Researchers from HUMAN have taken down a sizeable ad fraud scheme that spoofed more than 1,700 apps and managed to generate 12 billion ad requests a day.
By injecting JavaScript into the ads, the scammers were able to layer multiple ads, registering views for ads that users did not see. HUMAN dubbed the malicious campaign Vastflux.
Note
- Ad botnets/malvertising attacks are a constant and this is reminder that if your company pays for ads or takes revenue from ad placement, advertising networks have to be considered as part of your supply chain security and user awareness programs. In particular, increased use of MFA will bring increased “MFA fatigue” attacks, which share a lot of evil DNA with ad stacking attacks. Use this one as impetus for an awareness push to users and management.
Read more in