If you've visited Yahoo's home page in the past few days, chances are you've been infected with malware. Yahoo's ad servers have been spreading malware to hundreds of thousands of users, according to two security firms.
Fox IT , a security firm from the Netherlands, says the attack is the work of malicious hackers who have compromised Yahoo's ad network and are using it for their own purposes.
"Customers visiting Yahoo.com are receiving ads served by ads.Yahoo.com. Some of its ads are malicious," a message states.
And then, in response to some user questions, they report that if the victim user has an old version of Java, simply seeing the page is enough to be infected and does not require clicking on them. Apparently, users get a small program that exploits Java vulnerabilities and installs various malware.
The article in question states:
The infection, which is carried out via redirection of advertising websites, exploits Java vulnerabilities and installs various malware, including:
- Zeus
- Andromeda
- Dorkbot/Ngrbot
- Advertisement clicking malware
- Tinba/Zusy
- Necurs
The company believes that the infections began on December 30, 2013, although the attacks may have started even earlier.
Estimates show that around 27,000 computers are infected every hour, with most victims living in Romania, the UK or France. Fox IT says it is unclear which group is behind the attack, but they advise blocking several IP addresses that are exploiting the malicious ads, specifically the 192.133.137/24 subnet and the 193.169.245/24 subnet.
Yahoo appears to be cleaning its servers as the virus's traffic has already decreased.

