
Researchers at Flashpointhave discovered a large advertising framework that is parasitizing Google AdSense ads. The researchers said that the main targets of the attackers are browsers such as Google Chrome, Mozilla Firefox and Yandex Browser, which run on Windows and form the basis of the botnet. As the researchers report, over 1 billion ads through this framework in the last three months.
Infection of the victim's machine begins with the use of the Installer module, which will install and configure a malicious browser extension, as well as ensure its constant presence on the system by creating a scheduled task (the malware will pretend to be Windows Update).
Then, another framework module, Finder, starts collecting cookies and credentials from the infected system, sending them to the malicious actors, in the form of ZIP files. In addition, this module will communicate with the secondary management server, which transmits commands and reports to the malware on what frequency is necessary to collect and steal data from infected systems.
Then, the Patcher, which was used in an older version of the framework to install a malicious extension, has acquired new versions that are already included in the Installer module.
Once the browser is successfully infected, the extension will immediately start working, embedding ads on websites and creating data flow that is hidden from the user (for example, it will watch Twitch streams in the background or similar videos on YouTube).
An interesting fact is that the ad insertion does not appear on all websites visited by the victim. This means that the malware has extensive “blacklists”, which include domains on Google, various Russian websites, and pornographic sites.
According to Flashpoint, this campaign is mainly focused on countries like Russia, Ukraine, and Kazakhstan.
