Malvertising: A security researcher said that a malicious advertising campaign that could infect 50 million users affected popular sites such as Facebook.
“One of the main characteristics of the malvertising was the large scope, it was a fairly well-planned attack. The attacker found the right way to infect users, he made the exploit by carefully selecting only particularly popular sites,” explains Carl Leonard, principal analyst at Raytheon.
This massive attack was intended to compromise the OpenX platform (Online Advertising Technology) , the attackers used a malicious code to redirect their victims to the Angler Exploit Kit , which is an exploit for a vulnerability in Flash Player . The success of the malvertising attack involved a specific exploit (2 weeks after the vulnerability was made public), which meant that IT teams did not have time to fix the hole, and also that the attacker did not repeatedly use the same exploit, which made it harder to detect the malicious campaign. The lesson this attack teaches is that even trusted websites can contain malicious elements or direct you to them, through “fresh” vulnerabilities that have not yet been fixed. To protect yourself from this, keep your endpoint security software up to date , as it is the last line of defense for your computer with the Internet. Having strong protection can help you avoid such attacks. Malicious campaigns that exploit fresh vulnerabilities are preferable to cyber criminals as they require much less effort and of course lower cost. From a security perspective, experts should create layers of protection, the higher the cost for cyber criminals, the harder it will be for them to attempt it.
