Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign
ID: b662a35b-6d5c-5ea8-b422-507a324b432f
STIX ID: report--b662a35b-6d5c-5ea8-b422-507a324b432f
Feed Name: cybersecurityNews.com
D-Shortiez is running a large-scale malvertising campaign that abuses a WebKit popstate behavior to hijack the browser back button on iOS Safari, forcing users into scam pages; the campaign delivered over 300 million malicious ad impressions across the US, Canada, and parts of Europe, and was mitigated by Apple’s Safari/iOS security update HT213600. Security teams should apply the patch immediately, audit ad supply chains for redirect-based payloads, and block the actor’s wildcard subdomains at DNS/network layers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
