Following the Ashley Madison data breach , those unsuspecting people who were planning to meet that special someone online this week are once again at risk. A new malvertising attack has been detected by Malwarebytes researchers, affecting the popular dating site PlentyofFish, which attracts over 3 million users daily..

Those infected receive the Nuclear exploit kit, which can produce all sorts of attacks (such as banking Trojans) on users' computers. Thousands are likely to have been infected.
“The ad network involved in the malvertising campaign (ad.360yield.com) was familiar and it turns out that we had observed it in a rare attack when it was detected by our honeypots just a day before,” explained Malwarebytes researcher Jerome Segura in a blog post . “The redirect chain goes through multiple destinations before reaching its final destination, the landing page with the exploit kit.”
He added: “Given the time frame of both attacks and the ad network involved are the same, the chances are high that pof [dot] com also fell victim to a Trojan.”
PlentyOfFish has been informed of the matter, he said.
Using a dating site for malvertising makes perfect sense given the high average daily visitor count that most of them have. The larger the target audience, the higher the payout.
A report by Bromium Labs research that analyzes the current security risk of popular websites and software recently found that online ads with hidden malware were spread primarily through news websites (32%) and entertainment websites (26%). Notable websites that unknowingly hosted malvertising include: cbsnews.com, nbcsports.com, weather.com, boston.com, and viralnova.com.
