Ad-blocker caught injecting ads in search results
Full article269 words · extracted from therecord.media · click to collapse
Cyber-security firm Imperva said it discovered a malicious browser extension named AllBlock, available for both the Chrome and Opera browsers, that has been injecting ads and referral affiliate codes inside search results. The discovery took place in August this year when Imperva researchers said they identified a domain that was hosting a malicious script that contained ad injection capabilities. A subsequent investigation linked the script to infrastructure used by the AllBlock ad-blocker extension, Imperva researchers Johann Sillam and Ron Masas said in a report published yesterday. According to their findings, the malicious behavior was described as follows: Sillam and Masas said they believed the AllBlock extension was part of a larger distribution campaign that most likely involved more malicious browser extensions. Based on some indicators, like IP addresses and domain names, the Imperva team believed this was part of a malware distribution operation called PBot. An AllBlock spokesperson did not return an email seeking comment on Imperva's findings. At the time of writing, Opera has removed the AllBlock extension from its site, while the Chrome extension is still available on the official Chrome Web Store.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ad-blocker-caught-injecting-ads-in-search-results