Ad-based Phishing Season Kicks Into High Gear

Ad-based Phishing Season Kicks Into High Gear

Explosion in phishing events in May and June 2021 highlights the necessity of click-through scanning

  • 4X growth in ad-based phishing since the beginning of 2021, with severe uptick in May and June
  • Decline in distinct outbreaks alongside increase in overall hits suggests larger, more enduring campaigns
  • Recommendations:?
  • Exhaustive click-through scanning to identify malicious landing pages
  • Range of global profiles in client-side scanning for your needs, e.g., targeted geography and surrounding areas

Phishing is often viewed as the province of email scams—for example, the classic message from a suspicious address entices you to sign into your account by clicking a funky link. But phishing lures are also widely deployed on the web via malvertising, and the technique’s popularity is surging as the summer heats up.?

The Media Trust detected a 4X growth in phishing events since the beginning of the year—and specifically a massive spike in May 2021 that continued to build through June. [Figure 1] While the majority of episodes were identified in the US, the Digital Security & Operations team has cataloged high numbers of ad-based phishing hits worldwide.

No alt text provided for this image

Figure 1: Trajectory for ad-based phishing activity in 2021

The number of distinct outbreaks—typically containing thousands of hits—actually declined slightly in June while overall phishing events are ramping up. This suggests longer, more expansive campaigns that aren’t being shut down quickly. Prominent malvertisers are also showing renewed interest in these kinds of attacks: phishing events powered by mobile-focused?Ghostcat-3pc?malware spiked in May, more than doubling the month prior.?

Catching the Landing Page Hook

Just like its email-based cousin, web phishing attempts to pilfer a variety of personal data points from users, from emails and phone numbers all the way to US Social Security Numbers and other highly sensitive information. Creatives often revolve around bogus sweepstakes, fake contests, and nonexistent rewards. [Figure 2]

No alt text provided for this image

Figure 2: Sample creative used in ad-based phishing incidents

Phishing attacks can be difficult to identify without click-through scanning to analyze malicious landing pages. While the creative may contain the bait to grab a consumer click, it’s the landing page that provides the hook—and gives away the venomous nature of the campaign. [Figure 3]

No alt text provided for this image

Figure 3: Phishing landing pages luring personal information out of unsuspecting consumers via bogus offers.

Phishing License Revoked

Alongside the rise of malicious clickbait, this surge in ad-based phishing points to malvertisers diversifying strategies beyond the redirect. AdTech companies and publishers merely focusing on that attack vector are leaving consumers exposed to other highly pernicious scams. Swindled personal data could later be sold on the dark web and used to propagate ransomware campaigns.

Click-through scanning is key to identifying and then shutting down these phishing campaigns, rather than letting them endure and stalk more potential victims.

要查看或添加评论,请登录

Gavin Dunaway的更多文章

  • Deepfakes Take Brand Hijacking to New Levels — So What Will Brands Do?

    Deepfakes Take Brand Hijacking to New Levels — So What Will Brands Do?

    This was a response to a media inquiry; I was a little slow to reply, but I liked what I said! (I'm kinda biased.) One…

  • The Final Word(s) on #IABALM? Inventory Quality

    The Final Word(s) on #IABALM? Inventory Quality

    Is it too late to post my #IABALM takes? I'm sorry I'm such a slowpoke, but every time I started to write, I'd read…

    1 条评论
  • When IVT Is Quite Valid

    When IVT Is Quite Valid

    Just the mention of the term invalid traffic (IVT) elicits hisses across the digital advertising ecosystem. As the…

    1 条评论
  • Bottoms Up... On Your Homepage?

    Bottoms Up... On Your Homepage?

    Originally posted on The Media Trust blog. It wouldn’t be the holiday season without some programmatic advertiser…

  • Ops Is Community

    Ops Is Community

    At an Ops conference, I normally expect to hear the word programmatic repeated ad infinitum, mish-mashed with so many…

  • Why Wasn't Google at PubForum?

    Why Wasn't Google at PubForum?

    I’m often asked why Google isn’t at the Publisher Forum, and this recent iteration in Austin was no exception. It's a…

  • 5 reasons to attend a conference in August

    5 reasons to attend a conference in August

    Every August, AdMonsters heads to a unique destination for our summer Publisher Forum. This year we'll be basking in…

  • Death of DoubleClick, Birth of a Monster?

    Death of DoubleClick, Birth of a Monster?

    Cleaning out my apartment to prepare for a new family member, I came across an old, dusty travel mug that I don’t think…

    1 条评论
  • AT&T Draws the Battle Lines

    AT&T Draws the Battle Lines

    Gossip about a potential AT&T acquisition of AppNexus filled up just about all the conversations on the wharf and…

  • I Went to Cannes Lions and All I Got Are These Hot Takes

    I Went to Cannes Lions and All I Got Are These Hot Takes

    In previous years, I’ve rolled my eyes as Cannes Lions came around following Ops. It’s long seemed like a soapbox for…

    1 条评论

社区洞察

其他会员也浏览了