Nuclear exploit kit: Security firm Trend Micro discovered that ads served by New Jersey-based Mad Ads Media were redirecting to websites hosting the Nuclear exploit kit , which “interrogates” users’ computers for potential problems in order to deliver malware. The number of victims reached 12,500 as of May 2, Trend Micro said .
Initially, the phenomenon appeared to be another malicious example, according to Joseph Chen, a fraud researcher at Trend. Ad networks have occasionally faced incidents of malicious ads being sent to their networks and redirecting users to other pages with malicious content.
A closer look revealed that the Mad Ads Mediaused to serve ads had been modified — specifically, a JavaScript that assigns ads to a specific site. Instead, the library redirected users to servers hosting the Nuclear exploit kit, Chen said.
The websites targeted for redirection contained manga and anime content. Mad Ads Media 's servers serve more than 10,000 websites worldwide and deliver 8 billion ad impressions, according to the website.
If a user is redirected to the Nuclear exploit kit, it attempts to see if the browser is running an old version of the Adobe System Flash. If this is successful, the infamous Carberp malware, which is designed to steal authentication credentials, is already installed on the PC.
Although advertising companies try to filter out malicious ads, hackers often replace ads that have already passed the test with ones that haven't, hoping that the company won't notice. Such attacks can be very productive, as a misleading ad on a high-traffic site certainly means more potential victims.

