opinion

Malicious Monetization

Perhaps you can blame the declining economy as the culprit behind the escalating bad behavior being exhibited throughout certain segments of cyberspace, where everything from fraudulent billing to extortion and beyond awaits the unwary surfer with increasing regularity — a situation that sometimes hits too close to home.

For example, a recent XBIZ News story detailed a German federal Office for Information Security (BSI) report of the "growing and persistent array of online threats that continues to outwit even the savviest of users."

"The situation is serious — it is even more catastrophic than we feared," said Hartmut Isselhorst of the BSI. "We are all being attacked. As soon as we go online, we become the target of attacks."

And right they are.

I've been a heavy Internet user and webmaster since 1993, and in that time, I have had one website hacked (damn kids in Amsterdam deleted my site and put a photo of a bong on my homepage …) and had my workstation disabled by KAK, which left me freaked out by it shutting down and displaying a notice that "kagou anti krosoft says not today!"

But that was a long, long time ago, and my security has dramatically improved since then to the point that I don't get too worried about visiting some of the, shall we say, "shadier" online neighborhoods that my work sometimes finds me in.

Until now, that is.

What has me concerned is two recent attacks that hit within a matter of days of each other — events about which I'm still dealing with the fallout.

First up was an infection that left me with a copy of Spyware Protect 2009 on my system, displaying its ominous "Warning! You have spyware on your computer — click here to purchase our tool to remove it!" dialog boxes and Windows system-like behaviors to make it look "official." The folks behind this did a great job of presenting their offer, and the persistent little bugger took quite a bit of effort (and bad language) to remove — being entrenched in my browser, task bar and throughout my system's files.

As part of this attack, a host of other nasty mutants compromised some of my anti-virus and firewall protection in an attempt to "pry the door open" for further attacks, which was a most disheartening experience as I watched my fortress' walls crumbling.

As a side note, for the many people who doubtless bought into this software scam, far from removing the threat, the Spyware Protect 2009 installation would simply heap even more digital atrocities onto the hapless user's computer.

Did I pick something up on an adult site? Maybe, but I visit at least as many mainstream websites, and they often are more attractive to hackers.

Regardless of where the actual attack took place, those initiating these attacks are online extortionists who seek to use fear as a weapon to drive sales. And while I didn't make a purchase, I was scared — scared at the thought of losing all of my data (how current are those backups?) and of the loss of any sensitive information of value to identity thieves or other criminals. What else was my computer doing now — things that I didn't even know about — like launching "zombie" attacks on other computers?

It took a lot of Googling to get things straightened out, plus the use of some new tools such as Malwarebytes' Anti-Malware solution, as well as the loss of a few hours and a lot of stress to overcome this infection, which was far more sophisticated in its attack than the previous KAK virus that I had. Bastards.

And you'd think that I'd learned my lesson and would be more wary, but you'd be wrong — and so it was that two days after cleaning out my system I found myself upgrading an old WordPress installation on my server to the latest version, which has a nifty FTP client to upload and install plugins. But plugins by whom, from where — and how safe are they?

The one I installed that day using said fancy admin panel asked for my FTP username and password — not the first piece of software I've installed to do so. And you might have guessed it, but the next morning, all of the index pages on all of the sites on that server (and their subdirectories) had malicious commie code embedded in them, trying to send my visitors unknowing-like to domains that ended in .ru.

Encoded HTML redirects placed in my <head>s using JavaScript and "eval" commands, plus encrypted scripts injected into the PHP contained in my <body> tags. Had they done it by hand and gone back to check the pages, they could be wreaking havoc on anyone who landed on one of my pages. Sloppy hackers and their automation — stray snippets of their malicious code were left visible on some of my pages, and if not for this glaring red flag, I might not have noticed the attack — at least for some time.

Changing my FTP password stopped them, but once again, hours are lost and sleepless nights spent restoring corrupted pages from backup files and scouring folders for other signs of attack.

