Yahoo & AOL Visitors Hit by Ransomware

Security research firm Proofpoint is reporting that recent visitors to sites such as Yahoo & AOL may have been infected with ransomware through malvertisements.

What did Proofpoint detect?

Without having to click on anything, visitors to the impacted websites may be stealthily infected with the CryptoWall 2.0 ransomware. Using Adobe Flash, the malvertisements silently “pull in” malicious exploits from the FlashPack Exploit Kit. The exploits attack a vulnerability in the end-users’ browser and install CryptoWall 2.0 on end-users’ computers. Similar to the behavior of other “ransomware,” CryptoWall then encrypts the end-users’ hard drive and will not allow access until the victim pays a fee over the Internet for the decryption key. Typically, the end-users face an escalating time deadline; failure to pay by the deadline results in their hard drives being permanently encrypted, thus rendered effectively useless, with all information inaccessible.

Which websites were impacted?

Proofpoint detected that the following large websites were serving malvertisements which delivered the FlashPack exploit kit to visitors. The sites themselves were not compromised; rather, the advertising networks upon which they relied for dynamic content were inadvertently serving malware – which in turn, was not due to an explicit compromise of the networks; rather, it was due to the networks accepting ads from a malicious source without screening detection. The sites’ domain and Alexa rankings are displayed in parenthesis after each in order to provide context of potential end-user impact. All told, more than 3 million visitors per day were potentially exposed to this malvertising campaign.

Yahoo! Finance, Fantasy and Sports (, Global 4, US 4),
AOL (, US 37, Global 119),
The Atlantic (, US 386, Global 1,206),
9GAG (, US 528, Global 201,), (US 203, Global 631),
The Sydney Morning Herald (, Australia 13, Global 780), (Australia 17, Global 1,656),
The Age (, Australia 34), (New Zealand 9), (France 54, Global 1,649),
Dumpert (, Netherlands 24),
Flirchi (, India 106, Global 1,129),
Weatherzone Australia (, Australia 111),
Brisbane Times (, Australia 183),
RSVP (, Australia 351),
The Canberra Times (, Australia 403),
Time Out (US 1,145, Global 1,816),
The Beacon-News (, US 1,178),
Merca2.0 (, Mexico 229), (Japan 1,124),
iPhone for Hong Kong (, HK 112),
Noticias Argentinas (, Argentina 784)

6 thoughts on “Yahoo & AOL Visitors Hit by Ransomware”

  1. Anyone caught in this should forward the bill to A.O.L. and/or Yahoo since it was their negligence to not screen the advertisers. Maybe if it costs THEM money they will be a little more careful with who they let advertise.

    This is right up there with the mess at Home Depot. They are being charged with Criminal Negligence.

  2. I use AdBlock Plus, and never see ads in the first place. I don’t think the malads will affect me in this way, but there’s always a first time …

