Massive adware campaign spoofs top brands to trick users

Fraud
Image Credit: Shutterstock (Image credit: Gustavo Frazao / Shutterstock)

Cybersecurity researchers have recently discovered a huge website spoofing campaign that impersonates major brands to distribute malware or serve malicious ads to visitors. 

Researchers from Cyjax found a group called “Fangxiao”. This group operates more than 42,000 web domains impersonating companies such as Coca-Cola, McDonald’s, Unilever, Emirates, and others. 

More than 400 companies have experienced a form of identity theft in this campaign, researchers said.

How it works

The group, which apparently operates out of China (one of the exposed control panels was allegedly in Mandarin), creates roughly 300 of these domains every day. They then advertise them either through WhatsApp messages or mobile ads.

Victims that click on these links are sent to landing pages that employ all kinds of tactics to keep them engaged and too busy to consider the fact that it’s all one big scam. These landing pages also host ads from ylliX, an ad network labeled “suspicious” by both Google, and Facebook, the publication claims. 

The endgame is to have the victims either download an app (a Triada trojan), make SMS micropayments in ignorance, open up fake dating sites, or earn a commission for the attackers via Amazon affiliate links.

In some cases, the victims are also incentivized to download an app from the Play Store called “App Booster Lite - RAM Booster”. While this one isn’t outright malicious, it does request shady permissions and serves a huge number of hard-to-close ads. According to the report, this app was built by the same developer that was previously seen engaged in adware. 

Other than the fact that the threat actors are based in China, there is very little information that could lead to its identification. Fangxiao was also observed selling its services for other entities looking to boost web traffic. 

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
A padlock resting on a keyboard.
Understanding and avoiding malvertizing attacks
A close-up of an interent search bar with 'http://ww' visible
Major website hijacking scam sees over 35,000 sites attacked, redirected to gambling sites, so be on your guard
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Mac users targeted with new malware, so be on your guard
NordVPN
US hit with over 1.9 billion malware threats last year - here's how to stay safe
Latest in Security
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
A pair of hands using a keyboard
Microsoft SharePoint hijacked to spread Havoc malware
Latest in News
iPad Air M3
Apple makes one hardware change to the iPad Air that might be the best indicator of its true lightweight tablet intentions
An operator fires a saw blade from a weapon
Call of Duty: Black Ops 6 Season 3 gets two-week delay, will now release in April
Apple iPad A16
Apple's new entry-level iPad ups the performance for the same price, but doesn't support Apple Intelligence
iPad Air M3
Apple updates iPad Air with powerful M3 chip and pairs it with Pro-level Magic Keyboard
Samsung Galaxy Z Flip 6 in blue
The Samsung Galaxy Z Flip 7 might improve on its predecessor in one crucial way
Nvidia RTX 5070 Founders Edition GPU shown against a green and black backdrop
Nvidia RTX 5070 early pricing hints at plenty of GPUs at the MSRP – but I’ll believe it when I see it