Yahoo Ad Server Compromise Recap
ID: ba586d56-20e7-59be-b030-f63f7872f198
STIX ID: report--ba586d56-20e7-59be-b030-f63f7872f198
Feed Name: Zscaler Security Research Blog
A malvertising campaign (Jan 1–3) abused Yahoo advertisements to serve malicious iFrames that redirected users to the Magnitude exploit kit; the activity generated ~21,000 transactions and delivered multiple malware families (Zbot, Andromeda, Dorkbot, Tinba, Necurs and various adware). Several compromised landing domains and many randomly generated EK hostnames are enumerated, along with a common hosting IP (193.169.245.78), and investigators halted the campaign after researchers and Yahoo intervened.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
