Ad injectors are unwanted applications that insert new ads or replace existing ones. The malware has been infecting the internet for over a year, and Google has released a study to show us how pervasive they are.
Today, the company released details from a study conducted in collaboration with two universities (UC Berkley and Santa Barbara) and it reveals some worrying data.
According to Google, around 5.5% of unique IP addresses (imagine the number in millions of users) that visit Google pages come from Ad injectors. Around 5.1% of them use Windows and 3.4% use Mac (there goes the Mac security myth).
Researchers found that over 50,000 browser extensions and 34,000 software applications take control of browsing and have Ad injectors. 30% of these applications steal account credentials, record searches or general user activity, and submit it to third parties.
You may remember Lenovo's Superfish software that we reported on in February. Well, although Lenovo seems to have removed it, Superfish has left its mark. It's present in Google's research in 3.9% of cases. While Superfish can't serve ads on its own, it does provide a library of ad companies that the malware uses.
Google also says, according to TNW, that Ad injectors have hit 3,000 major companies like Sears, Wal-Mart, Target, and Ebay, which are seeing their ads replaced with unauthorized ones. Often, these companies don't know that anything is wrong, as advertisers typically can't tell when malware is on your computer.
Google has already taken steps to combat ad injectors. For example, the company banned 192 Chrome extensions that had infected about 14 million users. It also improved its tools for identifying unwanted software, while also notifying advertisers who may have been affected by the scams.
You can read the full study on Google's research page.
