DeceptionAds: How a Single Ad Network Trolled Over a Million Users Daily
DeceptionAds is a malvertising campaign exploiting ad networks to trick users into executing harmful scripts. By redirecting traffic to fake CAPTCHA pages, it cunningly steals sensitive information. Despite efforts to shut it down, the campaign has resurfaced, highlighting the need for better content moderation and security measures in ad networks.

Hot Take:
Ah, the wild west of the internet, where ads promise you the world and then steal your wallet. Who knew CAPTCHA could be the gateway to losing your life’s savings? Someone tell the cyber robbers that it’s “clickbait,” not “click-steal-your-fate.”
Key Points:
- DeceptionAds campaigns leverage a single ad network for malvertising, affecting over a million users daily.
- Cyber attackers use fake CAPTCHA pages to trick users into executing harmful PowerShell commands.
- Multiple threat groups are adopting this method for deploying various malicious software, including information stealers.
- Monetag and BeMob have been implicated in the campaign, with subsequent actions to remove malicious accounts.
- The campaign highlights the need for better content moderation and validation on ad networks.
Already a member? Log in here