Menu
Google nixes widespread malvertising attack

Google nixes widespread malvertising attack

Webmasters were flummoxed when their sites redirected to fraudulent websites hawking products

Webmasters figured out that malicious advertisements served by Google's AdSense were redirecting their users to bogus websites hawking spammy products.

Webmasters figured out that malicious advertisements served by Google's AdSense were redirecting their users to bogus websites hawking spammy products.

Google has stopped a widespread malicious advertising attack that bounced Web surfers to dodgy sites hawking weight loss and skin care products.

The malicious ads were delivered to website owners signed up with Google's AdSense program, wrote Denis Sinegubko, a senior malware researcher with Sucuri, a Delware-based security company. AdSense supplies relevant banner advertisements to websites.

When displayed, the malicious advertisements automatically redirected a person's browser to bogus websites. Those websites were designed to look like legitimate magazines such as Forbes and Good Housekeeping, featuring spammy offerings for anti-aging and brain-enhancing products, among others, Sinegubko wrote.

The attacks persisted since mid-December, spiking last Friday before Google apparently eliminated the malicious advertisements over the weekend, Sinegubko wrote. The problem generated a large number of questions and comments on Google's AdSense help forum.

The type of attack, known as malvertising, has been an ongoing problem for online advertising companies. Scammers will often submit non-malicious ads for approval then swap those out for malicious ones.

Google says that AdSense content is "reviewed by real people and clever machines" before appearing on websites. But the system doesn't appear to be foolproof.

In the AdSense support forum, Google moderators acknowledged the issue and said they were working to block the malicious ads.

Sinegubko wrote that the fake magazine websites were hosted on three domains, none of which show any content if viewed directly. The three domains were only just registered in mid-December, he wrote.

Some affected website owners figured out which advertisements were causing the problem. Banner advertisements that run on a person's site can be reviewed through an AdSense control panel called "Ad Review Center" and blocked if necessary.

Viewed through there, the malicious ads still redirected, giving webmasters a clue as to which ones were problematic.

Two campaigns were identified as malicious, although it was unclear if the accounts running them had possibly been hijacked by the scammers.

A broader issue is whether Google can control advertisements with third-party scripts that cause unauthorized redirects, Sinegubko wrote.

"If Google doesn't control scripts in their ads, AdSense may eventually turn into the largest malvertising platform despite of the still prevailing opinion that Google Ads are probably the most safe ad network out there," he wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags GooglesecuritySucuri

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments