The HookAds Malvertising campaign is on the loose again and is downloading various malware through the Fallout Exploit kit.
Mike Bittner, Digital Security & Operations Manager at The Media Trust:
“Bad actors behind the HookAds campaign appear to be switching their tactics and adding more weapons to their arsenal to make a clean sweep of their targets. It appears they have joined forces with distributors of Danabot, a banking trojan, either as part of a larger North American Danabot campaign that splits profits among various bad actors or as a renter of the malware. Other DanaBot campaigns in the region involved the use of eFax digital faxes. The Hook Ads malicious campaign makes use of an earlier campaign’s tactics: compromising adult websites and using an extensive network of rogue ad domains masquerading as legitimate advertising platforms. Two years ago, the campaign fed traffic into the RIG exploit, this year, it feeds traffic to the Fallout exploit kit. The tactical switch was likely done to target users who are less likely to update or patch legacy desktops used to conduct a wide array of personal transactions online, such as paying bills, shopping, etc. These machines likely store a lot of personal, sensitive information, so taking over them would give bad actors access to all of it. But to ensure they are able to scrape as much information as they can, they have also used Nocturnal Stealer to obtain passwords and information from Chrome and Firefox browsers, as well as rob cryptocurrency wallets.”
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.