Kyle & Stan attack Amazon, YouTube & Yahoo with malicious ads
Websites targeted by “Malvertising” that attacks Windows and Mac users


A highly sophisticated attack has been carried out on millions of users via hundreds of websites including Amazon, YouTube and Yahoo using a malicious advertising network.
The attack was discovered by researchers working for Cisco. Dubbed "Kyle and Stan", malicious adverts appearing on the website trigger a download that affects Windows and Mac users, according to Armin Pelkmann, a Cisco threat researcher.
Pelkmann said the network uses "the enormous reach of well-placed malicious advertisements on very well-known websites in order to potentially reach millions of users."
"The goal is to infect Windows and Mac users alike with spyware, adware and browser hijackers. It is not too far-fetched that other kinds of malware are being used as well."
The malware got its name because the monikers "Kyle and Stan" appear in the subdomains of more than 700 websites the hackers set up to distribute the virus.
Cisco said the 700 domains currently in use were "just the tip of the iceberg".
"The large number of domains allows the attackers to use a certain domain just for a very short time, burn it and move on to use another one for future attacks," said Pelkmann in a blog post. "This helps avoiding reputation and blacklist based security solutions."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We are facing a very robust and well-engineered malware delivery network that won't be taken down until the minds behind this are identified."
Around 10,000 users connected to the network during Cisco's investigations and the malvertising targeted only a small number of firms that supply ads to websites.
"If an attacker can get one of those major advertisement networks to display an advertisement with a malicious payload just for a few minutes without being detected, then countless machines can be infected by such an attack," he said.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Cisco claims new smart switches provide next-level perimeter defense
News Cisco’s ‘security everywhere’ mantra has just taken on new meaning with the launch of a series of smart network switches.
By Solomon Klappholz
-
Cisco is jailbreaking AI models so you don’t have to worry about it
News Cisco's new AI Defense security solution helps organizations shore up LLM security by identifying potential flaws.
By Solomon Klappholz
-
Cisco dispels Kraken data breach claims, insists stolen data came from old attack
News Cisco has refuted claims it has suffered a data breach after the Kraken threat group posted stolen data online.
By Solomon Klappholz
-
Cisco patches critical flaws in Identity Services Engine
News Cisco has issued patches for a pair of critical vulnerabilities affecting its Identity Service Engine (ISE).
By Nicole Kobie
-
Your office is now absolutely riddled with surveillance equipment
News While workplace monitoring is shown to have a detrimental effect on morale, many firms are still charging ahead
By Nicole Kobie
-
Cisco confirms attackers stole data, shuts down access to compromised DevHub environment
News The tech giant insists that no sensitive customer information has been compromised
By Solomon Klappholz
-
Cisco confirms investigation amid data breach claims
News The networking giant says its probe is ongoing amid claims a threat actors accessed company data
By Nicole Kobie
-
Rubrik partners with Cisco to bolster cyber resilience
News Rubrik now integrates with Cisco XDR and is listed on the connectivity giant’s SolutionsPlus program
By Daniel Todd