Security researchers have discovered a new malvertising campaign, instigated by the hacking group eGobbler. The campaign took place between August 1 and September 23. The hackers affected 1.16 billion ads, redirecting victims to malicious payloads.
In April, researchers discovered another campaign by the same group. Hackers used an exploit that helped them bypass the browser to spread fake ads to millions of users in the US and Europe in less than a week.
Previous eGobbler attacks focused on iOS devices . However, the new malvertising campaign also targets Windows, Linux, and macOS systems.
WebKit exploit
Researchers discovered that hackers used a new exploit payload, similar to the one used to target iOS users. However, the new payload has new features that affect WebKit browsers in a completely new way.
"This time, the iOS Chrome pop-up was not created like before, but we were actually redirected to WebKit browsers.".
Hackers use an inframe that exploits keystrokes. When users press a key, it is assumed that they are browsing the web, resulting in the ad sandboxing feature not preventing the redirects.

"It is worth noting that the campaign behind this payload targeted web applications with text boxes and search forms, in order to maximize the chances of abusing these keypresses," Confiant said.
Both the Chrome and Apple teams were notified of the bug in August when researchers discovered the malvertising campaign.
Chrome developers released a patch for WebKit on August 12. Apple, on the other hand, fixed the issue in September with iOS 13 and Safari version 13.0.1.
“eGobbler’s preference for desktop platforms during this campaign is related to the WebKit exploit, as it takes advantage of keystrokes,” Confiant explained.
The new campaign shows that the eGobbler group has changed the way it attacks. Previously, it focused on delivering malicious payloads to mobile devices.
In its latest attacks, eGobbler exploited various content (CDNs) to deliver its payloads.
Confiant researchers had discovered a similar campaign in November 2018, by the ScamClub. The hackers had affected approximately 300 million iOS users, redirecting them to adult content sites and other fake sites.
