Malvertising

Criminals take advantage of manipulated AI ads

Share:

Sophos X-Ops has seen a resurgence in the use of malvertising in various malware campaigns since the beginning of this year, both in its telemetry and in the increased surface of this topic on underground forums. Malvertising, the term for a method of injecting malicious code into digital advertisements, is not a new topic, nor is it a new TTP for attackers.

However, the technology has been used more and more in recent months, possibly due to Microsoft’s new protective measures against malicious macros from the Internet – also a  popular transmission method for malicious code .

During a recent investigation into a criminal marketplace, X-Ops found a number of ads promoting rigged Google Ads accounts and so-called “Black SEO” services. These are services designed to help attackers rank their malicious websites at the top of search results.

BatLoader and IcedID – the malvertising stars

Two of the most notable malware families that have exploited malvertising in recent months are BatLoader and IcedID. IcedID first appeared in 2017 as a banking Trojan designed to steal banking credentials. More recently, attackers have used IcedID to gain access to targeted networks as the first stage of a ransomware attack. Previous IcedID malvertising attacks involved malicious ads distributed via Google ads for office-related communication tools such as Slack, Microsoft Teams, and WebEx.

BatLoader has traditionally been a tool used by cybercriminals to infuse user systems with sophisticatedInfecting  malware , particularly with infostealers like RaccoonStealer . While previous BatLoader malvertising campaigns exploited users’ search for IT tools, more recent campaigns are slinging the hypeUsing artificial intelligence .

Christopher Budd, Director Threat Research at Sophos X-Ops: “Malvertising has many advantages for criminals. Just as legitimate advertisers carefully target their ads, criminals can use malvertising to target users, particularly geographically. In addition, it is often difficult for defenders to detect and combat these types of malware campaigns. Basically, we found that the attackers follow technical trends. The latest malicious ads try to generate clicks not only with popular IT and communication apps, but also with AI tools such as ChatGPT or MidJourney. Increased vigilance is required here, and it is very likely that criminals will continue to expand and professionalize their malvertising campaigns.”

 

(c) it-daily

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:31 am, Jun 2, 2025
weather icon 17°C
L: 16° | H: 18°
scattered clouds
Humidity: 55 %
Pressure: 1017 mb
Wind: 10 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:48 am
Sunset: 9:09 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
16° | 18°°C 0 mm 0% 12 mph 55 % 1017 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 20°°C 1 mm 100% 17 mph 92 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
10° | 18°°C 0.8 mm 80% 14 mph 78 % 1009 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
11° | 19°°C 1 mm 100% 16 mph 96 % 1007 mb 0 mm/h
Fri Jun 06 10:00 pm
weather icon
10° | 18°°C 1 mm 100% 16 mph 91 % 1009 mb 0 mm/h
Today 1:00 pm
weather icon
17° | 18°°C 0 mm 0% 8 mph 50 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
20° | 21°°C 0 mm 0% 7 mph 37 % 1016 mb 0 mm/h
Today 7:00 pm
weather icon
19° | 19°°C 0 mm 0% 12 mph 40 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
15° | 15°°C 0 mm 0% 8 mph 55 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
12° | 12°°C 0 mm 0% 8 mph 68 % 1013 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 11°°C 0 mm 0% 11 mph 76 % 1010 mb 0 mm/h
Tomorrow 7:00 am
weather icon
13° | 13°°C 0 mm 0% 15 mph 63 % 1008 mb 0 mm/h
Tomorrow 10:00 am
weather icon
13° | 13°°C 0.84 mm 84% 17 mph 87 % 1006 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,315.06
0.75%
Ethereum(ETH)
€2,189.81
-0.36%
Tether(USDT)
€0.88
0.00%
XRP(XRP)
€1.89
0.68%
Solana(SOL)
€135.64
1.11%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.167554
0.94%
Shiba Inu(SHIB)
€0.000011
0.41%
Pepe(PEPE)
€0.000011
1.14%
Peanut the Squirrel(PNUT)
€0.235838
2.29%
Scroll to Top