Ad Injection: Recent research by Google and the Universities of California, Berkeley and Santa Barbara, reveals that injection operations employ 50,780 Chrome Extensions and 34,407 Windows binaries.
Online advertising is a surprisingly profitable multi-billion dollar business and of course cyber-criminals are fully aware of this and are trying to take advantage of it through unfair means and aggressively.
According to the study's results, 30% of the packages contain malicious activities, and in addition to ad injection into web browser sessions, they can also steal credentials, attempt hijacking on searches, or expose the user's online activity.
The Injection libraries Superfish and Jollywallet are more widespread.
The administrators behind the applications that add the ads use a complex system that distributes the tools that throw the ads, gets the libraries for adding the ads, and the advertisers who fall victim to these tactics.
Google developed a solution to detect ad injection , and during the study (from June 1 to September 30, 2014) it found that millions of users were accessing the company's websites that contained illegal ads. Among the 25 companies providing ad injection libraries , Google found that Superfish and Jollywallet were the top providers, accounting for 3.4% and 2.4%, respectively, of the company's tracked views.
The distribution of illegal packages is done through marketing and bundling in very popular programs through malware or social advertising. Once the application (ad injection) that adds the ads is installed, they are inserted into the sites, accessible to the victims and the money goes to the advertisers when the clicks are recorded.
The online advertising system has been corrupted in this way, and the only ones who can benefit are criminals. The advertiser does not know where his banner is being played, so he cannot calculate the success of his campaign, while the publisher does not get paid as the ad is forced to appear on his website.
Google 's efforts to crack down on the phenomenon began with a cleanup of the Chrome Web Store and the launch of nearly 200 new extensions to nearly 14 million users. The company also improved pop-up notifications in Chrome when you try to download deceptive software.
In addition, the giant company informed advertisers of the illegal activities as well as the networks involved.

