Pornhub malvertising attack affects millions of users
Malvertising incidents are also expanding to whitelisted websites, expert warns


A large-scale malvertising attack saw millions of users of adult video website Pornhub tricked into installing malware on the computers, according to security researchers.
The campaign was active for more than a year, exposing millions of potential victims in the US, Canada, the UK, and Australia to fake software updates that actually installed malware, said IT security researchers at Proofpoint in a blog post.
The attacks were carried out by a hacking group known as KovCoreG. It is best known for distributing Kovter ad fraud malware and sitting atop the affiliate model that distributes Kovter more widely.
Victims were shown fake notifications of updates to their Chrome or Firefox web browser or Flash. When a file was downloaded, it installed Kovtar. This then was used by criminals to fake click on adverts. However, these clicks made money for criminals.
"The combination of large malvertising campaigns on very high-ranking websites with sophisticated social engineering schemes that convince users to infect themselves means that potential exposure to malware is quite high, reaching millions of web surfers," said the researchers.
"Once again, we see actors exploiting the human factor even as they adapt tools and approaches to a landscape in which traditional exploit kit attacks are less effective."
While the payload here is ad fraud malware, it could just as easily have been ransomware, an information stealer, or any other malware.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Regardless, threat actors are following the money and looking to more effective combinations of social engineering, targeting, and pre-filtering to infect new victims at scale," they added.
Pornhub, which has its own bug bounty programme, acted swiftly to fix the issue when Proofpoint made it aware of the issue.
Chris Olson, CEO of The Media Trust, told IT Pro that the widespread notion that malvertising is on the decline just isn't true, and that it's even extending to websites you'd be happy to visit at work.
"In fact, malvertising incidents have more than doubled in the past three years and are increasingly found on premium websites that are typically whitelisted by enterprises for employee internet use," he said.
"Fake virus alerts and system updates delivering malicious exploit kits are ubiquitous in today's highly complex and dynamic digital ecosystem. In order to effectively deliver malware and exploit kits, threat actors have resorted to sophisticated coding to enable advanced filtering," he added.
"There has been a surge in the detection-evading malware that only executes when conditions are favourable. Furthermore, in order to accurately target and deliver malware to specific endpoints and internet users, threat actors exploit the very technologies that website owners utilise to deliver customised and personalised content to their users."
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Global cybersecurity spending is set to rise 12% in 2025 – here are the industries ramping up investment
News Global cybersecurity spending is expected to surge this year, fueled by escalating state-sponsored threats and the rise of generative AI, according to new analysis from IDC.
By Ross Kelly Published
-
Google Cloud is leaning on all its strengths to support enterprise AI
Analysis Google Cloud made a big statement at its annual conference last week, staking its claim as the go-to provider for enterprise AI adoption.
By Rory Bathgate Published
-
JD Sports details cyber security revamp following January attack
News It hopes a multi-vendor approach will substantially improve its cyber resilience
By Connor Jones Published
-
96% of CISOs without necessary support to maintain cyber security
News Security professionals are leaving due to stress, and called out lack of understanding from co-workers
By Rory Bathgate Published
-
Employees behaving badly?
Whitepaper Why awareness training matters
By ITPro Published
-
Freshworks CISO Jason Loomis embraces the ‘shift left’ amid surging supply chain threats
Case Studies Fewer than 100 days in the role, Jason Loomis reveals his plans for the future of security at Freshworks, and discusses the rising threat of API vulnerablities
By Ross Kelly Published
-
CISOs reveal secrets to pandemic success in critical organisations
News The pandemic presented unique challenges for every business, but organisations tasked with delivering critical services may have worked the hardest
By Connor Jones Published
-
Almost 70% of CISOs expect a ransomware attack
News Many companies are willing to make ransomware payments in the face of the growing threat
By Danny Bradbury Published
-
CISOs aren’t leading by example when it comes to cyber security
News Cyber security leaders engage in risky online behavior, according to a survey
By Rene Millman Published
-
Panel Profile: Moonpig head of cyber security Tash Norris
IT Pro Panel We get face-to-face with one of the IT Pro Panellists
By IT Pro Published