Security Experts Warn Against Fraudulent 'Java Update' Popup on Adult Sites

Security Experts Warn Against Fraudulent 'Java Update' Popup on Adult Sites

LOS ANGELES — Two months after warning of a surge in malvertising fraud targeting adult websites, internet security experts have determined that the bad actors behind it have switched tactics from “exploit kit delivery” to “social engineering” via a fake Java update screen.

As XBIZ reported back in September, the criminal modality of “malvertising,” where bad actors sneak malicious code into supposedly legitimate banner ads, made a comeback this year as people spend more time online — and on adult sites.

Security firm Malwarebytes explained the initial stage of this campaign — which they dubbed “Malsmoke” — as “ads [that] redirect visitors to sites that serve malicious code.”

“When viewed with Internet Explorer or Adobe Flash, the code can exploit critical vulnerabilities in unpatched versions of Internet Explorer,” Malwarebytes initially warned.

Today, Malwarebytes announced that “starting mid-October, the threat actors behind ‘Malsmoke’ appear to have phased out the exploit kit delivery chains in favor of a social engineering scheme instead. The new campaign is tricking visitors to adult websites with a fake Java update.”

This change is significant, according to the security firm, because “it drastically increases the target audience, no longer limiting it to Internet Explorer users running outdated software.”

One of the largest adult sites targeted by the malvertising hackers, according to Malwarebytes, is xHamster.

To read an elaborate explanation of this latest modality in online fraud, visit Malwarebytes.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

CrakRevenue Introduces 'Trend Explorer' Feature for Affiliates

CrakRevenue has debuted the new Trend Explorer feature for its affiliates.

Tube Sites Submitter Introduces 'AI Video Description Generator' Feature

Tube Sites Submitter has introduced its new AI Video Description Generator feature for its platform.

Pineapple Support Releases End of Year Review for 2025

Pineapple Support has released its End of Year Review for 2025, detailing the organization's achievements, challenges, and new initiatives.

XBIZ Miami 2026 Lets the Good Times Roll at New South Beach Venue

Pack your favorite shades and sexiest poolside looks, because XBIZ Miami is splashing into a new hotspot — the chic Goodtime Hotel in the heart of Miami Beach — May 11–14.

Arcom Threatens to Block, Delist 2 Adult Sites Over AV Violation

French media regulator Arcom has sent enforcement notices to the operators of two adult websites that the agency says have failed to implement age verification as required under France’s Security and Regulation of the Digital Space (SREN) law.

Final Defendant Sentenced in GirlsDoPorn Case

Former adult producer Doug Wiederhold, previously a business partner of GirlsDoPorn owner Michael Pratt, was sentenced on Friday in federal court to four years in prison for conspiracy to commit sex trafficking.

FTC Takes Another Step Toward New 'Click to Cancel' Rule

The Federal Trade Commission (FTC) is negotiating the latest procedural hurdle in its effort to renew rulemaking concerning negative option plans, after a federal court previously vacated a “click-to-cancel” rule aimed at making it easier for consumers to cancel online subscriptions.

Pineapple Support, Brazzers to Host 'Navigating Relationships' Support Group

Pineapple Support and Brazzers are hosting a free online support group for performers to build and maintain healthy relationships.

Aylo, SWOP Behind Bars to Host 'Deplatforming' Community Panel

Aylo and Sex Workers Outreach Project (SWOP) Behind Bars will host a panel on creators’ rights and deplatforming on Feb. 10 at 3 p.m. (EST).

Show More