The Ads Themselves Were the Malware

The Ads Themselves Were the Malware

Tech News ad-blockers malvertising security yahoo

So everyone's timeline this week is wall to wall CES. Curved TVs, a smartwatch from Pebble that actually looks like a watch for once, some guy livetweeting a bendable phone demo like it's the second coming. I get it, Vegas is where the internet goes to lose its mind every January. But I want to talk about something that happened over New Year's that got maybe a tenth of the attention it deserved: Yahoo's own ad network was quietly serving malware to people just for loading yahoo.com.

This isn't a rumor, it's not some sketchy forum post. A Dutch security outfit called Fox-IT flagged it around January 3rd — malicious ads running through Yahoo's ad exchange were redirecting European visitors through a chain of sites and dumping exploit kits onto their machines, the kind of thing that goes after old Java installs and just quietly owns the box. No click required. You load the page, the ad iframe does its thing in the background, and if your Java's out of date (and whose isn't) you've got a problem you don't know about yet.

The numbers going around were genuinely ugly. Fox-IT estimated tens of thousands of infections an hour at the peak, over a run of a few days starting right around New Year's Eve. Yahoo's statement basically said "yeah this affected European users, we're on it, US users weren't targeted," which is the kind of sentence that's technically reassuring and also not reassuring at all if you think about it for more than four seconds. The ad network is the ad network. It doesn't check passports.

Here's my actual gripe, and it's not really about Yahoo specifically. It's that malvertising keeps happening and keeps getting treated like weather. Bad luck, nothing anybody could've done, move along. But the entire business model of ad exchanges is that nobody upstream actually knows what's rendering in that iframe until it already has. You're trusting a chain of resellers you've never heard of to not sell space to whoever's running the Magnitude kit this month. I've been saying for years on here that running an ad blocker isn't about being cheap or hating on sites trying to make a buck, it's a basic hygiene thing at this point, and stuff like this is exactly why. My mother-in-law's laptop got hit by something almost identical to this back in 2012 off a totally reputable news site, and I spent a Sunday afternoon I'll never get back running MBAM and Combofix trying to dig it out. That's the actual cost of "just don't worry about it."

I'll admit the CES stuff is more fun to write about. Nobody wants to read "update your Java" for the four hundredth time, myself included, and I say that as someone who still has Java installed on this machine for exactly one tax-prep tool I use once a year and hate. But a story where the attack surface is literally the front page of one of the biggest sites on the internet feels like it should get more than a couple days of coverage before everyone moves back to arguing about whether curved TVs are a gimmick. (They are, by the way. I don't care what Samsung's booth people tell you, sitting off-center in your living room the curve does nothing for you. Fight me.)

What I keep coming back to is how quiet the fix always is. No press conference, no keynote, just a network operator pulling some accounts and a security firm's blog post that most people never see unless someone like me links it. The malware doesn't need you to notice it. It just needs four days and an unpatched Java runtime, and apparently that's not hard to find at all. If you're running anything older than a browser update from the last few months, this is your one nudge from me to go check, especially if Java's still living on your machine for some ancient reason like mine is. It's not glamorous. Nothing about this is glamorous. That's kind of the point.