What we know about the cryptocurrency theft through Adform ads | Kaspersky official blog
Brief
Adform, a major advertising platform, remained compromised for roughly 24 hours from late on July 26 through the evening of July 27 after being breached by unknown attackers. Few people outside the industry recognize the name, but Adform serves around 1. 5 billion ad impressions every day across tens of thousands of websites. That means anyone visiting any site that runs Adform ads could have been targeted.
The attackers weren’t trying to install malware. Instead, they ran a script in the victim’s browser that checked the clipboard every three seconds, and if it found a cryptocurrency wallet address had been copied, swapped it for the attackers’ own wallet address.
So if someone had a site with the malicious ad open in one browser tab, and was making a crypto transaction in another tab or in a dedicated app, the funds could have ended up in the attackers’ pockets instead.
