The malicious advertising group Tag Barnakle hacked the Revive ad servers to inject and display malicious ads to unsuspecting visitors.
Most online publishers use hosted advertising platforms such as Google Ad Manager to display their ads, but some still prefer to use self-hosted ad platforms for greater control and flexibility in how their ads appear.

A self-hosted open-source platform that has been around for ten years is called Revive Adserver.
In a new report from the ad security company Confiant, we can see how a malicious advertiser known as Tag Barnakle massively compromises Revive ad servers to inject his own code into the existing advertising campaigns of a publisher.
“In recent months, we have seen a wave of malicious ads that are linked to Revive's advertising material that span dozens of ad servers, including those owned and operated by publishers and ad networks”, explained Confiant security researcher Eliya Stein in a report.

When it compromises servers, Tag Barnakle will modify the existing advertising material used by the publisher and add its own malicious JavaScript code.
This malicious code will detect when Firebug or a browser developer console is open and, if not, will perform a redirection to malicious websites promoting fake Adobe Flash.
Stein said that these fake Adobe Flash player updates install the Shalyer Trojan or other botnet packages on macOS systems.

For Windows users, the sample shared with BleepingComputer installs a bundle of adware, such as InstallCore, which is known to infect victims with ransomware, information-stealing Trojans, unwanted browser extensions, and other malware.
The ad servers that have been compromised have a large reach
Confiant has seen Tag Barnakle activity on more than 360 websites, but their reach is much greater due to the software used by smaller ad serving providers that offer real-time bidding.
On a compromised RTB ad provider, Confiant “saw” up to 1,25 (million) malicious ad impressions occurring in a single day.
While it may be tempting to use your own ad servers, it also opens a publisher to the risk of potential breaches that allow attackers to insert malicious ads.
Therefore, only use an open source ad server if you have the time and manpower to stay up to date on security and be able to install them quickly as they are released.
If you are a small company with limited staff, it may be wiser to adopt a hosted solution to avoid these risks.
