Yahoo's Homepage Was Serving Malware Over New Year's

Yahoo's Homepage Was Serving Malware Over New Year's

Tech News ads malvertising security yahoo

So the first "well that's not great" tech story of the year turned out to be Yahoo's ad network, of all things. A Dutch security outfit called Fox-IT put out a writeup a couple days ago saying that ads served through Yahoo's own advertising platform had been quietly redirecting people to an exploit kit since right around New Year's Eve. Not a phishing email, not some sketchy torrent site. You just had to load yahoo.com with an out of date Java plugin and the ad itself did the rest. No click required.

Fox-IT's numbers, if you believe them (and I mostly do, they're the same folks who've called out this kind of thing before), had it hitting somewhere in the neighborhood of two percent of Yahoo's served ads during the worst of it, concentrated hard in Romania, the UK, France, and a handful of other European countries. Apparently US traffic was barely touched, which is a weird kind of relief. Yahoo's official line, once they got around to confirming it on the 3rd, was that the malicious ads were live for about four days before they pulled them.

Four days is a long time for something like this to run on a site that's still, believe it or not, one of the most visited pages on the internet. I know Yahoo gets treated as a punchline these days, all Marissa Mayer headlines and nostalgia for GeoCities, but people forget how much default-homepage traffic it still pulls. My own mother still has it set as her browser's start page. Has for probably a decade. I've tried to change it twice and she just changes it back because "it's got the weather right there."

Which is actually why this whole thing got under my skin more than most malware stories do. I spent about four hours over the holidays going through my parents' computer, because that's apparently what December 26th through January 2nd are for now if you're the semi-technical kid in the family. Uninstalled three toolbars. Turned off some browser extension that was hijacking search results to Bing (not even correctly, it just sort of broke Google half the time). Installed Ghostery. Felt very satisfied with myself, honestly, like I'd done my civic duty for the year.

And then five days later I'm reading that the exact page she has pinned as her homepage was potentially shoving exploit code at anyone with a stale Java runtime, which, I'd bet real money, describes her setup pretty closely. I didn't check her Java version while I was over there. Rookie mistake. I'm going back this weekend to look, and also probably to explain to her, again, why she doesn't need Java enabled in her browser at all unless she's doing something extremely specific and she is not doing something extremely specific.

The exploit kit involved, by most accounts I've seen floating around, was something in the Magnitude family, which goes after old Java and Flash installs mostly, not zero days in anything current. That's the part that bugs me most. This wasn't some brilliant new attack. It's the same tired playbook, just running through an ad slot instead of a spam email, on a domain that has enough trust built up that nobody thinks twice about loading it.

I don't think this makes Yahoo uniquely bad, for what it's worth. Ad networks in general are a mess of third and fourth party redirects that nobody, including the sites running them, has full visibility into. That's sort of the whole complaint people like me have been making about ad-supported everything for years, and it's nice, in a grim way, to have a dated, specific example to point at instead of just grumbling about it in the abstract.

Anyway. If your holiday project list still has "set up an ad blocker on mom and dad's computer" sitting unchecked, this is your reminder. Mine's getting bumped back to the top.