{"id":34555,"date":"2020-04-22T15:05:11","date_gmt":"2020-04-22T15:05:11","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/31143\/Hackers-Have-Breached-60-Ad-Servers-To-Load-Their-Own-Malicious-Ads.html"},"modified":"2020-04-22T15:05:11","modified_gmt":"2020-04-22T15:05:11","slug":"hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/","title":{"rendered":"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/2020\/04\/21\/183dcb18-ef6e-457f-9fb2-c3bc3a65c292\/malvertising.png\" class alt=\"Malvertising\"><\/span><\/p>\n<p>A mysterious hacker group has been taking over ad servers for the past nine months in order to insert malicious ads into their ad inventory, ads that redirect users to malware download sites.<\/p>\n<p>This clever hacking campaign was discovered last month by cyber-security firm Confiant and appears to have been running for at least nine months, since August 2019.<\/p>\n<p>Confiant says hackers have targeted advertising networks running old versions of the <a href=\"https:\/\/github.com\/revive-adserver\/revive-adserver\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Revive<\/a> open-source ad server. Hackers breach outdated Revive servers and silently append malicious code to existing ads.<\/p>\n<p>Once the tainted ads load on legitimate sites, the malicious code hijacks and redirects site visitors to websites offering malware-laced files &#8212; usually disguised as Adobe Flash Player updates.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/\" class=\"lazy\" alt=\"malicious-ads.png\" data-original=\" https:\/\/zdnet4.cbsistatic.com\/hub\/i\/2020\/04\/21\/a099d84d-08ec-4fcf-94fc-71c792105575\/malicious-ads.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet4.cbsistatic.com\/hub\/i\/2020\/04\/21\/a099d84d-08ec-4fcf-94fc-71c792105575\/malicious-ads.png\" class alt=\"malicious-ads.png\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: Confiant<\/span><\/p>\n<p>Confiant says it identified around 60 Revive ad servers that have been compromised by this hacker group &#8212; which the company has codenamed Tag Barnakle.<\/p>\n<p>The company says the group has managed to load its malicious ads on thousands of sites, with the malicious ads being broadcast to other ad companies thanks to RTB (real-time bidding) integrations between services.<\/p>\n<p>&#8220;If we take a look at the volumes behind just one of the compromised RTB ad servers &#8211; we see spikes of up to 1.25 [million] affected ad impressions in a single day,&#8221; <a href=\"https:\/\/blog.confiant.com\/tag-barnakle-the-malvertiser-that-hacks-revive-ad-servers-redirects-victims-to-malware-50cdc57435b1\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">said Eliya Stein<\/a>, a Senior Security Engineer at Confiant.<\/p>\n<h3>Tag Barnakle is not not norm for malvertisers<br \/><\/h3>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>Stein says Tag Barnakle is a rare breed of malvertiser. Malvertising groups that hack ad servers haven&#8217;t been seen operating at this scale <a href=\"https:\/\/blog.checkpoint.com\/2016\/04\/01\/angler-ek-malvertising-via-hacked-revive-adserver\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">since 2016<\/a>.<\/p>\n<p>For the past years, most malvertising groups have operated by a different strategy &#8212; by creating networks of fake companies that buy ads on legitimate sites, which they later modify to load malicious code.<\/p>\n<p>This tactic has been prevalent over the past few years because some shady ad networks are willing to turn a blind eye to malvertisers buying ads on their systems since both parties are making a profit. However, Tag Barnakle&#8217;s modus operandi is not something that ad companies will be willing to put up.<\/p>\n<p>&#8220;We have seen other malvertisers do this, but it&#8217;s less widespread in general for several reasons,&#8221; Stein told <em>ZDNet<\/em> in an email. &#8220;First of all, I believe there&#8217;s a sense among the attackers that there&#8217;s a legal gray area when it comes to malvertising, but once you compromise an ad server there is no question that you&#8217;ve broken the law in a big way.&#8221;<\/p>\n<p>&#8220;It&#8217;s also a different focus altogether,&#8221; Stein added. &#8220;I imagine not all malvertisers have the skillset and wherewithal to actually go out and hack ad serving infrastructure or accounts. Paying for a media buy [an ad slot] is the path of least resistance.&#8221;<\/p>\n<h3>Attacks still ongoing<br \/><\/h3>\n<p>Stein tells <em>ZDNet<\/em> that Confiant has been spending the last few weeks notifying advertising companies that have been breached. However, not all advertising companies have yet to act on Confiant&#8217;s warnings about Tag Barnakle so far.<\/p>\n<p>&#8220;The campaign itself is ongoing among the ad servers that are still compromised,&#8221; Stein told <em>ZDNet<\/em>.<\/p>\n<p>&#8220;We have notified the owner of every single ad server about the breach, but not everyone has followed up with us. Some of the ad servers were impacted briefly, maybe just a matter of days before the ad server owner patched the breach. Others continue to be live to this day,&#8221; he added.<\/p>\n<p>&#8220;From our standpoint, we continue to block any ads on behalf of our customers that are being served from ad placements previously associated with the compromise.&#8221;<\/p>\n<p>Stein also said that Confiant will be publishing more reports on malvertisers hacking ad servers and their tactics going forward.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/31143\/Hackers-Have-Breached-60-Ad-Servers-To-Load-Their-Own-Malicious-Ads.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":34556,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[8594],"class_list":["post-34555","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinehackermalwarefraudbackdoor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-04-22T15:05:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"425\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads\",\"datePublished\":\"2020-04-22T15:05:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/\"},\"wordCount\":619,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png\",\"keywords\":[\"headline,hacker,malware,fraud,backdoor\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/\",\"name\":\"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png\",\"datePublished\":\"2020-04-22T15:05:11+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/04\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png\",\"width\":1000,\"height\":425},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,malware,fraud,backdoor\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackermalwarefraudbackdoor\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/","og_locale":"en_US","og_type":"article","og_title":"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-04-22T15:05:11+00:00","og_image":[{"width":1000,"height":425,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads","datePublished":"2020-04-22T15:05:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/"},"wordCount":619,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png","keywords":["headline,hacker,malware,fraud,backdoor"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/","url":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/","name":"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png","datePublished":"2020-04-22T15:05:11+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/04\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads.png","width":1000,"height":425},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hackers-have-breached-60-ad-servers-to-load-their-own-malicious-ads\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,malware,fraud,backdoor","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackermalwarefraudbackdoor\/"},{"@type":"ListItem","position":3,"name":"Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/34555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=34555"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/34555\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/34556"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=34555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=34555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=34555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}