Domains tainted by RoughTed malvertising reap half a billion hits

Some of which comes from Alexa top 500 websites

Mark Wahlberg and his come-to-life teddy bear in bed in the movie Ted. Copyright: Universal Pictures
Mark Wahlberg with a 'rough ted' of a different kind. Copyright: Universal Pictures

A strain of adblocker-aware malvertising is responsible for a range of scams, exploits and general skulduggery.

RoughTed can deliver a variety of payloads including exploit kits and malware. Hackers are leveraging fingerprinting and adblocker-bypassing techniques in a bid to ensure that marks are served content from RoughTed-tainted domains. The various nuisances pushed by the campaign also include adware for Macs, rogue?Chrome extensions, tech support scams and surveys.

Traffic comes from thousands of publishers, some ranked in Alexa's top 500 websites. Contaminated domains accumulated over half a billion visits in the past three months alone, according to security firm Malwarebytes.

The threat actors behind RoughTed have been leveraging the Amazon cloud infrastructure, in particular its Content Delivery Network (CDN), while also blending in the noise with multiple ad redirections from several ad exchanges, making it more difficult to identify the source of their malvertising activity.

RoughTed is a large malvertising operation that peaked in March 2017 but began over a year ago and remains at large. It's unusual in that it targets a wide array of users according to their operating system, browser and geolocation before delivering the appropriate payload.

Malwarebytes came across RoughTed while studying the Magnitude exploit kit, as explained in a blog post here. ?


Biting the hand that feeds IT ? 1998–2017

                                    1. 3239961348 2018-02-21
                                    2. 8189611347 2018-02-21
                                    3. 1166571346 2018-02-21
                                    4. 905911345 2018-02-21
                                    5. 238301344 2018-02-21
                                    6. 9856121343 2018-02-21
                                    7. 7107891342 2018-02-21
                                    8. 616201341 2018-02-21
                                    9. 97671340 2018-02-21
                                    10. 7844621339 2018-02-21
                                    11. 9607131338 2018-02-21
                                    12. 3095441337 2018-02-21
                                    13. 9602111336 2018-02-21
                                    14. 5723751335 2018-02-21
                                    15. 1275371334 2018-02-21
                                    16. 8517591333 2018-02-21
                                    17. 230661332 2018-02-21
                                    18. 3311101331 2018-02-21
                                    19. 6181321330 2018-02-20
                                    20. 6139401329 2018-02-20