On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

October 27th, 2009

Malware ads served from Gizmodo

Posted by Ryan Naraine @ 10:04 am

Categories: Adobe, Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Facebook, Flash, Locally Running Web Servers, Malware, Passwords, Social Networking Applications, Spam and Phishing, Spyware and Adware

Tags: Advertisement, Blog, Malware, Gizmodo, Ryan Naraine

[ UPDATE: Dancho has more details on this attack ]

Popular gadget blog Gizmodo has acknowledged falling victim to an “elaborate scam” that served malicious ads for scareware (fake anti-virus) to its readers.

In an apology posted online, Gizmodo said the its ad sales team was tricked into running malicious ads purporting to be from Suzuki.  This follows a similar attack that affected advertisements served from the New York Times site.

Here’s the note from Gizmodo’s editor:

Guys, I’m really sorry but we had some malware running on our site in ad boxes for a little while last week on Suzuki ads. They somehow fooled our ad sales team through an elaborate scam. It’s taken care of now, and only a few people should have been affected, but this isn’t something we take lightly as writers, editors and tech geeks. (And we would have noticed sooner except everyone on staff is on OS X or Linux for production machines.) Everything should be cleared up but you should be checking “qegasysguard.exe” if you’re experiencing random popups. Be careful, load up some antivirus and make sure your system is clean. I’m sorry.

Here’s a good primer from SANS on the malvertising scourge.  Also see Dancho’s ultimate guide to scareware protection.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 6 Talkback(s)
They may all have potential vulnerabilities but not all of them make it...
easy on malware writers.

As far as I know there is only one family of OSes that does that. (Read the rest)
Posted by: The Mentalist Posted on: 10/27/09 You are currently: a Guest | | Terms of Use
Disclosure please!  Joe_Raby | 10/27/09
Disclosure please!  n0neXn0ne | 10/27/09
Is is really needed?  The Mentalist | 10/27/09
Many  AzuMao | 10/27/09
All of them...  mrlinux | 10/27/09
They may all have potential vulnerabilities but not all of them make it...  The Mentalist | 10/27/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here