e-mails

The hottest research right in your inbox