HomeSecurityMalicious ads distribute fake Flash Player updates

Malicious ads distribute fake Flash Player updates

Fake-Flash-Player-Update-Prompted-by-Malicious-Advertisement.jpg

Users of a Japanese video-sharing website with more than 30 million members have reported seeing unwanted pop-up messages asking them to update Adobe Flash Player to the latest version.

The video sharing service is provided by Nico Nico in Japan and the pop-up messages were caused by a malicious script that was inserted into the code of the ads, which are distributed via MicroAd and appear during video playback.

The pop-up directed users to a fake Flash Player download site, identical to the real Adobe page. The current version of Flash Player is 14.0.0.125, but the fake page offered build 11.9.900.152 for installation.

According to experts, after installation, the malicious update collects information about the software and hardware of the infected systems and delivers it to a remote server. An additional component is introduced into the infected systems, which downloads an encrypted configuration file and gradually leads to the download and installation of additional malware.

MicroAd issued a security advisory, informing users about the incident and stated that it is investigating the issue.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS