News: 1669978792

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Domain aging gang CashRewindo picks vintage sites to push malvertising

(2022/12/02)


A sophisticated and very patient threat group behind a global malvertising scheme is using so-called aged domains to skirt past cybersecurity tools and catch victims in investment scams.

The attackers behind the CashRewindo campaign in many ways operate in the same way as other malvertising crooks. They inject malicious code into digital advertisements on legitimate ad networks, using the infected ads to steer website visitors to pages that may install malware or run scams.

Cybercriminals who run malvertising campaigns typically will spin up a domain and quickly put it into use.

[1]

However, CashRewindo has domains that have been registered for years and are left dormant, not activating them – updating certificates and assigning a virtual server – until right before launching the malvertising campaign, according to researchers at Confiant, whose tools protect companies' online reputation.

[2]

[3]

Confiant has been tracking CashRewindo – which was first detected in 2018 – for two years, Daniel Fonseca Yarochewsky, security software engineer at the vendor, wrote in a [4]report this week

Aged domains are not new or illegal. A quick Google search shows where people can buy abandoned domains, which still have plenty of backlinks pointing to them, before they expire. Smaller businesses buy them to more quickly launch a website and capture traffic already associated with the domain.

[5]

CashRewindo is patient, aging the domains before putting them to use. In all, Confiant linked 486 domains to the group, with some having been registered as long as ago as 2006 but not activated until this year. Others were activated weeks after being registered.

"We speculate that either they buy these from reputation-building markets, or wait around for them to age, likely the former," Yarochewsky wrote. "Being outsourced or not, this technique is able to bypass security systems that classify registration timing as reputable."

The technique works because such domains – being older with no history of malicious activity – are trusted and thus less likely to be considered suspicious by security software.

[6]

Melissa Bischoping, director of endpoint security research at Tanium, told The Register that research shows at least 20 percent of aged domains could be classified as suspicious. Such techniques require an investment of time and money by the attacker, who may be continually buying and aging domains in the background while running other operations in the meantime.

Given that, the technique is likely to be used by criminals with long term operations or those who are aging the domains to be sold to other threat groups, Bischoping said.

"An attacker who invests time in domain aging is more likely to be running an established and more sophisticated operation," she said. "As an example, the APT behind SolarWinds used years-old domain names in their operation."

Javvad Malik, security awareness advocate for KnowBe4, told The Register that "criminals will often set up such domains or fake profiles on social media sites like LinkedIn and then not do anything malicious for long periods of time before they undertake their actions. It highlights the lengths that criminals will go to avoid detection by security technologies."

Confiant recorded more than 1.5 million CashRewindo impressions over 12 months, with more than three-quarters hitting Windows devices. The group's attacks touched on more than 100 countries throughout Europe, North and South America, Africa, the Middle East, and Asia. The countries with the most impressions were from Eastern Europe.

CashRewindo's malvertising campaigns are tailored to specific regions, from using the local language, currency, and photos placed on the page, according to Yarochewsky.

The attackers do not rely only on domain aging to evade detection. The group also switches between scam ads and innocuous wording to avoid triggering software that detects "strong language," Yarochewsky wrote. At the start of a campaign, CashRewindo uses innocuous ads before switching to "call-to-action" ads later.

[7]Malwarebytes blocks Google, YouTube as malware

[8]Serendipitous discovery nets security researcher $70k bounty

[9]Facebook phishing campaign nets millions in IDs and cash

[10]How dodgy browser plugins, web scripts can silently rewrite that URL you were about to hit – and throw you into an internet wormhole

The attackers also put a small red circle in the middle of images to throw off computer vision detection tools. In addition, they target particular victims, determined through the language, time zone, and device platform used on the systems.

If someone not part of the targeted audience hits the "Click Here" button, they are directed to an innocuous site. Those targeted people who click the button trigger the malicious JavaScript code in the WSS, another step for evading detection.

From there the victim is sent to a scam page and then redirected to a platform hawking fake cryptocurrency investments.

Tanium's Bischoping said that protecting against such a campaign calls for a combination of tools, from next-generation firewalls and DNS filtering to email threat protection and threat intelligence feeds. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y4ovNBRQZehrtZ-XJ3f29gAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4ovNBRQZehrtZ-XJ3f29gAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4ovNBRQZehrtZ-XJ3f29gAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://blog.confiant.com/cashrewindo-how-to-age-domains-for-an-investment-scam-like-fine-scotch-a48d22788c84

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y4ovNBRQZehrtZ-XJ3f29gAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y4ovNBRQZehrtZ-XJ3f29gAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/09/21/malwarebytes_blocks_google_domains/

[8] https://www.theregister.com/2022/11/20/in_brief_security/

[9] https://www.theregister.com/2022/06/09/facebook_phishing_campaign/

[10] https://www.theregister.com/2019/08/15/hijacked_clicks_research/

[11] https://whitepapers.theregister.com/



And people want me to allow ads

Pascal Monett

Sorry, I won't.

At the best of times, they're useless. When they get creepy, they want to sell me something I just bought.

Then there are the ads that are downright threats to my computer and/or my privacy/money/data.

NoScript and Ublock Origin, or Brave is what I use, and you can pry them out of my cold, dead hands.

Re: And people want me to allow ads

Anonymous Coward

NoScript can help with domain squatters as you tend not to be bounced round the 'net

MalwareBytes does a free browser add-on that intercepts suspected phishing/malware sites

2006?

chivo243

That's the 'long con job' in action there. Gondorff and Hooker would be proud!

There is a simple way to stop malvertising forever

Wade Burchette

There is a simple way to stop malvertising forever: disallow javascript and tracking in ads. When the internet went from novelty to necessity, ads were static. It worked then, and it can still work now.

But I already know that advertisers will never implement this pro-consumer solution. Their greed trumps my security.

Re: There is a simple way to stop malvertising forever

elsergiovolador

Sadly many organisations use malicious tracking still, so you unfortunately have to make exceptions e.g. for some banking.

For instance, I couldn't use international payment facility of one of high street banks until I disabled ad block completely.

Re: There is a simple way to stop malvertising forever

Ball boy

'tis the reason I have two browsers. One for regular use and one I only use for accessing the bank and an online accounting package. The latter is a vanilla setup and only used for those two cases. Neither bank or accounting s/w plaster adverts in their screens so I'm okay with disabling Pi-Hole for the duration if I have to.

Once I'm done it's simply Pi-hole back on, Chrome cleaned and closed and we're back to Firefox for some sanity.

Re: There is a simple way to stop malvertising forever

Anonymous Coward

I would change banks, and let them know why. I bank with one of the top three banks in my country, and they have no problems with an ad blocker running in my browser.

Any site that has problems with UBlock loses my business.

Sex, Drugs & Linux Rules
-- MaDsen Wikholm, mwikholm@at8.abo.fi