Malvertising
TL;DRMalvertising uses online ad networks to spread malware. The episode covers the 2013 Yahoo/CryptoWall ransomware attack, the history of Flash-based exploits, social engineering scams, and hackers hijacking the Revive ad server.
Jordan Bloemen & Scott Francis Winder discuss how to turn popups into paydays with malicious online advertising.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: Internet security has found 20 unwanted files on your computer. Congratulations, you are a winner. Today only, special offer, critical Firefox update. You are randomly selected to participate in this short, amazing, great accomplishment with Fireflies. So y'all remember Yahoo in 2013, right? Seven years ago, Yahoo is getting about 7,000,000,000 monthly visitors. They're generating around a billion bucks a quarter. Times are good. And they're generating most of that revenue off of advertising, the basic economic driver on which most of the modern Internet is built. With the exception of a handful of subscription services, Yahoo, like everyone else, are, and importantly were, selling the eyeballs of their visitors to advertisers. One of the ad networks serving ads on Yahoo and a slew of other AOL owned media properties at the time was called Rubicon Network. Generally speaking, if I want to run an ad on the Internet, I don't go directly to Yahoo or the New York Times or whatever site I want to run ads on, I go to an advertising network. There are hundreds if not thousands, and their job is to serve as middlemen between advertisers and websites. I pay Rubicon. I give them my ad. They serve the ad to Yahoo who runs it for their audience. Yahoo gets paid out. Rubicon takes a cut. My ad reaches its audience. This is the basic economic model that props up the Internet today, and in September 2013, it failed spectacularly. You see, Rubicon and OpenX and a bunch of these advertising networks partner with something called demand side platforms or DSPs, essentially services that let anyone buying ads bid across multiple platforms via one interface. The The DSP serves the ad to the winning network, the network serves it to the site, pretty simple. Until one DSP starts serving ads on the front page of Yahoo and the Atlantic and AOL that delivered malware. Specifically, a piece of ransomware called CryptoWall, which locks up a person's files unless they pay a ransom in Bitcoin. All in, Yahoo alone exposed about 3,000,000 folks a day to this malware. And while we don't know exactly how many were infected total, best estimates say that the people behind the scam were generating about $25,000 a day doing it. Since 2007, people have been figuring out how to use online ads to scam, extort, spy, and grift people online. This last week, a crew of cyber criminals found a new, pretty simple way to get around the walls that ad networks have built up to prevent what people call malvertising, Which makes this as good a time as any to dive into the history, the tricks, and the techniques of turning pop ups into paydays. This is Malvertising, here on hacked. So back in 2007, we bumped into what is the earliest instance that I can find of this term, this this kinda corny term, malvertising. It's a post on a website called the Internet Storm Center, and the poster, a guy named William Saluski writes, malvertising, malicious advertising, is a reasonably fresh take on an online criminal methodology that appears focused on the installation of unwanted or outright malicious software through the use of internet advertising media networks. Which brings up the question, what is an ad? Not in like a philosophical sense, but all the ads we see online, if I wanna run one, what is it that I'm making?
Speaker 2: Well, I think that there's an evolution there where I think the original online ads were just like a JPEG. You know, you bought content or you bought ad properties off of the actual website itself. There wasn't really ad networks. You you gave them leaderboard images, and they just put them and embedded them on their website. Then kind of as the industry evolved, you got into ad distribution networks and content networks, and, you know, automated platforms that deliver these ads in, etcetera. Now we're at the we went to a Flash based ad system where, you know, you could deliver swift files, which were essentially animations or movies that played on websites. And now I think with the kind of the the death of Flash, we're seeing a, increase in HTML five animations, which are essentially full mini web pages that just get embedded into the web page. They're on top rate advertising networks and display ad networks. You'd have a really hard time sliding in some malicious code, but they do take JavaScript, and JavaScript is the language that does a client side. A lot of client side exploits on the web are done through JavaScript.
Speaker 1: I wanna loop back to something that Scott said.
Speaker 2: The death of Flash.
Speaker 1: The death of Flash. That blog post from 2007 that I quoted a few minutes back, the one with the first instance I could find of the term malvertising, describes the most common attack vector for these hacks at the time as being, quote, a result of the client rendering Adobe Flash files. Basically, malvertising attacks were born by people exploiting Flash. Now that's not what killed Flash. What killed Flash was an open letter written by Steve Jobs in 2010 saying that they weren't gonna be supporting it anymore. But Flash is a good way into what Scott kinda described to me as the top scariest tier of malvertising attacks. Attacks that strike at vulnerabilities in your browser and your computer.
Speaker 2: Let's imagine that we had to sit back and get afraid. We would put all of the different types of malvertising into categories. And, like, let's assume, like, Defcon one, the top one, is, like, an ad that's delivered to you when you visit a website, but that ad itself actually also delivers malware at the exact same time onto your computer without you doing anything.
Speaker 1: So let's just hypothetically use Flash as an example of what one of those attacks might look like.
Speaker 2: Yeah. So just think about it like this. Flash delivers essentially a piece of software. So the swift file that Flash exports the movie has code in it. So the person who makes that movie can embed stuff in the code. So, naturally, people found ways to exploit that. In HTML five, the ad is actually a small web page, and you can put code in it, JavaScript and other things. So you can naturally figure out ways to exploit that. Such as? Well, it depends. It depends on how much cleansing and checking is going on at the, Display Network side. So, obviously, you know, Google Display Network knows that people will be looking to exploit these ads, so they take a lot of precautions to make sure that they're not exploitable. Mhmm. But when you get into, you know, wild third party ad networks, the kind of things that you'd find on, like, streaming movie sites and all of the websites that you claim you never go to but always go to, those probably are not scrutinized. So, you know, those forced click ads that you have to click through to get to watch, you know, whatever 1986 movie you're excited to watch, they could be chock full of, you know, bad code, you know, artificial websites, clones, things like that.
Speaker 1: So that's level one, and we call it Scott's hierarchy of malvertising. Malvertising attacks that rely on, and this is important, vulnerabilities that are already in your browser or on your computer. And to Scott explain to me, it really comes back to that pre existing vulnerability.
Speaker 2: I think in today's world, you'd really need with the death of kind of Flash as a as an ad platform, in today's world, you'd really need to have a known exploit. You'd have to have a zero day or something that you could exploit to to force and execute a piece of malware onto a a viewer's computer. Often, after I've been doing some, you know, Internet browsing in places where I probably shouldn't be, my downloads folders often got three or four executables in it. And that's just kinda how that works.
Speaker 1: Which brings us to level two. Adds that download files you do not want.
Speaker 2: I think level two is probably an ad that does something similar, but instead of delivering the malware and exploiting something on your computer to have it installed, this actually delivers the executable or the malware code to your computer. So it hasn't been run yet, but it's been deployed to you. So any kind of accidental click, any kind of automatic open, anything like that will trigger it.
Speaker 1: An ad on the Internet is made up of two parts. There's what you see and where it goes. There's an ad with a bunch of sneakers that takes you to a sneaker store if you click on it. But there's this other kind of ad, an ad for sneakers that doesn't take you to a sneaker store. It takes you somewhere else. Else.
Speaker 2: If you imagine, like, the two principal parts of an ad are the thing that's displayed to you and the destination when it's been clicked on. You know, I think that's basic two things that are in all ads on the Internet. You know? Showing something to the user, and if they click on it, taking them somewhere. Where you take them is very independent. So, you know, I might show an ad for and if it's on a CD ad network, I might show an ad for hackedpodcast.com. When you click on that ad, it might take you somewhere very differently.
Speaker 1: At which point, you take them to the executable file that downloads the malware.
Speaker 2: And if it's a forced click ad, I e something that's an overlay on top of a video I'm trying to watch and I have to click it to remove it, all of a sudden I'm downloading multiple executable files. If I had always run clicked on my dot EXE's for downloads, boom.
Speaker 1: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's going to work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 3: Sierra has all the best active and outdoor brands for the super athletic stuff, like running gear for cruising up the trail. Whoo. And the super athletic stuff, like fishing gear for chilling by the creek. Nice cast. Fitness apparel to push for higher reps. You got this. And golf balls priced so you could afford to lose one. Or a few. Head to Sierra or sierra.com for the brands you want at the prices that let you do it all. From athletic to athletic ish, Sierra's got it.
Speaker 1: In 2009, the New York Times helped build a botnet. It's mid September, and visitors to the New York Times are being served advertisements telling them that their system is infected, trying to trick them into installing rogue security software onto their computers. Software was actually hijacking those computers into something called the Bahama botnet, a big network of computers that the hacker could control and wield like a blunt instrument online, attacking and taking down other sites. What's interesting about this hack is it doesn't sound like the culprit went through a network, They went straight to the source. New York Times spokeswoman Diane McNulty said, quote, the culprit approached the newspaper as a national advertiser and had provided apparently legitimate ads for weeks. They called up the newspaper, ran a bunch of real ads for weeks, and then swapped them out for scam ads. In the first half of the show, we talked about the first two kinds of malvertising, the kind where the hack runs the second ad is even shown, and the kind where a malicious file is delivered via drive by download. Which brings us to the third category, where the vulnerability isn't your browser or your computer, it's you. Well, I
Speaker 2: think that's, you know, something that you're familiar with, and we talk about social engineering always as part of a hack and tricking somebody. You know, I'm not gonna lie, my mother and mother-in-law have both called me for the same problem, and it's a large screen takeover saying Microsoft Corporation has detected malware on their computer. And they need to call this 1800 number, talk to this perfectly nice customer service person who then asked them to send them money. And it's like, you know, that's not explicitly malware, but it's not non malware. And I'm sure if you were to get roped into their scheme, they would probably happily deliver an EXE with malware onto your computer at the same time. So, you know, taking taking advantage of people's lack of knowledge or lack of comfort.
Speaker 1: So we've got ads that exploit vulnerabilities in the browser, the computer, and the viewer. But there is this whole other way, the thing that sparked us talking about this subject this week at all. Since August 2019, hackers have been targeting ad networks running an old version of an open sourced ad server called Revive. Instead of using networks to run dodgy ads, they just hacked the whole network.
Speaker 2: Yeah. This is, like, the real this is the hacker's solution. Like, this isn't just this isn't the Russian malware solution. This is like the Russian hacker's solution, where it's like, how can we exploit something that exists? This is how can we take over and change something that exists to do what we want it to.
Speaker 1: Imagine all of the wild shit you could do if you took over an ad network.
Speaker 2: I think taking over an ad network and taking over actually physically taking over the servers or, I guess, virtually taking over the servers would give you just tons of benefits because you'd literally be able to go in, add your own insertions. So, like, set up your own ads. You'd be able to bypass and change any rules and restrictions on those ads. You'd be able to target specific websites that you wanted those ads to show. You'd have nobody and no systems, doing any kind of sanity checks on your ads. So they could be ads for, like, Oprah Winfrey's new book club and have nothing to do the destination and everything. The other part of them would have nothing to do with it because there's nobody literally reviewing or checking anything.
Speaker 1: Mhmm.
Speaker 2: Like, I don't know if anybody out there has done anything on, like, Facebook, and they have rigorous ad policies, and they adhere them, and they have automated AI systems that verify and check things. And then they go if they fail AI checks, they go to human verification. And it's like there's this, you know, massive tiers of things that you'd have to bypass to, like, get malware onto, like, a Facebook ad. It'd be probably virtually impossible. But if you control the ad network, there's no checks. You're literally in the back end system inserting your own ads, telling them where to go and artificially saying that you've purchased x amount of space. So you'd be able to distribute them wide and far without anybody really noticing until they noticed. Mhmm.
Speaker 1: That seems like it would have, a lot of utility even outside of just trying to deliver malware. If you suddenly had the ability to run unlimited ads, like, think about what you can do with an advertisement, especially at volume.
Speaker 2: Totally. You
Speaker 1: can bend the wheel of democracies. Like, you can do
Speaker 2: all kinds of crazy crap. Yeah. For sure. For sure. I never I didn't take it political, but I see your point. But I was thinking about, like, I could be the next, you know, luggage mogul.
Speaker 1: Oh, yeah.
Speaker 2: Or, like, whatever it is. It seems to be every day some online company spins up that makes the best version of something that we've had Sure. For a hundred years.
Speaker 1: Your pastel millennial brand that sells, like, the finest socks you can possibly buy. Best socks.
Speaker 2: We should probably not knock them because they'll probably hopefully become advertisers in our podcast.
Speaker 1: Which brings us to this ad for Billy's socks. If you were to open up Google Chrome and go to the extensions storefront and you were to look at the top charts for browser extensions well, first off, you actually can't because Google doesn't have top charts the way that the App Store does, and I think I know why. But if you were to open up Chrome, a browser made by Google, a company that made 70% of its $134,000,000,000 profit off of advertising, you'll find that some of the most popular extensions for this browser are little pieces of software called ad blockers. And this discussion of malvertising begs the question,
Speaker 2: how do they work? The basic explanation for how it works is essentially ads have a fingerprint, and the ad blocker recognizes the fingerprint in the HTML code and hides it. That's essentially the basic premise of how it works. And if inside of that HTML code that it would have loaded as the ad was the malicious code, that malicious code no longer gets loaded and executed locally on the client side browser. So that's essentially how it stops it. So it is also how it stops the entire ad network and ad world online working, which then doesn't allow your favorite, you know, video game review site to get paid for you to read their articles. And actually, there's a beautiful thing happening where it's like, I don't think I've been to a quality like, I have an ad blocker, and I probably shouldn't. And when I go to a lot of quality content sites, the New York Times, the Bloombergs, the IGNs, they immediately see that I have an ad blocker. So they've refingerprinted when a browser has an ad blocker, and then they prevent you from getting access to their code unless you modify the code live, but you don't have to do that. So they've they've kind of rehacked the hack. You know? And it it seems to be more and more so only on legitimate sites. There haven't been any illegitimate sites that are asking me to turn off my ad blocker. So it seems to be kind of a a positive social pressure and a plea for, like, hey. You don't pay for this content. Please at least let us make a few sense from showing ads to you.
Speaker 1: The longer you think about it, the weirder our relationship with ads starts to seem. They're annoying and as we've learned, potentially malicious, and yet, we don't have a great scalable alternative. They pay for the stuff we like, and yet you really couldn't be blamed for having a piece of software that explicitly blocks them from doing that.
Speaker 2: The like, you we were talking about or we can talk about, we haven't talked about, we texted briefly about, you know, people's trust in an ad link versus their trust in a link say that they get in an email. It's like I think we've all become so accustomed to getting spam that we know, and phishing and stuff like this has become so routine in our lives that we don't click links in email unless we trust them. I think people just inherently have a different trust for ads, and that's very exploitable. You know, which taken us, what, thirty years to train people not to click links in email, and people still click them all the time. It's gonna take us longer, and it's gonna be a huge change for the ad, you know, world as advertising is mostly funneling online. Imagine if people just stop trusting advertisements.
Speaker 1: At very least, the media landscape would look completely different if we were paying for stuff piecemeal.
Speaker 2: Oh, a 100%. Like, literally everything, like Twitch streaming to, you know, online media sites to, you know, the COVID twenty nineteen Post Malone Nirvana livestream that was out last weekend. That literally was funded by ad dollars. You could see ad placements of products in the background, It'll be it Bud Light or whatever the water sponsor was they had. Like, there was literally obvious ad placements in that livestream. That's like, you know, everything that's done on the Internet has to get funded somehow, and advertising seems to be the way to fund it.
Speaker 1: Hey, everybody. Thank you for listening. Little update for you. For the last two months, we've been doing weekly updates between our monthly episodes. We asked you all for feedback about this, and a bunch of people reached out and expressed excitement over us putting more time into the big monthly episodes. Some folks rightly pointed out that the shorter the episodes got, the longer the ads felt. And this episode's subject matter was, I'm sure, completely uninspired by that genuinely helpful feedback. So we will be back with a news update in two weeks instead of one with regular episodes on the last Tuesday of the month with the goal being we're gonna put more time, more energy, more love into those big episodes. Thank you all for listening, and Scott and I are gonna catch you here on the next episode of Hack.
Speaker 4: From lashes for days with the Viral Liquid Lash Extensions mascara to awakening your eyes with lift and color from the brilliant eye brightener, Thrive Cosmetics is the go to when you want to amplify your everyday look. Plus, every product is 100% vegan, cruelty free, and made with clean skin loving ingredients that work with your skin. And for every product purchased, Thrive Cosmetics donates to help communities thrive. So every time you use your favorite Thrive Cosmetics product, you're helping communities you care about too. Amplify your everyday. Go to thrivecosmetics.com/shine26 for an exclusive offer of 20% off your first order. That's thrive cosmetics, causemetics,.com/shine20six.
Speaker 5: Summer weekends are all about family, sunshine, and making memories together. Before everyone arrives, I stop by my local Total Wine and More to pick up a great bottle, maybe a favorite we already love, or something new to enjoy with dinner on the patio. With so many bottles to choose from, it's easy to discover something amazing. And with the lowest prices, it's easy to grab an extra bottle for the table. Not sure what to pick? Their friendly guides are always there to help. Find what you love and love what you find only at Total Wine and more. Curbside pickup and delivery available in most areas. Visit totalwine.com to learn more. Spirits not sold in Virginia and North Carolina. Drink responsibly. Must be 21.