Googleâs DoubleClick Abused to Deliver Miners
ID: 1845c201-7877-5fdd-9cf4-c902f6eb12bf
STIX ID: report--1845c201-7877-5fdd-9cf4-c902f6eb12bf
Feed Name: TrendAI Security Blog
Trend Micro observed a malvertising campaign in January 2018 that hijacked Google DoubleClick ads on high-traffic websites to deliver Coinhive and a modified private web miner, causing a ~285% increase in detections on January 24; the attackers used randomized logic to run either Coinhive or a private miner (to avoid Coinhive fees), configured heavy CPU usage via throttle settings, and the report provides IoCs (file hashes and multiple malicious domains) and recommended countermeasures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
