YNOT
  • Home
  • Industry News
    • Adult Business News
    • Adult Novelty News
    • YNOT Magazine
    • EU News
    • Opinions
    • Picture Galleries
  • PR Wire
    • Adult Company News
    • Adult Retail News
    • Adult Talent News
    • Adult Videos News
  • Podcasts
  • Industry Guides
    • Adult Affiliate Guide
    • Affiliate Marketing for Beginners
    • Top Adult Traffic Networks
    • Top Adult PR Agents
    • Funding an Adult Business
  • Business Directory
    • View Categories
    • View Listings
    • Submit Listing
  • Newsletters
  • Industry Events
    • Events Calendar
    • YNOT Cam Awards | Hollywood
    • YNOT Awards | Prague
    • YNOT Cammunity
    • YNOT Summit
    • YNOT Reunion
  • Login with YNOT ID

Pornhub, TrafficJunky Shut Down Major Malvertising Hub

Posted On 10 Oct 2017
By : Marty O'Brien

A click-fraud malvertising attack that has hidden in the shadows for more than a year lost a major distribution vector when advertising network TrafficJunky and adult tube site Pornhub shut down a pathway that exposed millions of porn-site visitors in the U.S., Canada, U.K. and Australia to infection by Kovter malware.A click-fraud malvertising attack that has hidden in the shadows for more than a year lost a major distribution vector when advertising network TrafficJunky and adult tube site Pornhub shut down a pathway that exposed millions of porn-site visitors in the U.S., Canada, U.K. and Australia to infection by Kovter malware.

The malicious-redirect attack, mounted by the KovCoreG Group, is ongoing and continues to affect other sites, according to the researchers at Proofpoint who spotted the exploit. Pornhub was of more concern than most because the site receives about 9 million unique visitors daily, they said.

“We do not have data on the precise length of time that Pornhub and TrafficJunky were compromised but, as noted, we know that the KovCoreG Group has been using this type of attack on multiple sites for over a year,” Proofpoint Vice President of Operations Kevin Epstein told Threatpost. “It is likely that Pornhub, in particular, was being abused for some time, although both Pornhub and TrafficJunky moved very quickly to address the issue as soon as we informed them of the problem.”

The user-facing attack combines social engineering with a slight variation of the tried-and-true fake browser update scheme to distribute Kovter click-fraud malware. The ruse works with all three major Windows web browsers.

Kovter is particularly vexing because it employs a unique triple-threat persistence mechanism that drops a registry entry, a .bat file shortcut and the .bat file itself into the victim’s operating system.

“Despite dramatic declines in exploit kit activity over the last year, malvertising remains a profitable enterprise for actors who can achieve sufficient scale and deliver malware effectively in a landscape where vulnerable machines are increasingly scarce,” Proofpoint researchers noted in a blog post. “To improve infection rates, criminals have turned to advanced filtering techniques and social engineering over the use of exploits.

“This campaign uses clever social engineering to trick users into installing fake updates that appear as soon as they visited a page containing a malicious ad,” the researchers noted. “Once users clicked on what they thought was an update file, they may not have even noticed a change in their systems as the malware opened an invisible web browser process, clicked on ads and generated potential revenue for cybercriminals.”

In this case, the cybercriminals’ actions may have cost advertisers some money, but the attack did no lasting harm. Things could have been much, much worse, the Proofpoint researchers warned.

“While the payload in this case is ad-fraud malware, it could just as easily have been ransomware, an information stealer or any other malware,” they wrote. “Regardless, threat actors are following the money and looking to more effective combinations of social engineering, targeting and pre-filtering to infect new victims at scale.”

 

About the Author
Raised in the Appalachian Mountains of Kentucky, Marty O'Brien was the first of the O'Brien clan to obtain a college degree. A former sports journalist, O'Brien got a peek at the inner workings of the adult entertainment industry while on an assignment to cover the Los Angeles Lakers. He joined the YNOT editorial team in late 2010 and now specializes in technology , business news and ogling starlets.
  • google-share
Previous Story

The Logical Fallacy of Asserting Life Imitates Porn

Next Story

Ride ’Em, Cowgirl! New Sex Machine Debuts

Related Posts

Jenna Starr Passes 50K Subs on PornHub

Posted On 19 Mar 2025
, By newswire
Chaturbate Sponsors TEA Trans Broadcaster of the Year Award

Chaturbate Sponsors TEA Trans Broadcaster of the Year Award

Posted On 07 Mar 2025
, By GeneZorkin
This Week on Adult Site Broker Talk: Part 2 of Interview with Solomon Friedman

This Week on Adult Site Broker Talk: Part 2 of Solomon Friedman Interview

Posted On 04 Feb 2025
, By GeneZorkin

Leave a Reply Cancel reply

You must be logged in to post a comment.

Sponsor

YNOT Shoot Me

YNOTShootMe.com has exclusive pics from adult industry business events. Check it out!

YNOT Directory

  • PussyCash
    Paysite Affiliate Programs
  • NiteFlirt.com
    Phone Sex Services
  • EC Props
    Studios, Sets & Locations
  • Premiere Listing

    Live Studio

    More Details

RECENT

POPULAR

COMMENTS

Pineapple Support

Teasy Agency Joins Pineapple Support As Supporter-Level Sponsor

Posted On 13 Jun 2025

ChickPass Amateurs Newbie Corner Features MILF Jess B

Posted On 13 Jun 2025

Stephanie Love Scores Kink Queens Mag Cover & Feature

Posted On 13 Jun 2025

Vanessa, Meet Vivid

Posted On 29 Sep 2014
Laila Mickelwaite and Exodus Cry

Laila Mickelwaite, Exodus Cry and their Crusade Against Porn

Posted On 03 May 2021

Sex Toy Collective Dildo Sculptor

Posted On 19 Mar 2019

Find a good sex toy is now a problem,...

Posted On 18 Mar 2024

Thanks to the variety of sex toys, I can...

Posted On 02 Feb 2024

I understand the concerns about...

Posted On 05 Jan 2024

Sponsor

Sitemap
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.OkPrivacy Policy