logo

Liveblog: Malvertising from Google advertisements via possibly compromised reseller

ID: de2e393e-b1c3-5186-8b08-ecf7d06e8e78

STIX ID: report--de2e393e-b1c3-5186-8b08-ecf7d06e8e78

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2015-04-07

Date Updated: 2026-04-27

...
...

Fox-IT observed a large-scale malvertising campaign via the Google ad reseller engagelab.com that redirected users to the Nuclear Exploit Kit (exploiting Flash, Java, and Silverlight) and delivered Pony Loader; the report lists observed domains/IPs and the C2 server and recommends blocking the IPs, using ad blockers, and updating vulnerable plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.