The “CashRewindo” group uses old domains in global malvertising campaigns that lead to investment fraud websites.
Malvertising occurs when cybercriminals insert malicious JavaScript code into online ads that appear on websites operated by legitimate ad networks. This can trick website visitors into going to pages that host phishing forms, drop malware, or carry out scams.
The CashRewind team has adjusted the language and currency so that malvertising campaigns appear legitimate to audiences in Europe, North and South America, Asia, and Africa.
Confiant analysts have been monitoring the “CashRewindo” group for two years and report that this threat actor is unusually skilled at creating malicious advertising campaigns. They pay close attention to detail.

Domains get better as they get older
Criminals register domains and leave them unused for years in the hope of avoiding detection by security software.
This technique works because old domains that have not been involved in malicious activity for a long time gain the trust of the internet, making them unlikely to be flagged as suspicious by security tools.
See also: Microsoft Defender: Tamper protection for everyone by default
According to Confiant, CashRewindo only uses domains that have been aged for at least two years before activation (their certificates have been updated and a virtual server has been assigned to them).
The security firm was able to identify at least 487 domains used by the group. Some of these domains had been registered since 2008 and were first used in 2022.
Victims end up on these sites by clicking on infected ads found on legitimate websites.

Global but highly targeted
CashRewindo’s success is due to its specificity – each campaign is targeted to a specific audience. This means that landing pages either reveal the scam, display an unassuming page, or are blank for users who don’t fit the target profile.

This is done by checking the time zone, device platform, and language used on the visitor's system.
See also: Trigona ransomware: Carries out attacks worldwide
If users or devices that are not part of the target audience click the “Click Here” button, they will be redirected to a safe and non-offensive website.
Valid targets, on the other hand, will execute JavaScript code with the malicious code hidden within a shared library to avoid request inspection.

These users are led to a scam site and eventually redirected to a fake cryptocurrency investment platform that promises unrealistic investment returns.

Confiant reports that it has recorded over 1.5 million impressions of CashRewindo in the last 12 months, with a particular focus on Windows.
Investment scams are widespread, but typically, threat actors prefer quantity over quality, promoting their hastily constructed fake websites to large groups of users and hosting their scam platforms on newly registered domains that are doomed to quickly go offline.
CashRewindo's method is more difficult, but it significantly increases the chances of success for the person carrying out the threat.
Information source: bleepingcomputer.com
