2 comments

[ 3.4 ms ] story [ 12.1 ms ] thread
The malware uses basic router exploits and/or guesses default credentials to get into the routers. From there DNS hijacking is easy as pie, as long as the target does not do DNSSEC.

This is not technically attacking websites, only connections served by hijacked routers should be affected. Besides, since the malware intercepts Google Analytics tags to inject ads, any website not using that tracking engine should not be affected.

Source: the Ara Labs report linked in the article, at http://aralabs.com/blog/2015/03/25/ad-fraud-malware-hijacks-...