Euro Websites Broadcast Trojan in Banner Ads

CYBERSPACE — A string of European websites transmitted malicious code to visitors over the course of approximately six hours this weekend after banner ads and advertising servers became infected with Bofra/IFrame code exploits, according to SANS Institute’s Internet Storm Center.

The problem was eventually traced back to the third-party advertising server Falk AG, which transmits advertising to websites that include The Register, NBC Universal, The Golf Channel and A&E Networks.

Also affected was NU.nl, the Netherlands’ largest news website with over 450,000 visitors each month.

According to Falk, the problem started around 6:10 p.m. GMT, when the company experienced an attack on one of its load balancers. Designed to evenly distribute requests to multiple servers, the balancer began to distribute about every 30th request to search.comedycentral.com, a compromised website that contained the Bofra/IFrame exploit.

“The purpose of the exploit was to establish a redirect to malicious code through a javascript component of Falk’s ad delivery,” Falk told its customers. The total amount of redirects were only 2 percent of EU ad requests, the company said.

LURHQ Threat Intelligence Group reported that at least two different Trojans were being installed by during the six hours that the compromised advertisements were being served. Infamous adware Trojan Virtumonde and backdoor downloader Trojan.Agent.EC were both fingered in the attacks.

Both programs use the IFrame exploit, discovered in late October and applicable to all Windows platforms except Windows XP Service Pack 2.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

TrustyFans Introduces New Blog

Creator directory TrustyFans has introduced an official blog to its site, titled "From Hidden to Hype."

JustFor.fans' Dominic Ford Featured in Wired Magazine

JustFor.fans Founder and CEO Dominic Ford is featured in a new article in Wired Magazine, titled "The Internet Revolutionized Porn. Age Verification Could Upend Everything."

Dr. Charlotte Gaydos Joins ProDx Health Advisory Board

Dr. Charlotte Gaydos has joined the Advisory Board of ProDx Health.

Aylo Fined $5 Million as FTC, Utah Settle Safety Practices Complaint

The Federal Trade Commission and the state of Utah on Wednesday settled a complaint against Aylo, requiring the company to pay a $5 million penalty and implement measures to prevent illegal content from appearing on its sites.

New AI Companion Platform 'Pornstar.love' Launches

Pornstar.love, a new AI companion platform, has officially launched.

Pineapple Support, Stripchat to Host 'Navigating Thoughts of Suicide' Support Group

Pineapple Support and Stripchat are hosting a free online support group to help performers deal with suicidal ideation.

Plaiir Names Cade Maddox as Lead of Creator Relations

Networking platform Plaiir has appointed Cade Maddox as its new lead of creator relations.

Go.cam Launches 'One-Line Integration' Verification Solution

Go.cam has introduced a one-line code integration for age verification.

XBIZ Amsterdam to Debut 'Behind the Lens' Screening Series

XBIZ is pleased to announce the debut of “Behind the Lens,” a new screening series presenting discussions with noted directors, taking place at the upcoming annual European conference, XBIZ Amsterdam.

'White Rabbit' Party Headed for XBIZ Amsterdam

XBIZ is pleased to announce the White Rabbit Party, an XBIZ Amsterdam special event set to take place Wednesday, Sept. 3.

Show More