Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flaw in Google Ad Manager Exploited to Deliver Crypto-Stealing Malware
August 1, 2026
Best Cloud Firewall Solutions: Top 10 for 2026
August 1, 2026
HackerOne Mandates ID Verification for Bug Bounty Submissions
August 1, 2026
Home/CyberSecurity News/Critical Flaw in Google Ad Manager Exploited to Deliver Crypto-Stealing Malware
CyberSecurity News

Critical Flaw in Google Ad Manager Exploited to Deliver Crypto-Stealing Malware

Key Takeaways Adform, a major advertising technology firm, suffered a supply chain compromise where its ad-serving infrastructure was used to distribute crypto-stealing malware. Attackers injected...

Emy Elsamnoudy
Emy Elsamnoudy
August 1, 2026 4 Min Read
2 0

Key Takeaways

  • Adform, a major advertising technology firm, suffered a supply chain compromise where its ad-serving infrastructure was used to distribute crypto-stealing malware.
  • Attackers injected malicious code into a widely used JavaScript tracking script, silently infecting visitors to thousands of websites leveraging Adform’s services.
  • The malware functions as a clipboard hijacker, replacing cryptocurrency wallet addresses with attacker-controlled ones, and also collects victim IP addresses and visited URLs.
  • The attack was highly stealthy, with all associated malicious indicators initially appearing clean on major security platforms due to the compromise of a trusted source.
  • Website operators using Adform’s services are urged to audit third-party scripts and monitor outbound traffic for suspicious activity.

Adform Supply Chain Compromise Delivers Crypto-Stealing Malware

Adform, a prominent advertising technology provider with an estimated 30% share of the demand-side platform market and serving approximately 14,000 businesses, has experienced a significant supply chain breach. This compromise transformed its trusted ad-serving network into a conduit for distributing malware designed to steal cryptocurrency.

Table Of Content

  • Key Takeaways
  • Adform Supply Chain Compromise Delivers Crypto-Stealing Malware
  • Stealthy Distribution via Trusted Script
  • Evasion of Detection Mechanisms
  • What You Should Do

The incident was brought to light by security researcher Kevin Beaumont, who discovered that threat actors had hijacked a commonly deployed JavaScript file. This enabled them to covertly infect users browsing thousands of websites that integrate Adform’s advertising solutions.

The compromised element was a tracking script, hosted on Adform’s own domain, which is routinely embedded across numerous client websites to monitor advertising campaign performance.

Stealthy Distribution via Trusted Script

The widespread reliance on this single script meant that by compromising just one file, attackers gained potential access to millions of end-users. Any individual visiting a website that incorporated Adform’s tracking pixel could have unwittingly downloaded malicious code, making this a classic example of a supply chain attack.

Upon execution, the malicious script operates as a clipboard hijacker, a type of malware specifically engineered for cryptocurrency theft. It continuously monitors the victim’s clipboard, scanning every few seconds for copied Bitcoin, Ethereum, or Tron wallet addresses. When a legitimate wallet address is detected, the script surreptitiously replaces it with an address controlled by the attackers.

Given the complexity and length of cryptocurrency addresses, most users paste them without meticulous verification. This vulnerability allows funds intended for legitimate recipients to be diverted directly into a hacker’s wallet. The malware’s persistence is particularly concerning; even if a victim notices the discrepancy and re-copies the correct address, the malicious script overwrites it again during its subsequent polling cycle.

Beyond its financial theft capabilities, the script also functions as a surveillance tool. It silently logs the victim’s IP address, the referring website, and the specific URL path visited. This collected data is then transmitted back to an attacker-controlled server, providing insights into the spread of the supply chain compromise and helping the attackers map their reach across affected sites.

Evasion of Detection Mechanisms

A particularly alarming aspect of this incident is its ability to circumvent conventional security defenses. Initial checks against leading antivirus and threat intelligence platforms showed that every file, URL, domain, and IP address associated with the attack returned clean results. The malicious code was expertly concealed within a script originating from a legitimate and trusted advertiser, allowing it to bypass standard security filters designed to flag suspicious third-party content.

As of this reporting, Adform has not publicly confirmed whether it has notified affected customers or issued a formal disclosure. However, Kevin Beaumont has observed indicators suggesting the active removal of the malicious code, implying that either Adform or the attackers are aware that the operation has been exposed.

The indicators of compromise (IoCs) related to this attack include:

  • IP Address: 84.32.102[.]230 (Attacker-controlled beacon/C2 server on port 7744)
  • Domain: s2.adform[.]net (Compromised Adform subdomain serving malicious script)
  • URL: hxxps://s2[.]adform.net/banners/scripts/st/trackpoint-async.js (Malicious tracking script delivering clipboard hijacker)
  • File Hash (SHA-256): 02ff86c7f9fe609a753ff15bda90baa3c3e0d4a2e559ec4fcf8a3de0954b7c55 (Malicious payload file, flags clean on VirusTotal)
  • Beacon URL Pattern: hxxp://84.32.102[.]230:7744/p?h=<domain>&u=<path> (Data exfiltration request pattern, including victim domain and URL path)

What You Should Do

For website operators utilizing Adform’s services, immediate action is crucial:

  • Audit Third-Party Scripts: Conduct a thorough review of all third-party JavaScript files, especially those sourced from advertising platforms like Adform, to identify any unauthorized modifications or suspicious inclusions.
  • Monitor Outbound Traffic: Implement robust network monitoring to detect and alert on outbound connections to the identified attacker infrastructure (e.g., IP address 84.32.102[.]230 on port 7744), as well as any unusual data exfiltration patterns.
  • Rotate Credentials: If the compromise of Adform’s platform suggests broader access, consider rotating any API keys, tokens, or credentials that may have been exposed or used to integrate with Adform’s services.
  • Educate Users: Advise internal users and customers to exercise extreme caution when pasting cryptocurrency wallet addresses and to always double-check the address before finalizing transactions.
  • Review Security Logs: Analyze web server and client-side security logs for any indicators of compromise related to the malicious script or its beaconing activity.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Best Cloud Firewall Solutions: Top 10 for 2026

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CyberStrike: AI Platform Automates Penetration Testing
July 31, 2026
Critical JetBrains TeamCity CVE-2024-27198 Remote Code Execution Flaw Patched
July 31, 2026
FBI Warns North Korean IT Workers Exploit Stolen Identities
July 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us