Security researchers have discovered an adware they have dubbed Zacinlo, which specializes in ad fraud. According to Bitdefender, Zacinlo can replace ads from various platforms, such as Google Adsense.

Adware has long been used by developers who distribute their programs for free to increase their profits. In a statement, Bitdefender wrote that “Adware has made great progress in recent years, both in how much information it collects and how difficult it is to remove. The line between adware and spyware is now very thin as the most modern adware combines aggressive policies and complex marketing terms, as well as highly sophisticated techniques aimed at complete control of the computer.
Zacinlo, which has been around since 2012, after infecting a computer, does one of two things: It opens invisible windows in which it loads ads and then pretends that the user clicks on them, or it replaces the ads that are loaded in the user's browser with the aim of generating revenue.
An interesting feature of adware is that it contains a rootkit driver, which protects the adware itself and its components. Rootkit-based malware is found in less than 1% of threats, and its removal is extremely difficult.
“Threats like Zacinlo are proof that cybercrime really does pay. Ad fraud has been known to happen for years, but Zacinlo raises the bar significantly. Its sophistication, longevity, and the sheer number of samples it has generated show that the group behind it is able to steal significant amounts of money from publishers and advertisers.”
