Thursday, April 9, 09:54
Home security Abuse of legal TDS platform to distribute malware

Abuse of legal TDS platform to distribute malware

TDSCyber ​​criminals violated the law TDS (Traffic Direction System) platform Keitaro and used it to redirect them users in exploit kits RIG and Fallout in order to infect them with malicious software.

TDS platforms are designed for redirection of users in particular sites. Legitimate TDS platforms, such as Keitaro, are mainly used by individuals and companies that want to advertise services or their products. Platforms drive users to the pages that companies want, targeting specific customers and promoting an ad campaign.

The Keitaro platform, for example, uses more than 20 filters to accurately target users (e.g., location, device information, information for the browser and more).

However, these platforms can also be used by hackers for evil purposes.

There are, indeed, some that are specially designed for illicit purposes (e.g. EITest, Seamless, Sutra, BlackOS, NinjaTDS). These TDS platforms redirect the possible victims in exploit kits that try to infect them with malware.

"TDS platforms are a very useful tool for an attacker who wants to restrict the distribution of malicious content," said Proofpoint researchers. "An attacker using TDS can ensure that the detectors and Investigators security they see nothing malicious, but real users are redirected to exploits and malware».

- Advertisement -

Distribution of malware

Proofpoint researchers discovered that some hackers had breached it platform Keitaro and used it for making malvertising and malspam campaigns.

Using a legitimate TDS platform has made it difficult to detect illegal activity but also to block redirects.

Keitaro was used in August to redirect users to the Fallout or RIG exploit kit where possible vulnerabilities and the geographical location of each target, and based on various other criteria.

The goal of the hackers was to redirect users: 1) to malvertising sites that infected them using one of two exploit kits, 2) on malicious files that install malware. In the end, they were even guided by law sites.

Victim systems were infected with various malicious programs, such as AZORult, Predator the Thief, CoinMiner, KPOT, SystemBC, Osiris, Chthonic, Vidar Stealer, Amadey, Danabot “40”, Vidar, Gootkit or Onliner.

The attackers who took advantage of the Keitaro TDS platform were cleverly moved to exploit a legitimate platform so their malicious activities could not be easily detected.

Researchers continue to monitor the Keitaro platform.

Absent Mia
Absent Mia
Being your self, in a world that constantly tries to change you, is your greatest achievement


Please enter your comment!
Please enter your name here


OTEAcademy: Telecommunication Program for Scientists & Freelancers, affected by COVID-19

OTEAcademy participates in the special telecommunication program - certification for scientists and freelancers affected by COVID-19.

Facebook wanted to buy Pegasus Spyware to track Apple users

According to NSO CEO Shalev Hulio, Facebook tried to buy ...

7 apps to watch movies online at the same time as your friends

According to the recommendations made by governments and health organizations around the world, ...

Tesla's model uses solar energy to move

The designs for a Tesla Roadster, with an engine that uses solar energy, were recently released on the internet and ...

George Soros is pushing for a postal vote due to COVID-19

George Soros pushes for postal voting due to COVID-19: For the purposes of the vote, George Soros-funded Brennan Center ...

Sony: Reveals the new DualSense controller for the PS5!

Together with the fifth model Playstation, PS5, Sony has unveiled the new DualSense space controller, which retains some of the ...

Koronoios: Fraudsters sell blood and saliva from a survivor on the Dark Web

The ad on Own Shop, a store on the Dark Web, claims that someone has been infected with coronavirus and is now selling ...

UbuntuDDE: Ubuntu Linux with Deepin desktop

UbuntuDDE: Ubuntu Linux with Deepin desktop- Have you ever wondered what would happen if you combined the powers ...

Facebook: Launches new chat application for couples due to COVID-19!

As the governments of a large number of countries have taken measures of social distancing and lockdown, in an effort to limit ...

Netflix: Lock your PIN account for more security

Netflix: Lock your PIN account for more security - Netflix, one of the best known ...