Skip to main content

CBS-affiliated Television Stations Expose Visitors to Angler Exploit Kit

  • May 4, 2016
  • 2 replies
  • 1 view

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
May 4, 2016  BY Jérôme Segura
 
                                         


 

A rogue advertiser managed to subvert the Ta.gify self-serve ad platform to push the Angler exploit kit to unsuspecting visitors of two CBS affiliated TV stations. One in St. Louis called KMOV, and the other WBTV, is located in Charlotte, North Carolina.
 
This malvertising attack leveraged a familiar technique of hijacking GoDaddy accounts to create various subdomains pointing to malicious servers. These are used to host the ad content (JavaScript, image, etc.) but also to hide malicious code and alternate between clean and infected adverts depending on multiple factors (time of day, user agent, IP blacklist, etc).
 
Full Article

2 replies

Baldrick
Gold VIP
  • Gold VIP
  • May 4, 2016
Well, for ingenuity that has to take the biscuit...how the hell did they come up with that. :S

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
They are becoming increasingly adept at getting past security systems.