HomeSecurityVastflux ad scam affected more than 11 million devices

Vastflux ad scam affected more than 11 million devices

Security experts have uncovered an “extremely advanced” ad fraud that has affected over 11 million devices worldwide. Dubbed Vastflux, the malicious attack exploited 1,700 apps and defrauded at least 120 ad publishers. The attack abused programmatic advertising, which is essentially automated online advertising.

See also: T-Mobile hack: 37 million users' data breached

Vastflux

Every time you access an ad-supported app or website, multiple ads appear before your eyes. However, what you don’t realize is the intense competition between companies for that ad space – it all happens behind closed doors! Programmatic advertising makes this process easier by allowing for rapid auctions to determine which ads will appear on someone’s screen. Ad publishers spend money to secure a spot on either an app or website of their choice.

See also: Yum! Brands owner of KFC, Pizza Hut and Taco Bell hacked

The creators of Vastflux abused this process in mobile apps (particularly iOS, but also some Android apps) to carry out the scam. They initially purchased an ad slot in popular apps with no ill intentions. However, once their offer was accepted and they were granted access to this premium slot, they quickly injected malicious JavaScriptinto it. This allowed them to secretly stack 25 different video ads into a single space for advertising purposes – all without the knowledge of users who only noticed one ad playing. As the Vastflux attack profited from every single ad impression fraudulently registered through this method, the more money the hackers made.

Since 25 ad requests from the same device at the same time would raise suspicion, the attackers forged the ad assets of 1,700 apps. This gave them an advantage, as they disguised 25 ad requests originating from a single device as coming from multiple devices. To make it look even more convincing, they modified the ad tags and stacked multiple videos in the same slot to further deceive publishers.

At its peak in June last year, Vastflux was generating 12 billion ad requests every day. Since users are only exposed to one ad at a time, they have no reason to be suspicious. Additionally, their phones may experience higher power and processor usage as the devices have to handle multiple videos at once – but most people will assume that this is a problem with the app itself, not this stealth attack. What makes detection even more difficult is that once the ad disappears, so does any trace of malicious activity!

See also: Hook Android malware: Learn everything about the new big threat

Vastflux ad scam affected more than 11 million devices

Human Security researchers discovered the Vastflux scam in June of last year, which affected more than 11 million Android and iOS devices. Its creators likely made a significant amount of money by exploiting ad publishers with this criminal activity. Although the malicious attack was interrupted several times, its servers were taken down just a month ago - however, it is very likely that the same criminals will return using new tactics, as they have done in the past with similar operations.

Information source: androidheadlines.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS