A group that has been committing cybercrimes in recent months has been placing malicious ads on porn sites in order to redirect users to another website and infect them with malware.
The group called Malsmoke has operated on a very high scale compared to other similar groups and has hacked “too many porn sites.”.
Security firm Malwarebytes, which monitors Malsmoke attacks, says that most of the time, the group manages to place malicious ads on not-so-well-known porn sites, but recently they “hit the jackpot” when they managed to do the same on xHamster, one of the largest portals for adult videos and one of the largest websites on the internet, with billions of visitors every month.

The role of the group's malicious ads was to use deceptive JavaScript and redirect users from the adult content site to a malicious site hosting an exploit kit.
The exploit kits then used vulnerabilities in Adobe Flash Player or Internet Explorer to install malware on the user's computers, with the most common payloads being Smoke Loader, Raccoon Stealer , and ZLoader.
Of course, only users still using Internet Explorer or Adobe Flash were targeted by these malicious ads.
The attacks can be seen as a last-ditch effort to infect users with old-school hacking tools, such as exploit kits, whose use has declined in recent years as modern browsers have become more difficult to hack.
Most exploit kits are built for vulnerabilities in Flash and Internet Explorer, which has made them less effective as most internet users have now removed Flash or moved to Chrome and Firefox.
With Flash scheduled for end of life (EOL) at the end of the year, and Internet Explorer slowly being phased out by Microsoft, these are the last few months that attackers are still relying on exploit kits.
“Despite recommendations from Microsoft and security professionals, we can only conclude that there are still a significant number of users (consumers and businesses) worldwide who have not yet migrated to a more modern and fully supported browser,” Malwarebytes said in a report published earlier this week.
