Google nixes widespread malvertising attack

Webmasters were flummoxed when their sites redirected to fraudulent websites hawking products

Webmasters figured out that malicious advertisements served by Google's AdSense were redirecting their users to bogus websites hawking spammy products.

Webmasters figured out that malicious advertisements served by Google's AdSense were redirecting their users to bogus websites hawking spammy products.

Google has stopped a widespread malicious advertising attack that bounced Web surfers to dodgy sites hawking weight loss and skin care products.

The malicious ads were delivered to website owners signed up with Google's AdSense program, wrote Denis Sinegubko, a senior malware researcher with Sucuri, a Delware-based security company. AdSense supplies relevant banner advertisements to websites.

When displayed, the malicious advertisements automatically redirected a person's browser to bogus websites. Those websites were designed to look like legitimate magazines such as Forbes and Good Housekeeping, featuring spammy offerings for anti-aging and brain-enhancing products, among others, Sinegubko wrote.

The attacks persisted since mid-December, spiking last Friday before Google apparently eliminated the malicious advertisements over the weekend, Sinegubko wrote. The problem generated a large number of questions and comments on Google's AdSense help forum.

The type of attack, known as malvertising, has been an ongoing problem for online advertising companies. Scammers will often submit non-malicious ads for approval then swap those out for malicious ones.

Google says that AdSense content is "reviewed by real people and clever machines" before appearing on websites. But the system doesn't appear to be foolproof.

In the AdSense support forum, Google moderators acknowledged the issue and said they were working to block the malicious ads.

Sinegubko wrote that the fake magazine websites were hosted on three domains, none of which show any content if viewed directly. The three domains were only just registered in mid-December, he wrote.

Some affected website owners figured out which advertisements were causing the problem. Banner advertisements that run on a person's site can be reviewed through an AdSense control panel called "Ad Review Center" and blocked if necessary.

Viewed through there, the malicious ads still redirected, giving webmasters a clue as to which ones were problematic.

Two campaigns were identified as malicious, although it was unclear if the accounts running them had possibly been hijacked by the scammers.

A broader issue is whether Google can control advertisements with third-party scripts that cause unauthorized redirects, Sinegubko wrote.

"If Google doesn't control scripts in their ads, AdSense may eventually turn into the largest malvertising platform despite of the still prevailing opinion that Google Ads are probably the most safe ad network out there," he wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags GooglesecuritySucuri

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?