Malvertising

Criminals take advantage of manipulated AI ads

Share:

Sophos X-Ops has seen a resurgence in the use of malvertising in various malware campaigns since the beginning of this year, both in its telemetry and in the increased surface of this topic on underground forums. Malvertising, the term for a method of injecting malicious code into digital advertisements, is not a new topic, nor is it a new TTP for attackers.

However, the technology has been used more and more in recent months, possibly due to Microsoft’s new protective measures against malicious macros from the Internet – also a  popular transmission method for malicious code .

During a recent investigation into a criminal marketplace, X-Ops found a number of ads promoting rigged Google Ads accounts and so-called “Black SEO” services. These are services designed to help attackers rank their malicious websites at the top of search results.

BatLoader and IcedID – the malvertising stars

Two of the most notable malware families that have exploited malvertising in recent months are BatLoader and IcedID. IcedID first appeared in 2017 as a banking Trojan designed to steal banking credentials. More recently, attackers have used IcedID to gain access to targeted networks as the first stage of a ransomware attack. Previous IcedID malvertising attacks involved malicious ads distributed via Google ads for office-related communication tools such as Slack, Microsoft Teams, and WebEx.

BatLoader has traditionally been a tool used by cybercriminals to infuse user systems with sophisticatedInfecting  malware , particularly with infostealers like RaccoonStealer . While previous BatLoader malvertising campaigns exploited users’ search for IT tools, more recent campaigns are slinging the hypeUsing artificial intelligence .

Christopher Budd, Director Threat Research at Sophos X-Ops: “Malvertising has many advantages for criminals. Just as legitimate advertisers carefully target their ads, criminals can use malvertising to target users, particularly geographically. In addition, it is often difficult for defenders to detect and combat these types of malware campaigns. Basically, we found that the attackers follow technical trends. The latest malicious ads try to generate clicks not only with popular IT and communication apps, but also with AI tools such as ChatGPT or MidJourney. Increased vigilance is required here, and it is very likely that criminals will continue to expand and professionalize their malvertising campaigns.”

 

(c) it-daily

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:13 pm, Jul 13, 2025
weather icon 23°C
L: 21° | H: 24°
broken clouds
Humidity: 65 %
Pressure: 1011 mb
Wind: 9 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 76%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:58 am
Sunset: 9:13 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
21° | 24°°C 0 mm 0% 15 mph 75 % 1015 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
15° | 21°°C 1 mm 100% 19 mph 84 % 1016 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
15° | 27°°C 0.2 mm 20% 13 mph 85 % 1017 mb 0 mm/h
Thu Jul 17 10:00 pm
weather icon
18° | 27°°C 0.76 mm 76% 10 mph 91 % 1017 mb 0 mm/h
Fri Jul 18 10:00 pm
weather icon
18° | 31°°C 0.53 mm 53% 5 mph 93 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 21°°C 0 mm 0% 5 mph 64 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 18°°C 0 mm 0% 8 mph 68 % 1011 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 10 mph 75 % 1011 mb 0 mm/h
Tomorrow 10:00 am
weather icon
21° | 21°°C 0 mm 0% 12 mph 54 % 1012 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
25° | 25°°C 0 mm 0% 14 mph 36 % 1013 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
25° | 25°°C 0 mm 0% 15 mph 42 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 14 mph 33 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
19° | 19°°C 0 mm 0% 9 mph 46 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,748.44
1.49%
Ethereum(ETH)
€2,555.06
2.19%
XRP(XRP)
€2.43
5.10%
Tether(USDT)
€0.85
0.00%
Solana(SOL)
€138.88
1.69%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.171550
3.01%
Shiba Inu(SHIB)
€0.000011
2.12%
Pepe(PEPE)
€0.000010
2.83%
Peanut the Squirrel(PNUT)
€0.244320
5.81%
Scroll to Top