THREAT OPS › Threat News › Adform compromised to serve crypto stealer via supply chain attack
Adform compromised to serve crypto stealer via supply chain attack
<p>Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category.</p><p>They operate by offering a Javascript embed for websites, via this URL:</p><p>hxxps://s2.adform.net/banners/scripts/st/trackpoint-async.js</p><p>This script was compromised to serve a crypto stealer. Adform have been hacked. As far as I can tell Adform haven’t told people
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- 02ff86c7f9fe609a753ff15bda90baa3c3e0d4a2e559ec4fcf8a3de0954b7c55sha256
- http://84.32.102.230:7744/p?h=example.com&u=/testurl
- https://pastebin.com/mc7psaNFurl
- 84.32.102.230ipv4
- s2.adform.netdomain