Researchers at Confiant published updated information regarding a threat group they have labelled Tag Barnakle. This group specializes in compromising Revive Adserver instances in order to distribute millions of malvertisements, which are ads with embedded malicious javascript. These ads perform actions such as exploiting vulnerabilities on an end user’s computer or attempting to get an end user to install a malicious application. Confiant’s estimate of compromised Revive servers exceeds 120. This is double the number of estimated infected servers from the prior year. Due to the nature of how advertisements propagate online, this means millions of devices are currently exposed to this attack. Tag Barnakle utilizes tactics that selectively target vulnerable devices and attempt to install second stage malware when possible. Propeller Ads, one of the largest Internet advertising networks, has commented that they are an intermediary and are not responsible for the advertisements propagated through their network.
