New Malvertising Attack: The DNSChanger exploit kit is back, more effective than ever. The new DNSChanger is widely used for malicious attacks targeting home routers. It should be noted that home routers are also used by many companies…
According to researchers at Proofpoint, the main target of the intruders is the DNS records on the target router. In this way, all queries pass through the intruder's DNS servers. 
What is the benefit of Malvertising for the attackers?
Victims are served ads that generate money for the attackers. Of course, the malicious actions do not stop at ad distribution.
“When attackers take control of the DNS server in a network, they can carry out a wide range of malicious actions on devices connected to the network. These include banking fraud, man-in-the-middle attacks, phishing, advertising fraud, and many more. In this case, the DNSChanger exploit kit allows attackers to exploit the internet router,” said the researcher from Proofpoint, Kafeine.
How the specific Malvertising attack is carried out
Everything starts with ads that exist on legitimate websites. When they are served to a potential victim, they ping the attackers' server, offering it the victim's local IP address.
If the IP address is already known, or is not present in the targeted regions, the user is served a legitimate advertisement and the attack stops there.
If, however, the IP address meets the conditions set by the attacker, a malicious advertisement (a PNG file) is served to the victim, containing HTML code that redirects the victims to the destination page of the DNSChanger exploit kit. There, some JavaScript begins to execute various functions.
After the IP address check (once again), the DNSChanger exploit kit loads multiple functions and an AES key that is hidden via steganography in a small image.
“This key will be used to decrypt the list of [router] fingerprints, says Kafeine. “Then, using the victim's browser, malicious users will try to locate the router being used on the network.”
The results were sent back to the exploit kit, which then sends instructions on how the specific router model can be compromised.
Once the router is compromised, the DNS settings change. Thus attackers can eavesdrop on traffic from certain large advertising companies.

How to protect yourself?
The list of routers included in the exploit kit is large, and potentially vulnerable router models are not easy to identify.
“The safest approach for end users is to assume that all known exploits are included in this exploit kit, and thus all routers should be updated to the latest known firmware,” advises Kafeine. Naturally, if manufacturers do not provide secure firmware this is another issue.
If you also use ad-blocking software you can minimize the risk of being infected by malicious advertising campaigns.
According to Kafeine, the current campaign targets Chrome users on Windows computers and Android devices.
