A billion risky impressions: lessons from the Adform hack

Visit a familiar website, and along with the usual ad banner you could pick up a script that steals cryptocurrency. How can you protect yourself from attacks delivered through online ads?

What we know about the cryptocurrency theft through Adform ads

Adform, a major advertising platform, remained compromised for roughly 24 hours from late on July 26 through the evening of July 27 after being breached by unknown attackers. Few people outside the industry recognize the name, but Adform serves around 1.5 billion ad impressions every day across tens of thousands of websites. That means anyone visiting any site that runs Adform ads could have been targeted.

The attackers weren’t trying to install malware. Instead, they ran a script in the victim’s browser that checked the clipboard every three seconds, and if it found a cryptocurrency wallet address had been copied, swapped it for the attackers’ own wallet address. So if someone had a site with the malicious ad open in one browser tab, and was making a crypto transaction in another tab or in a dedicated app, the funds could have ended up in the attackers’ pockets instead. Adform’s owners caught the attack and fixed the problem, but there’s no guarantee a similar incident won’t happen again — which is why every user should defend themselves against malvertising. Check out our tips at the end of this post.

What we know about the attack on Adform

There isn’t a lot of information out there, since the company’s official statement covers only what happened and when, without getting into the root cause of the incident. Independent research has dug up technical details about how ordinary users were targeted, but none of that explains how Adform itself was breached in the first place.

What’s clear is that the attackers slipped their own code into the JavaScript that loaded on every site running Adform ads. Whenever an ad was about to display, the script would load from Adform’s server, pick the right ad, and show it — but the attackers had tacked on a set of malicious functions: monitoring the clipboard, sending data about the site where the encounter happened, and the victim’s IP address back to their own server, and swapping out Bitcoin, Ethereum, and Tron wallet addresses.

All it took to make it work was having any site with Adform-served ads open in one browser tab. It didn’t matter what kind of site it was, what the ad looked like, or which advertiser it belonged to. The one thing that mattered was whether the site ran over HTTP or HTTPS. According to Adform, the attack couldn’t succeed on a site loaded over HTTPS since the connection to the attackers’ server was blocked in this case.

The company hasn’t shared any information on how many users were affected, or how many sites still serve their content and ads over HTTP.

Malicious ads are an everyday occurrence

Unfortunately, dangerous online ads have become a systemic problem. And we’re not just talking about sketchy supplement ads or gambling promos — we mean ads that spread malware or lead to sites designed to steal payment details and other valuable data. Attackers have built out industrial-scale infrastructure to pull this off, and they use several different approaches.

  • Hacking and compromising ad servers. Adform isn’t an isolated case: attackers have previously breached Revive ad servers, for one, and spread malware through ads on PornHub.
  • Hijacking the ad accounts of legitimate, reputable brands. All it takes is stealing a password from someone in marketing. From there, the cybercriminals run ads posing as the company they hacked, pushing fake app updates, bogus promotions, and similar scams. In the worst cases — like the account breaches at adtech.de and adxpansion.com — attackers managed to run ads that redirected victims straight into automatic malware installs (drive-by downloads).
  • Buying ads directly. That’s right — attackers simply set up their own advertiser accounts and run ads for their phishing sites and malware, just like any other business online.

Since ads show up practically everywhere — on websites, in apps, and on social media — these threats can turn up in pretty much any context. And you’ll find variations of this threat on both computers and mobile devices.

How to protect yourself from malicious ads

The only way to seriously cut your risk is to block as much advertising as possible, and combine that with protection against cyberattacks across all your devices:

  • Use a secure DNS service with content filtering built in. These are effective at blocking most known ad networks. The idea is straightforward: whenever your device tries to connect to a server, the DNS service blocks requests to known ad domains. This switches off ads everywhere at once: on smart TVs, in every browser, and in mobile apps. Some internet providers offer this as a service, but a cleaner, more universal fix is to set up secure DNS on your home router yourself by following our guide.
  • Turn on ad and tracker blockers in your all-in-one cybersecurity solution. We recommend Kaspersky Premium, which calls this feature Anti-Banner. This kind of protection matters most while traveling, since secure DNS can sometimes cause connection issues in hotels, restaurants, and airports.
  • Use browser protection. Basic security software can stop malware from downloading and running, but a small stealer script like the one in the Adform attack can still slip in unnoticed. To guard against this, use protection that can actually analyze what’s happening inside your browser. In Kaspersky Premium, this feature is served by the Kaspersky Protection browser extension. It guards against data harvesting online, blocks banner ads, secures your payments, protects your keystrokes, and blocks phishing.

Eager to know what other risks are lurking in online ads and how to protect yourself? Check out further posts:

Tips