Description

As per sources, a new cyber attack campaign named Deception Ads, has been uncovered by cybersecurity experts. This attack focuses on exploiting a single ad network, using malvertising to target unsuspecting users. The campaign involves over 1 million daily ad impressions and affects thousands of victims by stealing their accounts and money. The malicious activity primarily impacts websites with pirated content, which redirect users to fake CAPTCHA pages that lead to the installation of information-stealing malware like Lumma. The attack begins when website owners register with the ad network Monetag, which then redirects users to a Traffic Distribution System (TDS). This system directs users to a fake CAPTCHA page where they are tricked into executing a malicious PowerShell command. The attackers use services like BeMob ad-tracking to disguise the malicious content, making it harder for security measures to detect the threat. The campaign was active for several months and saw significant growth in daily attacks, reaching thousands of victims. Furthermore, Monetag has removed over 200 accounts related to the threat actors, and BeMob has taken action to eliminate accounts used for cloaking. Despite these efforts, the campaign appears to have resumed in December 2024. The incident highlights the importance of effective content moderation and account validation to prevent similar attacks in the future. The attack shows how legitimate ad networks can be manipulated for malicious purposes, making it essential for ad services and hosting providers to take responsibility for such incidents.