HomeSecurityMicrosoft: Malvertising campaign affected 1 million computers

Microsoft: Malvertising campaign affected 1 million computers

Microsoft has removed some GitHub repositories because they were being used as part of a massive malvertising campaign that affected nearly a million devices worldwide.

Microsoft: Malvertising campaign affected 1 million computers

According to the company's researchers, these attacks were detected in early December 2024, when many devices began downloading malware from GitHub repositories. This malware was then used to deploy other malicious payloads on compromised systems.

After analyzing the malvertising campaign, they discovered that the attackers inserted ads into videos on illegal pirate streaming sites, which lead potential victims to malicious GitHub repositories.

See also: Alarming rise in ClickFix attacks via Malvertising “DeceptionAds”

“ Streaming sites embedded malvertising redirectors within movie frames to generate per-view or pay-per-click revenue from malvertising platforms ,” Microsoft explained . “ These redirects then routed traffic through one or two additional malicious redirectors, ultimately leading to another site, which then redirected to GitHub .”

The GitHub repositories were infected with malware designed to collect detailed system information (e.g. memory size, graphics details, screen resolution, operating system (OS), and user paths) and export the collected data. At the same time, other malicious payloads were deployed (second stage).

A third-stage PowerShell script payload then downloads the remote access trojan NetSupport (RAT) from a command-and-control server, thereby establishing registry persistence for the RAT. Once executed, the malware can deploy the Lumma credential theft malware and the Doenerium credential theft malware to extract user data and credentials.

See also: Hackers exploit Google Search ads to spread Malvertising

However, if the third-stage payload is an executable file, it creates and executes a CMD file while installing a renamed AutoIt interpreter with a .com extension. The AutoIt component launches the binary and may install another version of the AutoIt interpreter with a .scr extension. A JavaScript file is also deployed to help execute and obtain persistence for .scr files.

In the final stage of the attack, AutoIt payloads use RegAsm or PowerShell to open files, enable remote browser debugging, and extract additional information.

Microsoft Malvertising

According to Microsoft, GitHub was the primary platform for hosting payloads in this malvertising campaign (in the first stage), but researchers observed that Dropbox and Discord were also used.

See also: Hackers exploit Google Search ads to spread Malvertising

Researchers say the campaign affected multiple organizations across different industries, including personal and corporate devices.

Protection from malvertising campaigns

  1. Use an ad blocker
  2. Keep the software up to date
  3. Use a secure browser
  4. Avoid clicking on ads
  5. Enable built-in security features
  6. Use a DNS-based security solution
  7. Be wary of free VPNs and extensions
  8. Disable unnecessary browser plugins
  9. Scan your device regularly for malware
  10. Use a secure network and VPN

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS