CBCnews
Story Tools: EMAIL | PRINT | Text Size: S M L XL | REPORT TYPO | SEND YOUR FEEDBACK | Bookmark and Share

Hackers using banner ads to hide malware

Last Updated: Friday, November 16, 2007 | 5:15 PM ET

Hackers are using banner ads on websites to hide malicious software, or "malware," that hijacks computers without the user even clicking on them.

The malware has been spotted on several legitimate websites, including ones run by The Economist magazine and Major League Baseball, as well as Canada.com, Wired magazine reported on Thursday.

Hackers are hiding the harmful code in the DART platform used by DoubleClick, which is a major online ad services company. Many web publishers, including the CBC, use DoubleClick to manage their ad inventory.

The malicious code causes the web browser window to close and re-open, then redirects the user to an antivirus site. A dialog box then appears and tells the user their computer is infected and their hard drive is being scanned.

Because the malware is hidden in an ad, there is little a user can do to detect it before it is too late.

Matt Doris, manager of advertising operations for AOL Canada, which services ads for CBC.ca, said that while the site is potentially vulnerable, there have not been any reports of compromised ads related to this malware.

"Any site serving ads is vulnerable," he said.

Doris said all the ads on the CBC website are being reviewed for the malware. He added that at this point, there is not much a user can do to avoid it.

DoubleClick has acknowledged the problem and said it has implemented additional security measures, which have captured and disabled a hundred ads.

"Unfortunately, there are bad actors who misrepresent themselves and purchase advertising as an avenue to distribute malware," Sean Harvey, senior product manager at DoubleClick DART, told Wired. "This has the potential to affect all businesses and consumers in the online environment."

DoubleClick urged web publishers to pay close attention to the agencies and advertisers they work with, particularly any new ones.

Security firms have suggested the malware is the work of AdTraff, an online marketing company that poses as a legitimate advertiser.

AdTraff could not be reached for comment by Wired.

Internet search leader Google Inc. is in the midst of a $1.3-billion U.S. acquisition of DoubleClick, but the deal has hit a snag with European regulators expressing antitrust concerns.

  • This story is now closed to commenting.
Story Tools: EMAIL | PRINT | Text Size: S M L XL | REPORT TYPO | SEND YOUR FEEDBACK | Bookmark and Share
 

Technology & Science Headlines

Bell quietly drops system access fee
The cellphone system access fee is all but extinct. Bell Canada has quietly axed the charge, joining rivals Rogers and Telus.
Beam sent around Large Hadron Collider
The operators of the Large Hadron Collider have successfully sent a beam of particles around the ring of the world's largest particle collider in Switzerland.
Astronauts complete 6-hour spacewalk
Astronauts from space shuttle Atlantis completed the second of three scheduled spacewalks Saturday, spending just over six hours installing equipment on the International Space Station.
Asian carp close to Great Lakes
U.S. officials say the despised Asian carp may have breached an electronic barrier designed to prevent it from invading the Great Lakes.
Billy Bragg, NDP push for new law on music downloads
British folk singer Billy Bragg teamed up with Canadian songwriters and the NDP to advocate for copyright reform and a new approach to music downloads while on tour in Ottawa Friday.

Top CBCNews.ca Headlines

Headlines

Afghan prisoner transfers halted 'more than one time' Video
Canadian officials have halted the transfer of prisoners to Afghanistan's intelligence service "more than one time," because of the possibility of torture, Canada's chief of defence staff said Sunday.
Indonesian ferry sinks in storm
Rescuers saved more than 240 people aboard an Indonesian passenger ferry that sank Sunday in rough waters off Sumatra island, but at least 25 people have died, officials said.
Iranian forces practise defending nuke sites
Iran on Sunday began large-scale air defence war games aimed at protecting the country's nuclear facilities against any possible attack, state television reported.
Baby survives as crash kills 4
RCMP say four Calgary women are dead after a crash south of Calgary that left only a single survivor —a baby that had been strapped into a car seat.
Plaskett double winner at Canadian Folk Music Awards
Joel Plaskett's triple album Three earned the Halifax singer-songwriter a double win at the Canadian Folk Music Awards on Saturday.