RedTube Fixes Malware Security Breach

BURBANK, Calif. — RedTube announced this week via Twitter that it fixed a bug on its adult tube site that redirected users to malicious URLs and exposed them to Trojan horse viruses.

The highly trafficked MindGeek-owned property apparently was hacked via a malicious HTML iframe placed directly in the source code of the site and made invisible to the user.

The source code on RedTube's main page was modified in order to redirect the user to malicious URLs hosting the Angler Exploit Kit, according to security blog MalwareBytes, which first discovered and reported the breach. 

Once redirected, the software kicks in and tries to exploit Adobe's recently patched CVE-2015-0313 bug to run malicious code, MalwareBytes said.

Officials of MindGeek’s RedTube division, in a response to MalwareBytes, said that the attack occurred this past Sunday for a “brief period of time.”

“Our security systems immediately detected the breach, and we took direct action to rectify the situation in order to protect RedTube users,” MindGeek told MalwareBytes.

“RedTube pursues stringent privacy requirements and maintains the highest industry standards of privacy protection to secure not only their assets and properties, but to provide comprehensive protection of their customers’ data when visiting a RedTube-owned site.  

"RedTube is committed to providing their customers with an optimal online experience and the peace of mind when they are accessing a RedTube site.”

According to reports, RedTube is not the only adult tube site to have fallen victim to malware in recent months.

Another site, xHamster, was said to be serving up a Flash file that exploited a flaw via a malicious advertisement.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

New EU User Stats Could Reclassify Major Adult Sites Under DSA

Three high-traffic adult sites previously classified as “very large online platforms” under the European Union’s Digital Services Act are reporting user numbers below the threshold for that label, opening the way for possible downgrading of their obligations under that law.

Spicerack Launches 'SpicyFanz' Creator Monetization Platform

Adult product marketplace Spicerack Market has launched its SpicyFanz creator monetization platform.

Singapore Livestreamer Jailed for Performing 'Obscene Acts' in Public

A judge in Singapore on Thursday sentenced a Vietnamese woman to three weeks in jail for livestreaming “obscene acts” from a public area.

FSC Withdraws Support for North Dakota AV Bill

The Free Speech Coalition (FSC) has withdrawn its support for an age verification bill in North Dakota, following changes made by the state legislature.

APClips Launches New Blog

APClips has launched a blog, AmateurPorn.com.

Centrobill Launches 'Max' Payment Suite

Payment processing service Centrobill has launched its new Max Suite toolkit.

AEBN Publishes Popular Searches by Country for December, January

AEBN has released the list of popular searches from its straight and gay theaters by country in December and January.

South Dakota Legislators Debate AV Legal Strategies

The South Dakota state Senate Judiciary Committee on Tuesday heard testimony and debate over two competing age verification bills, in a hearing that focused largely on which piece of legislation could best withstand potential legal challenges.

Mobile OnlyFans Management Platform 'TopCreator' Launches

Mobile OnlyFans management and chat platform TopCreator has launched.

JustFor.fans Marks Its 7th Anniversary With Palm Springs Conference

JustFor.fans is celebrating its seventh anniversary with a four-day conference and party in Palm Springs May 18-21.

Show More