HomeSecurityMalvertising campaigns return to Microsoft's MSN portal

Malvertising campaigns return to Microsoft's MSN portal

Microsoft's MSN portal is once again being targeted by malvertisers after a similar malvertising campaign with various types of malware in August 2015.

Just like before, the guilty ad network displaying these malicious ads is AdSpirit, the same ad network used in August to display malverts on MSN, Weather.com, Wunderground, and The Drudge Report.

Malvertising campaigns return to Microsoft's MSN portal

The difference this time is that the advertisers used the Neutrino and RIG exploit kits, instead of Angler. There is a trend among malicious actors moving away from using the Angler exploit kit, a trend that has been observed since the beginning of the year.

This may have to do with the fact that Angler was the most widely used exploit kit last year and many cybersecurity vendors have focused their efforts on detecting its presence on Web.

According to Malwarebytes, this latest MSN malvertising campaign was detected in Germany. Most of the infected ads targeted Lidl, one of Germany's leading low-cost supermarket chains.

Security researchers said it was easy to spot the ads, since most were using “advertising domains that were newly created just a few days before the attack or were hidden behind the Cloudflare.”

Although researchers were unable to infect any of the test stations with malware with this campaign, a similar, older malvertising campaign with the same parameters was detected spreading the CryptoWall ransomware.

To protect yourself from malicious ads, the simplest solution is to use an ad blocker, but using a security product is a much wiser solution since users could add pages to the whitelist and let malicious ads through.

In recent months, most malicious actors have shifted spam activities to malvertising campaigns, as they are more likely to infect users through insidious advertisements on legitimate websites, rather than relying on users opening, downloading, and then double-clicking on a malicious executable.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS