Miscreants turn to ad tech to measure malware metrics

microsoft, miscreants turn to ad tech to measure malware metrics

Miscreants turn to ad tech to measure malware metrics

Now that’s what you call dual-use tech

Cyber baddies have turned to ad networks to measure malware deployment and to avoid detection, according to HP Wolf Security.…

The security group’s Q4 2024 Threat Insights Report finds criminals have adopted ad tech tools to make their social engineering attacks more effective.

“Cyber criminals are applying the same tools a business might use to manage a marketing campaign to optimize their malware campaigns, increasing the likelihood the user will take the bait,” explained Ian Pratt, global head of security for personal systems at HP, in a statement.

The DarkGate PDF malware campaign, for example, relies on ad tools. Dating back to 2018, DarkGate provides backdoor access to victim’s computers for the purpose of data theft and ransomware.

The campaign involves sending email messages to victims with malicious PDF attachments. Those duped into opening one see a social engineering message – often in the form of a Microsoft OneDrive error message that prompts the victim to click a link to download the document.

The report explains that this often works because the attackers know that office workers rely on cloud-based applications with user interfaces that often change. This makes it more difficult to spot fake interface elements or bogus error messages.

Clicking on the fake OneDrive error message does not immediately download the malware payload. Rather, it routes the victim’s click – containing identifiers and the domain hosting the file – through an advertising network and then it fetches the malicious URL, which is not evident in the PDF.

“Using an ad network as a proxy helps the attacker to evade detection and collect analytics on who clicks their links,” the report explains. “Since the advertising network uses CAPTCHAs to verify real users to prevent click fraud, it’s unlikely automated malware analysis systems would be able to scan the malware payload, leading to the risk of falsely classifying the file as safe.”

According to HP Wolf Security, 11 percent of malware analyzed in Q4 2023 relied on PDFs for delivery – up from 4 percent in Q1 and Q2 that same year. As an example, the security biz points to the WikiLoader campaign, which used a fake parcel delivery PDF to spread malware known as Ursnif.

The security biz also notes that it’s seeing more Office exploits and fewer macro-enabled attacks. During Q4, about 84 percent of attempted intrusions incorporated spreadsheets, while 73 percent involved Word documents

Finally, the report notes that attackers continue to host malware on cloud services as a way to benefit from the trust users may place in these platforms. The analysts point to the Remcos remote access trojan, which relies on a user downloaded JavaScript file hosted on chat service Discord. The malicious file then connects to file sharing service TextBin to fetch a Base64 encoded executable hosted there.

While the attacks may be more sophisticated, Pratt’s advice for countering them remains the same: “To protect against well-resourced threat actors, organizations must follow zero trust principles, isolating and containing risky activities like opening email attachments, clicking on links, and browser downloads.” ®

News Related

OTHER NEWS

Lawsuit seeks $16 million against Maryland county over death of pet dog shot by police

A department investigator accused two of the officers of “conduct unbecoming an officer” for entering the apartment without a warrant, but the third officer was cleared of wrongdoing, the suit says. Read more »

Heidi Klum shares rare photo of all 4 of her and Seal's kids

Heidi Klum posted a rare picture with husband Tom Kaulitz and her four kids: Leni, 19, Henry, 18, Johan, 17, and Lou, 14, having some quality family time. Read more »

European stocks head for flat open as markets struggle to find momentum

This is CNBC’s live blog covering European markets. European markets are heading for a flat open Tuesday, continuing lackluster sentiment seen at the start of the week in the region ... Read more »

Linda C. Black Horoscopes: November 28

Nancy Black Today’s Birthday (11/28/23). This year energizes your work and health. Faithful domestic routines provide central support. Shift directions to balance your work and health, before adapting around team ... Read more »

Michigan Democrats poised to test ambitious environmental goals in the industrial Midwest

FILE – One of more than 4,000 solar panels constructed by DTE Energy lines a 9.37-acre swath of land in Ann Arbor Township, Mich., Sept. 15, 2015. Michigan will join ... Read more »

Gaza Is Falling Into ‘Absolute Chaos,’ Aid Groups Say

A shaky cease-fire between Israel and Hamas has allowed a surge of aid to reach Palestinians in Gaza, but humanitarian groups and civilians in the enclave say the convoys aren’t ... Read more »

Bereaved Israeli and Palestinian families to march together in anti-hate vigil

Demonstrators march against the rise of antisemitism in the UK on Sunday – SUSANNAH IRELAND/REUTERS Bereaved Israeli and Palestinian families will march together as part of an anti-hate vigil on ... Read more »
Top List in the World