HomeSecurityAbuse of legitimate TDS platform to distribute malware

Abuse of legitimate TDS platform to distribute malware

TDS Cybercriminals compromised the legitimate TDS (Traffic Direction System) platform Keitaro and used it to redirect users to the RIG and Fallout exploit kits with the aim of infecting them with malware .

TDS platforms are designed to redirect users to specific sites. Legitimate TDS platforms, such as Keitaro, are primarily used by individuals and companies who want to advertise their services or products. The platforms direct users to pages that the companies want, thus achieving the targeting of specific customers and promoting an advertising campaign.

The Keitaro platform, for example, uses more than 20 filters to precisely target users (e.g., geographic location, device information, browser information , and more)

However, these platforms can also be used by hackers for malicious purposes.

There are, in fact, some that are specifically designed for illegal purposes (e.g. EITest, Seamless, Sutra, BlackOS, NinjaTDS). These TDS platforms redirect potential victims to exploit kits that attempt to infect them with malware.

“TDS platforms are a very useful tool for an attacker looking to limit the distribution of malicious content,” Proofpoint researchers said. “An attacker using TDS can ensure that researchers security don’t see anything malicious, but real users are redirected to exploits and malware.”

Abuse of legitimate TDS platform to distribute malware

Malware distribution

Proofpoint researchers discovered that hackers compromised the platform and used it to carry out malvertising and malspam campaigns.

Using a legitimate TDS platform made it difficult to detect illegal activity and block redirects.

Keitaro was used in August to redirect users to the Fallout or RIG exploit kit depending on the potential vulnerabilities and geographic location of each target, as well as based on various other criteria.

The hackers' goal was to redirect users: 1) to malvertising sites that infected them using one of two exploit kits, 2) to malicious files that installed malware. In the end, they also led them to legitimate sites.

The victims' systems were infected with various malware, such as AZORult, Predator the Thief, CoinMiner, KPOT, SystemBC, Osiris, Chthonic, Vidar Stealer, Amadey, Danabot “40”, Vidar, Gootkit or Onliner.

The attackers who exploited the Keitaro TDS platform were smart, exploiting a legitimate platform so that their malicious activities could not be easily detected.

Researchers continue to monitor the Keitaro platform.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS