{"id":36467,"date":"2026-08-11T10:18:13","date_gmt":"2026-08-11T14:18:13","guid":{"rendered":"https:\/\/www.kaspersky.com.au\/blog\/?p=36467"},"modified":"2026-08-12T01:29:37","modified_gmt":"2026-08-11T14:29:37","slug":"adform-compromise-malicious-ads-cryptocurrency-theft","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.au\/blog\/adform-compromise-malicious-ads-cryptocurrency-theft\/36467\/","title":{"rendered":"A billion risky impressions: lessons from the Adform hack"},"content":{"rendered":"<p>Adform, a major advertising platform, remained compromised for roughly 24 hours from late on July 26 through the evening of July 27 after being breached by unknown attackers. Few people outside the industry recognize the name, but Adform <a href=\"https:\/\/web.archive.org\/web\/20260801102947\/https:\/site.adform.com\/media\/zwkpcmh5\/adform-annual-report-2025.pdf\" target=\"_blank\" rel=\"noopener nofollow\">serves around 1.5 billion ad impressions every day<\/a> across tens of thousands of websites. That means anyone visiting any site that runs Adform ads could have been targeted.<\/p>\n<p>The attackers weren\u2019t trying to install malware. Instead, they ran a script in the victim\u2019s browser that checked the clipboard every three seconds, and if it found a cryptocurrency wallet address had been copied, swapped it for the attackers\u2019 own wallet address. So if someone had a site with the malicious ad open in one browser tab, and was making a crypto transaction in another tab or in a dedicated app, the funds could have ended up in the attackers\u2019 pockets instead. Adform\u2019s owners caught the attack and fixed the problem, but there\u2019s no guarantee a similar incident won\u2019t happen again \u2014 which is why every user should <a href=\"https:\/\/www.kaspersky.com.au\/premium?icid=au_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">defend themselves against malvertising<\/a>. Check out our tips at the end of this post.<\/p>\n<h2>What we know about the attack on Adform<\/h2>\n<p>There isn\u2019t a lot of information out there, since <a href=\"https:\/\/web.archive.org\/web\/20260807222617\/https:\/site.adform.com\/resources\/newsroom\/security-incident-company-update\/\" target=\"_blank\" rel=\"noopener nofollow\">the company\u2019s official statement<\/a> covers only what happened and when, without getting into the root cause of the incident. <a href=\"https:\/\/doublepulsar.com\/adform-compromised-to-serve-crypto-stealer-via-supply-chain-attack-2f1ec024f33e?gi=47d6680b0ff6\" target=\"_blank\" rel=\"noopener nofollow\">Independent research<\/a> has dug up technical details about how ordinary users were targeted, but none of that explains how Adform itself was breached in the first place.<\/p>\n<p>What\u2019s clear is that the attackers slipped their own code into the JavaScript that loaded on every site running Adform ads. Whenever an ad was about to display, the script would load from Adform\u2019s server, pick the right ad, and show it\u00a0\u2014 but the attackers had tacked on a set of malicious functions: monitoring the clipboard, sending data about the site where the encounter happened, and the victim\u2019s IP address back to their own server, and swapping out Bitcoin, Ethereum, and Tron wallet addresses.<\/p>\n<p>All it took to make it work was having any site with Adform-served ads open in one browser tab. It didn\u2019t matter what kind of site it was, what the ad looked like, or which advertiser it belonged to. The one thing that mattered was whether the site ran over HTTP or HTTPS. According to Adform, the attack couldn\u2019t succeed on a site loaded over HTTPS since the connection to the attackers\u2019 server was blocked in this case.<\/p>\n<p>The company hasn\u2019t shared any information on how many users were affected, or how many sites still serve their content and ads over HTTP.<\/p>\n<h2>Malicious ads are an everyday occurrence<\/h2>\n<p>Unfortunately, dangerous online ads have become a systemic problem. And we\u2019re not just talking about sketchy supplement ads or gambling promos\u00a0\u2014 we mean ads that spread malware or lead to sites designed to steal payment details and other valuable data. Attackers have built out industrial-scale infrastructure to pull this off, and they use several different approaches.<\/p>\n<ul>\n<li><strong>Hacking and compromising ad servers.<\/strong> Adform isn\u2019t an isolated case: attackers have previously <a href=\"https:\/\/arstechnica.com\/information-technology\/2021\/04\/malvertisers-use-120-hacked-ad-servers-to-target-millions-of-web-surfers\/\" target=\"_blank\" rel=\"noopener nofollow\">breached Revive ad servers<\/a>, for one, and spread malware <a href=\"https:\/\/www.kaspersky.com\/blog\/pornhub-malvertising\/19698\/\" target=\"_blank\" rel=\"noopener nofollow\">through ads on PornHub<\/a>.<\/li>\n<li><strong><a href=\"https:\/\/www.kaspersky.com\/blog\/cyberattacks-on-your-marketing\/50571\/\" target=\"_blank\" rel=\"noopener nofollow\">Hijacking the ad accounts<\/a> of legitimate, reputable brands<\/strong>. All it takes is stealing a password from someone in marketing. From there, the cybercriminals run ads posing as the company they hacked, pushing fake app updates, bogus promotions, and similar scams. In the worst cases\u00a0\u2014 like the <a href=\"https:\/\/www.pcworld.com\/article\/431667\/malicious-advertisements-on-major-sites-compromised-many-computers.html\" target=\"_blank\" rel=\"noopener nofollow\">account breaches at adtech.de and adxpansion.com<\/a>\u00a0\u2014 attackers managed to run ads that redirected victims straight into automatic malware installs (<a href=\"https:\/\/www.kaspersky.com\/blog\/bad-rabbit-ransomware\/19887\/\" target=\"_blank\" rel=\"noopener nofollow\">drive-by downloads<\/a>).<\/li>\n<li><strong>Buying ads directly.<\/strong> That\u2019s right\u00a0\u2014 attackers simply set up their own advertiser accounts and run ads for their phishing sites and malware, just like any other business online.<\/li>\n<\/ul>\n<p>Since ads show up practically everywhere\u00a0\u2014 on websites, in apps, and on social media\u00a0\u2014 these threats can turn up in pretty much any context. And you\u2019ll find variations of this threat on both computers and mobile devices.<\/p>\n<h2>How to protect yourself from malicious ads<\/h2>\n<p>The only way to seriously cut your risk is to block as much advertising as possible, and combine that with <a href=\"https:\/\/www.kaspersky.com.au\/home-security?icid=au_kdailyplacehold_acq_ona_smm__onl_b2c_blo_lnk_sm-team______\" target=\"_blank\" rel=\"noopener\">protection against cyberattacks across all your devices<\/a>:<\/p>\n<ul>\n<li>Use a secure DNS service with content filtering built in. These are effective at blocking most known ad networks. The idea is straightforward: whenever your device tries to connect to a server, the DNS service blocks requests to known ad domains. This switches off ads everywhere at once: on smart TVs, in every browser, and in mobile apps. Some internet providers offer this as a service, but a cleaner, more universal fix is to <a href=\"https:\/\/www.kaspersky.com\/blog\/secure-dns-private-dns-benefits\/47209\/\" target=\"_blank\" rel=\"noopener nofollow\">set up secure DNS on your home router yourself by following our guide<\/a>.<\/li>\n<li>Turn on ad and tracker blockers in your <a href=\"https:\/\/www.kaspersky.com.au\/home-security?icid=au_kdailyplacehold_acq_ona_smm__onl_b2c_blo_lnk_sm-team______\" target=\"_blank\" rel=\"noopener\">all-in-one cybersecurity solution<\/a>. We recommend <a href=\"https:\/\/www.kaspersky.com.au\/premium?icid=au_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">Kaspersky Premium<\/a>, which calls this feature <a href=\"https:\/\/support.kaspersky.com\/kaspersky-for-windows\/21.26\/settings\/15982#block1\" target=\"_blank\" rel=\"noopener\">Anti-Banner<\/a>. This kind of protection matters most while traveling, since secure DNS can sometimes cause connection issues in hotels, restaurants, and airports.<\/li>\n<li>Use browser protection. Basic security software can stop malware from downloading and running, but a small stealer script like the one in the Adform attack can still slip in unnoticed. To guard against this, use protection that can actually analyze what\u2019s happening inside your browser. In <a href=\"https:\/\/www.kaspersky.com.au\/premium?icid=au_bb2022-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">Kaspersky Premium<\/a>, this feature is served by the <a href=\"https:\/\/support.kaspersky.com\/kaspersky-for-windows\/21.26\/settings\/15472\" target=\"_blank\" rel=\"noopener\">Kaspersky Protection browser extension<\/a>. It guards against data harvesting online, blocks banner ads, secures your payments, protects your keystrokes, and blocks phishing.<\/li>\n<\/ul>\n<blockquote><p>Eager to know what other risks are lurking in online ads and how to protect yourself? Check out further posts:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/disable-rtb-ad-tracking-law-enforcement-spy-agencies\/51019\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Advertisers sharing data about you with\u2026 intelligence agencies<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-remove-yourself-from-data-brokers-people-search-sites\/54209\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Why data brokers build dossiers on you, and how to stop them doing so<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/disable-mobile-app-ad-tracking\/53096\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>How smartphones build a dossier on you<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/web-beacons-explained-and-how-to-stop-them\/47281\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Who is tracking you on the web and how<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/deleting-digital-footprints\/54591\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>How to disappear from the internet<\/strong><\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\">\n","protected":false},"excerpt":{"rendered":"<p>Visit a familiar website, and along with the usual ad banner you could pick up a script that steals cryptocurrency. How can you protect yourself from attacks delivered through online ads?<\/p>\n","protected":false},"author":2722,"featured_media":36468,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2646],"tags":[810,105,374,2620,1905,2672,1134,1250,1946,43,97,422,131,113],"class_list":["post-36467","post","type-post","status-publish","format-standard","has-post-thumbnail","category-threats","tag-ads","tag-android","tag-bitcoin","tag-cryptocurrencies","tag-dns","tag-ethereum","tag-internet","tag-ios","tag-macos","tag-privacy","tag-security-2","tag-threats","tag-tips","tag-windows"],"hreflang":[{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/adform-compromise-malicious-ads-cryptocurrency-theft\/36467\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/adform-compromise-malicious-ads-cryptocurrency-theft\/30973\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/adform-compromise-malicious-ads-cryptocurrency-theft\/26001\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/adform-compromise-malicious-ads-cryptocurrency-theft\/30803\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/adform-compromise-malicious-ads-cryptocurrency-theft\/42487\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/adform-compromise-malicious-ads-cryptocurrency-theft\/56257\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/adform-compromise-malicious-ads-cryptocurrency-theft\/30938\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/adform-compromise-malicious-ads-cryptocurrency-theft\/36382\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.au\/blog\/tag\/privacy\/","name":"privacy"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36467","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/users\/2722"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/comments?post=36467"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36467\/revisions"}],"predecessor-version":[{"id":36469,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36467\/revisions\/36469"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media\/36468"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media?parent=36467"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/categories?post=36467"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/tags?post=36467"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}