'Scareware' Targets High-Profile Sites Through Ad Networks

LOS ANGELES — A new security report reveals that hackers are exploiting vulnerabilities in ad-serving software to deliver a new breed of malware to unsuspecting users.

The attack looks like a regular pop-up warning, except in this case, users are faced with a window that warns them away from the current webpage and directs them to a different site to purchase antivirus software.

Security expert call this technique "scareware," and even the largest sites online are susceptible to it. Readers of the New York Times online portal encountered scareware this week. Admins at NYTimes.com discovered, however, that their site wasn't infected — its advertisements were.

This technique differs from traditional attacks, where the site itself is the target, researchers said.

"I think there is a problem with ad networks, in general," said Graham Cluley of the Sophos security firm. "The problem really is with websites handing over control of some of their content to third parties."

But with NYTimes.com, the plot thickened. Apparently the hackers initially posed as an ad network that represented mobile carrier Vonage. NYTimes.com accepted the ad and placed it on its site. Later, the hackers switched out the Vonage ad with the malicious one.

The websites for the San Francisco Chronicle and Fox News have both been victims of this style of scareware.

Online executive Troy Davis offered detailed technical analysis of the attack on NYTimes.com. Davis, CEO of the online development firm Seven Scale, noted that the scareware successfully imitates a local security program to trick users into following its commands.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Canada Exempts Online Adult Content From 'CanCon' Quotas

The Canadian Radio-television and Telecommunications Commission (CRTC) has updated its broadcasting regulatory policies, exempting streaming adult content from “made in Canada” requirements that apply to other online material.

Creator Law Firm 'OnlyFirm' Launches

Entertainment attorney Alex Lonstein has officially launched OnlyFirm.com for creators.

German Court Puts Pornhub, YouPorn 'Network Ban' on Hold

The Administrative Court of Düsseldorf has temporarily blocked the State Media Authority of North Rhine-Westphalia (LfM) from forcing telecom providers to cut off access to Aylo-owned adult sites Pornhub and YouPorn.

FSC: NC Law Invalidating Model Contracts Takes Effect December 1

The Free Speech Coalition (FSC) announced today that North Carolina's Prevent Exploitation of Women and Minors Act goes into effect on December 1.The announcement follows:

Teasy Agency Launches Marketing Firm

Teasy Agency has officially launched Teasy Marketing firm.

Ofcom Investigates More Sites in Wake of AV Traffic Shifts

U.K. media regulator Ofcom has launched investigations into 20 more adult sites as part of its age assurance enforcement program under the Online Safety Act.

MintStars Launches Debit Card for Creators

MintStars has launched its MintStars Creator Card, powered by Payy.

xHamster Settles Texas AV Lawsuit, Pays $120,000

Hammy Media, parent company of xHamster, has settled a lawsuit brought by the state of Texas over alleged noncompliance with the state’s age verification law, agreeing to pay a $120,000 penalty.

RevealMe Joins Pineapple Support as Partner-Level Sponsor

RevealMe has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

OnlyFans Institutes Criminal Background Checks for US Creators

OnlyFans will screen creators in the United States for criminal convictions, CEO Keily Blair has announced in a post on LinkedIn.

Show More