While malicious website attacks are nothing new, this apparent increase in the incidence and severity of these attacks doesn't bode well for e-merchants, mainstream or adult, who rely on a customer's trust factor when dealing with virtual entities.

At a time when every sale counts, marketers and others using malicious tools to further their means and bottom lines are a threat to all operators — and a threat that must be confronted and addressed.

For my part, I'm going to beef up security and push ahead.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

opinion

Why Retail Expertise Is Essential When AI Tools Analyze Store Data

Somewhere in one of our stores, someone scanned a barcode into a quantity field. The number entered was 8,388,607. At $19.99 per unit, that made a single line item worth roughly $167 million. The number was so large that the import failed immediately.

Zondre Watson ·
trends

Why Adult Retailers Need Better Training on Disability, Chronic Health

Every customer who walks into an adult store brings a different body, comfort level and set of needs. Retail staff already know how to ask the basics: Do you prefer vibration or suction? Are you using water-based or silicone lubricant? Do you have a latex allergy? What size are you comfortable with?

Mersy Love ·
profile

YourVids' Gino on Listening, Learning and Putting Creators First

Get Gino talking about the work creators pour into their careers, and his passion quickly becomes contagious. He deeply appreciates the people powering the business and has firm ideas about what they deserve in return.

Jackie Backman ·
profile

Vendo CEO Mitch Platt Reflects on 20 Years of Lessons and Evolution

More than 20 years ago, three entrepreneurs in Barcelona began gathering over beers to pitch, dissect and routinely destroy one another's business ideas. The ritual was simple: One person arrived with a concept, while the other two tried to expose every weakness. Any proposal that survived earned another look. Most did not.

Jackie Backman ·
profile

Abby Rose on Camming, Connection and Creative Chaos

Abby Rose has mastered the art of viewing life through rose-colored glasses, finding the good in even the most challenging circumstances. With the bubbly charm of Elle Woods and the steely determination of G.I. Jane, she pairs a resilient spirit with a deep love for bringing people together.

Jackie Backman ·
opinion

How to Avoid the Hidden Risks of AI-Generated Legal Documents

Artificial intelligence can write a contract in seconds, but that does not mean it can write the contract your business actually needs. Across the adult industry, operators, creators and producers are increasingly using generative AI to prepare model releases, performer agreements, privacy policies, takedown notices, employment documents and responses to regulators. The appeal is obvious: Legal work is expensive, AI is fast and the resulting document often looks impressively professional. That polished appearance is exactly what makes the practice dangerous.

Corey Silverstein ·
profile

Anastasia's Bedroom Founder Chelsea Mani Bridges Ecommerce With Local Events

Chelsea Mani spends her weekends at local markets, where she displays an assortment of lingerie ranging from new lace bodysuits and silky robes to carefully sourced, cleaned and pressed vintage pieces. Passersby stop to examine the fabrics, ask questions and sometimes find themselves opening up unexpectedly.

Jackie Backman ·
profile

Karla Lane Talks Curves, Confidence and Career Longevity

With her killer curves poured into a slinky silver dress, longtime performer Karla Lane swept onto the XMAs stage in Miami earlier this year to claim the trophy for BBW Premium Social Media Star. As she ascended the steps, presenter and fellow performer Vicki Chase purred, "Come on, big mama," in a playful nod to Latto's viral anthem.

Jackie Backman ·
opinion

How Rolling Reserves Affect Cash Flow and Merchant Stability

You log in to your payment processor’s dashboard, discover they are withholding 10% of your sales, and immediately assume something has gone wrong. In reality, everything is working exactly as intended.

Jonathan Corona ·
opinion

Creator Tips for Turning AI Prompts Into Effective Promos

Creating great content is only half the job. Every photo set, clip, custom video, pay-per-view message, bundle and subscription offer still needs to be marketed, and finding fresh ways to promote the same material can become just as exhausting as creating it.

Megan Stokes ·
Show More