HomeSecurityThe group behind malvertising in Windows 10 App has been identified

The group behind malvertising in Windows 10 Apps has been identified

The group behind the recent spate of malicious ads (malvertising) appearing through Microsoft's Windows 10 apps and games has been identified as being based in Hong Kong. This group is behind millions of ads that redirect users to scams, malware , and adware bundles.

malvertising

In April and June of this year, BleepingComputer reported on how French and German users had been targeted by malvertising that displayed tech support scams, phishing pages,and fake sweepstakes. What made this attack unusual was that the ads appeared in Microsoft's free games and Windows 10 apps, allowing them to escape the app and launch to unwanted websites in a user's default browser.

According to a report published by BleepingComputer, advertising firm Confiant discovered a Hong Kong who was creating corporate identities to work with DSPs (demand-side platforms). It then distributed the low-quality and often malicious ads through the DSPs to other ad networks.

In addition to direct collaboration with DSPs, “fiber-ads” also participated in the MyMediAds advertising marketplace.

This malvertising group was very successful, with over 100 million ads being displayed in 2019 alone and was in the top two in May 2019 and June 2019. The May campaign took place around the same time frame that French users reported seeing these ads, and in June, German users reported the same.

Currently, malvertising campaigns from this group are being monitored and blocked by Confiant, but the ad security firm warns that advertisers need to do a better job of vetting their advertisers and if they are unsure, avoid doing business with them.

Malvertising led to scams and malware

The malvertising campaigns were not distributed exclusively to target Windows 10 apps and Microsoft. Instead, they targeted a specific subset of users, and Microsoft apps can be “earned” with in-app ads, but they were also displayed there.

You can see examples of the types of scams of this type and how exactly they appear below.

The group behind malvertising in Windows 10 Apps has been identified

In addition to tech support scams and free products, desktop users would also be presented with more malicious payloads in the form of pages that “push” unwanted security programs and adware packages.

As always, users should never download software from a website that claims to have detected a risk or security issue. These usually lead to the installation of malware and fake security software on a computer.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS