logo

Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign

ID: b662a35b-6d5c-5ea8-b422-507a324b432f

STIX ID: report--b662a35b-6d5c-5ea8-b422-507a324b432f

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

D-Shortiez is running a large-scale malvertising campaign that abuses a WebKit popstate behavior to hijack the browser back button on iOS Safari, forcing users into scam pages; the campaign delivered over 300 million malicious ad impressions across the US, Canada, and parts of Europe, and was mitigated by Apple’s Safari/iOS security update HT213600. Security teams should apply the patch immediately, audit ad supply chains for redirect-based payloads, and block the actor’s wildcard subdomains at DNS/network layers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.