Malvertising

Criminals take advantage of manipulated AI ads

Share:

Sophos X-Ops has seen a resurgence in the use of malvertising in various malware campaigns since the beginning of this year, both in its telemetry and in the increased surface of this topic on underground forums. Malvertising, the term for a method of injecting malicious code into digital advertisements, is not a new topic, nor is it a new TTP for attackers.

However, the technology has been used more and more in recent months, possibly due to Microsoft’s new protective measures against malicious macros from the Internet – also a  popular transmission method for malicious code .

During a recent investigation into a criminal marketplace, X-Ops found a number of ads promoting rigged Google Ads accounts and so-called “Black SEO” services. These are services designed to help attackers rank their malicious websites at the top of search results.

BatLoader and IcedID – the malvertising stars

Two of the most notable malware families that have exploited malvertising in recent months are BatLoader and IcedID. IcedID first appeared in 2017 as a banking Trojan designed to steal banking credentials. More recently, attackers have used IcedID to gain access to targeted networks as the first stage of a ransomware attack. Previous IcedID malvertising attacks involved malicious ads distributed via Google ads for office-related communication tools such as Slack, Microsoft Teams, and WebEx.

BatLoader has traditionally been a tool used by cybercriminals to infuse user systems with sophisticatedInfecting  malware , particularly with infostealers like RaccoonStealer . While previous BatLoader malvertising campaigns exploited users’ search for IT tools, more recent campaigns are slinging the hypeUsing artificial intelligence .

Christopher Budd, Director Threat Research at Sophos X-Ops: “Malvertising has many advantages for criminals. Just as legitimate advertisers carefully target their ads, criminals can use malvertising to target users, particularly geographically. In addition, it is often difficult for defenders to detect and combat these types of malware campaigns. Basically, we found that the attackers follow technical trends. The latest malicious ads try to generate clicks not only with popular IT and communication apps, but also with AI tools such as ChatGPT or MidJourney. Increased vigilance is required here, and it is very likely that criminals will continue to expand and professionalize their malvertising campaigns.”

 

(c) it-daily

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:44 pm, Apr 1, 2025
weather icon 8°C
L: 7° | H: 9°
clear sky
Humidity: 78 %
Pressure: 1024 mb
Wind: 11 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 1%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:35 am
Sunset: 7:32 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
7° | 9°°C 0 mm 0% 16 mph 75 % 1024 mb 0 mm/h
Thu Apr 03 10:00 pm
weather icon
9° | 16°°C 0 mm 0% 11 mph 84 % 1021 mb 0 mm/h
Fri Apr 04 10:00 pm
weather icon
10° | 18°°C 0 mm 0% 13 mph 84 % 1022 mb 0 mm/h
Sat Apr 05 10:00 pm
weather icon
7° | 17°°C 0 mm 0% 12 mph 73 % 1022 mb 0 mm/h
Sun Apr 06 10:00 pm
weather icon
7° | 13°°C 0 mm 0% 11 mph 78 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
8° | 8°°C 0 mm 0% 10 mph 75 % 1023 mb 0 mm/h
Tomorrow 4:00 am
weather icon
7° | 7°°C 0 mm 0% 9 mph 75 % 1024 mb 0 mm/h
Tomorrow 7:00 am
weather icon
8° | 8°°C 0 mm 0% 11 mph 73 % 1024 mb 0 mm/h
Tomorrow 10:00 am
weather icon
12° | 12°°C 0 mm 0% 14 mph 59 % 1023 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
14° | 14°°C 0 mm 0% 15 mph 49 % 1022 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
13° | 13°°C 0 mm 0% 16 mph 54 % 1021 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
12° | 12°°C 0 mm 0% 12 mph 61 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 11°°C 0 mm 0% 11 mph 68 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€78,992.63
3.20%
Ethereum(ETH)
€1,774.50
4.91%
Tether(USDT)
€0.93
0.02%
XRP(XRP)
€1.99
2.67%
Solana(SOL)
€117.15
0.39%
USDC(USDC)
€0.93
0.00%
Dogecoin(DOGE)
€0.160487
4.26%
Shiba Inu(SHIB)
€0.000012
2.64%
Pepe(PEPE)
€0.000007
6.92%
Scroll to Top