Criminals take advantage of manipulated AI ads

Share:

Sophos X-Ops has seen a resurgence in the use of malvertising in various malware campaigns since the beginning of this year, both in its telemetry and in the increased surface of this topic on underground forums. Malvertising, the term for a method of injecting malicious code into digital advertisements, is not a new topic, nor is it a new TTP for attackers.

However, the technology has been used more and more in recent months, possibly due to Microsoft’s new protective measures against malicious macros from the Internet – also a  popular transmission method for malicious code .

During a recent investigation into a criminal marketplace, X-Ops found a number of ads promoting rigged Google Ads accounts and so-called “Black SEO” services. These are services designed to help attackers rank their malicious websites at the top of search results.

BatLoader and IcedID – the malvertising stars

Two of the most notable malware families that have exploited malvertising in recent months are BatLoader and IcedID. IcedID first appeared in 2017 as a banking Trojan designed to steal banking credentials. More recently, attackers have used IcedID to gain access to targeted networks as the first stage of a ransomware attack. Previous IcedID malvertising attacks involved malicious ads distributed via Google ads for office-related communication tools such as Slack, Microsoft Teams, and WebEx.

BatLoader has traditionally been a tool used by cybercriminals to infuse user systems with sophisticatedInfecting  malware , particularly with infostealers like RaccoonStealer . While previous BatLoader malvertising campaigns exploited users’ search for IT tools, more recent campaigns are slinging the hypeUsing artificial intelligence .

Christopher Budd, Director Threat Research at Sophos X-Ops: “Malvertising has many advantages for criminals. Just as legitimate advertisers carefully target their ads, criminals can use malvertising to target users, particularly geographically. In addition, it is often difficult for defenders to detect and combat these types of malware campaigns. Basically, we found that the attackers follow technical trends. The latest malicious ads try to generate clicks not only with popular IT and communication apps, but also with AI tools such as ChatGPT or MidJourney. Increased vigilance is required here, and it is very likely that criminals will continue to expand and professionalize their malvertising campaigns.”

 

(c) it-daily

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:14 pm, Jan 13, 2025
weather icon 4°C
L: 2° | H: 5°
overcast clouds
Humidity: 86 %
Pressure: 1037 mb
Wind: 5 mph WSW
Wind Gust: 14 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 8:00 am
Sunset: 4:17 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
2° | 5°°C 0 mm 0% 7 mph 97 % 1037 mb 0 mm/h
Wed Jan 15 9:00 pm
weather icon
5° | 9°°C 0 mm 0% 4 mph 99 % 1035 mb 0 mm/h
Thu Jan 16 9:00 pm
weather icon
5° | 9°°C 0 mm 0% 4 mph 97 % 1036 mb 0 mm/h
Fri Jan 17 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 4 mph 89 % 1036 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 4 mph 86 % 1035 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 4°°C 0 mm 0% 7 mph 82 % 1037 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 7 mph 81 % 1036 mb 0 mm/h
Tomorrow 6:00 am
weather icon
4° | 4°°C 0 mm 0% 7 mph 83 % 1035 mb 0 mm/h
Tomorrow 9:00 am
weather icon
4° | 4°°C 0 mm 0% 5 mph 85 % 1036 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
7° | 7°°C 0 mm 0% 6 mph 78 % 1035 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 4 mph 89 % 1034 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
7° | 7°°C 0 mm 0% 4 mph 97 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
7° | 7°°C 0 mm 0% 4 mph 97 % 1035 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,111.11
-0.59%
Ethereum(ETH)
€3,044.42
-5.19%
XRP(XRP)
€2.45
-0.87%
Tether(USDT)
€0.98
0.01%
Solana(SOL)
€178.54
-3.41%
Dogecoin(DOGE)
€0.328505
-0.84%
USDC(USDC)
€0.98
0.01%
Shiba Inu(SHIB)
€0.000021
-3.14%
Pepe(PEPE)
€0.000017
-6.51%
Peanut the Squirrel(PNUT)
€0.55
-5.66%
Scroll to Top