Malvertising Actor ‘D-Shortiez’ Exploits WebKit Back-Button Hijack in Forced-Redirect Campaign
ID: e3dce186-9c72-5669-a3d4-e1b3f0ffbb84
STIX ID: report--e3dce186-9c72-5669-a3d4-e1b3f0ffbb84
Feed Name: GBHackers
Threat Score
A malvertising campaign attributed to "D‑Shortiez" leverages a WebKit popstate/back‑button handling flaw in Safari and iOS browsers to trap users on fraudulent landing pages via forced redirects; researchers report over 300 million malicious ad impressions in six months (primarily targeting US iOS users), describe adaptive rotating infrastructure and fingerprinting, and recommend closing tabs and stricter ad JavaScript validation until a browser patch is released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
