By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: DeceptionAds Delivers 1M+ Daily Impressions via 3,000 Sites, Fake CAPTCHA Pages
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > DeceptionAds Delivers 1M+ Daily Impressions via 3,000 Sites, Fake CAPTCHA Pages
Tech News

DeceptionAds Delivers 1M+ Daily Impressions via 3,000 Sites, Fake CAPTCHA Pages

By Viral Trending Content 4 Min Read
Share
SHARE

Dec 16, 2024Ravie LakshmananMalvertising / Threat Intelligence

DeceptionAds

Cybersecurity researchers have shed light on a previously undocumented aspect associated with ClickFix-style attacks that hinge on taking advantage of a single ad network service as part of a malvertising-driven information stealer campaign dubbed DeceptionAds.

“Entirely reliant on a single ad network for propagation, this campaign showcases the core mechanisms of malvertising — delivering over 1 million daily ‘ad impressions’ [in the last ten days] and causing thousands of daily victims to lose their accounts and money through a network of 3,000+ content sites funneling traffic,” Nati Tal, head of Guardio Labs, said in a report shared with The Hacker News.

Cybersecurity

The campaigns, as documented by several cybersecurity companies in recent months, involve directing visitors of pirated movie sites and others to bogus CAPTCHA verification pages that instruct them to copy and execute a Base64-encoded PowerShell command, ultimately leading to the deployment of information stealers like Lumma.

The attacks are no longer confined to a single actor, with Proofpoint recently stating that multiple “unattributed” threat clusters have embraced the clever social engineering approach to deliver remote access trojans, stealers, and even post-exploitation frameworks such as Brute Ratel C4.

DeceptionAds

Guardio Labs said it was able to trace the origins of the campaign to Monetag, a platform that claims to offer several ad formats to “monetize websites, social traffic, Telegram Mini Apps,” with threat actors also leveraging services like BeMob ad-tracking to cloak their malicious intent. Monetag is also tracked by Infoblox under the names Vane Viper and Omnatuor.

DeceptionAds

The campaign effectively boils down to this: website owners (i.e., threat actors) register with Monetag, after which traffic is redirected to a Traffic Distribution System (TDS) operated by the malvertising ad network, ultimately taking visitors to the CAPTCHA verification page.

“By supplying a benign BeMob URL to Monetag’s ad management system instead of the direct fake captcha page, the attackers leveraged BeMob’s reputation, complicating Monetag’s content moderation efforts,” Tal explained. “This BeMob TDS finally redirects to the malicious CAPTCHA page, hosted on services like Oracle Cloud, Scaleway, Bunny CDN, EXOScale, and even Cloudflare’s R2.”

Cybersecurity

Following responsible disclosure, Monetag has removed over 200 accounts linked to the threat actor. BeMob, in a similar effort, removed the accounts that were used for cloaking. That said, there are signs that the campaign has resumed again as of December 5, 2024.

The findings once again highlight the need for content moderation and robust account validation to prevent fake registrations.

“From deceptive publisher sites offering pirated or clickbait content to complex redirect chains and cloaking techniques, this campaign underscores how ad networks, designed for legitimate purposes, can be weaponized for malicious activities,” Tal said.

“The result is a fragmented chain of responsibilities, with ad networks, publishers, ad statistics services, and hosting providers each playing a role yet often avoiding accountability.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

How can derailments in workplace leadership cause a toxic triangle?

Amazon vs Perplexity AI: Legal Battle over AI Browser Shopping Access

5 Reasons Why the Motorola Edge 70 is the Super-slim Phone To Buy

Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions

Feeling the Effects of the Time Change? We Asked Experts How to Get Back on Track

TAGGED: CAPTCHA, Cyber Security, Cybersecurity, Information Stealer, Internet, malvertising, Remote Access Trojan, social engineering, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article The Elusive Definition of ‘Deepfake’
Next Article Dune: Prophecy's Sister Francesca Is Stronger Than You Think
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Kingdom Come: Deliverance 2 Director Lambasts the “Static, Scripted” Nature of The Outer Worlds 2
Gaming News
New Five Nights at Freddy's 2 trailer shows off Springtrap, Balloon Boy, and more
Gaming News
Today in History: November 5, Susan B. Anthony defies law and casts vote for president
World News
Meet Mira Nair, Zohran Mamdani’s 68-year-old mother who hit it big in Hollywood directing critical darlings like ‘Monsoon Wedding’
Business
Monero (XMR) jumps to 5-month high as privacy coins lead surprise market rally
Crypto
Strategy’s Bitcoin Position Is Bear-Proof, Analyst Says
Crypto
Should I follow Michael Burry’s lead and sell my red-hot Nvidia stock?
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Kingdom Come: Deliverance 2 Director Lambasts the “Static, Scripted” Nature of The Outer Worlds 2

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Kingdom Come: Deliverance 2 Director Lambasts the “Static, Scripted” Nature of The Outer Worlds 2
November 5, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?