logo

Yahoo Ad Server Compromise Recap

ID: ba586d56-20e7-59be-b030-f63f7872f198

STIX ID: report--ba586d56-20e7-59be-b030-f63f7872f198

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

A malvertising campaign (Jan 1–3) abused Yahoo advertisements to serve malicious iFrames that redirected users to the Magnitude exploit kit; the activity generated ~21,000 transactions and delivered multiple malware families (Zbot, Andromeda, Dorkbot, Tinba, Necurs and various adware). Several compromised landing domains and many randomly generated EK hostnames are enumerated, along with a common hosting IP (193.169.245.78), and investigators halted the campaign after researchers and Yahoo intervened.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.