
Advertising -- or more explicitly, "malvertising" -- has long been
a vector for distributing malicious software, but a new, insidious exploit utilizes an innovative model for distributing it. Instead of utilizing a single malvertisement to install malicious code on a
user's device -- usually by redirecting the user to a landing page that automatically download pre-compiled malicious code -- SourTrade does it in clandestine installments, treating the user's browser
as a passive file receiver that functions as an active local compiler or assembler launching the code when it is completed.
You can read more about it in this post by the team at cybersecurity firm Confiant, but it's probably something legitimate advertisers and agencies should be
aware of, because -- well you know, because increasingly sophisticated malvertising exploits could kill legit advertising's golden goose -- by increasing angst among any user fearful of their
browser's security.
advertisement
advertisement
“The attacker is no longer simply sending a malicious file through the advertising ecosystem. The browser is being used as the final assembly point, retrieving
separate components and creating a unique payload on the user’s device," explains The Media Trust Founder-CEO Chris Olson. "That allows the campaign to appear benign during portions of the
delivery chain and makes traditional file-based detection less effective. Protecting consumers requires continuous inspection of what the advertisement causes the browser to do, not only what the ad
or landing page initially appears to contain.”