Malvertising Campaign Hits 10 Million Users in Just 10 Days! –Security firm Cyphort Labs reports that 10 million users have been affected in just 10 days by a malvertising and exploit kit campaign.
Mr. Nick Bilogorskiy, a security researcher at Cyphort, has revealed that 10 million users may have been affected in just 10 days due to the malvertising and exploit kit campaign. According to the expert, the actors behind the campaign used the well-known Angler exploit kit to compromise millions of computers around the world.
This campaign began around July 11, when experts noticed some infections in countries in Asia, the United States, and Europe.
"Over the past ten days, Cyphort Labs has found many more affected domains – which are shown below. Please do not visit these pages which are dangerous.".
We have reported the issue to e-planning.net and they are actively working to resolve it. At least ten million users have visited these websites and potentially been exposed to the Angler exploit kit in just 10 days according to estimates and data from SimilarWeb.” It is mentioned, among other things, in a post published by the company.
As is common in malvertising campaigns, attackers tend to expose websites with a large number of visitors, in this case among these websites are some that were exploited by hackers to spread the malware ,among them we find sitessuch as the Japanese section of The Huffington Post, Magna entityreadms.com, and the Indonesian newspaper bisnis.com. Below you can see the full list of exposed domains.
"These all appear to be top-rated websites in various countries, including Vietnam, Turkey, Japan, Saudi Arabia, and Germany."
Bilogorskiy confirmed that Cyphort Labs has advised companies affected by the malvertising campaign, including Microsoft Azure, and ad platforms E-Planning.net and adtech.de.
Experts at Cyphort Labs observed that cybercriminals adopted every precautionary method to avoid raising suspicion, such as using multiple SSL redirectors to encrypt traffic.
Below you can see an example of a redirection chain adopted in the campaign:



