Accessibility Statement Skip Navigation
  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing
  • Login
  • GDPR
  • Create a Free Account
Return to PRWeb homepage
  • News
  • Resources
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
  • Business & Money
      • Auto & Transportation

      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • View All Auto & Transportation

      • Business Technology

      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • View All Business Technology

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Financial Services & Investing

      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • View All Financial Services & Investing

      • General Business

      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • View All General Business

  • Science & Tech
      • Consumer Technology

      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • View All Consumer Technology

      • Energy & Natural Resources

      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • View All Energy & Natural Resources

      • Environ­ment

      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • View All Entertain­ment & Media

      • Health

      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • View All Health

      • Sports

      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • View All Sports

      • Travel

      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • View All People & Culture

  • Hamburger menu
  • Cision PRWeb provides efficient communication tools to continuously engage with target audiences across multiple online channels
  • Create a Free Account
    • ALL CONTACT INFO
    • Contact Us


      11AM ET Sunday – 8PM ET Friday

  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR
  • Send a Release
  • Sign up
  • Log in
  • Resources
  • RSS
  • GDPR

Morphixx Malvertising Scam Attacks US, Japan & Europe in a Global Malicious Ad Campaign to Steal Credit Card Numbers & Generate $5 - 10 Billion in Credit Card Charges

GeoEdge security research team first uncovered the Morphixx malicious credit card scam attack ads in Europe in June, and a full-blown auto-redirect malvertising attack with millions of ad impressions was launched in Japan on August 15th and in the US on September 6th, which was thwarted by GeoEdge


News provided by

GeoEdge

Sep 09, 2020, 15:00 ET

Share this article

Share toX

Share this article

Share toX


NEW YORK, Sept. 9, 2020 /PRNewswire-PRWeb/ -- This year has already been a record year for malicious advertising, with malware attack ads increasing by 85% according to ad security provider GeoEdge.

Research from the Federal Trade Commission shows that identity theft has increased by 75.4% between 2017 and 2019 with credit card scams accounting for 41.8% of the reported incidences of identity theft. And this is before accounting for the increase in 2020 as a result of COVID-19 and the laxer security resulting from more users working from home.

“The Morphixx malvertising credit card scam was run by an advanced and well-funded group of cybercriminals, judging by the sophistication of the ad implementation and personalization, the timing of the ads for less than 24 hours during the weekend when fewer security employees are working, and the f

Post this

As these numbers attest, credit card scams have become big business. According to cyber intelligence firm Sixgill, in the first half of 2019, there were 23 million credit and debit card numbers for sale in the dark web, with 15 million of those American cards.

This has enticed multinational cybercriminal organizations to invest resources to develop and implement digital advertising-based credit card scams. The global nature and sophistication of the Morphixx malvertising attacks indicate that the perpetrators aren't teens in their basement. And the increased digitization of payments will undoubtedly be met with a significant increase in malvertising attacks involving payment solutions.

On June 23rd, the Morphixx campaign ads were first noticed in Europe, in low volumes, and without the malicious payload. The malicious advertisers inserted keywords like 'Adidas' into the ad's URL as a distraction to gain the trust of the ad networks which ran the campaign, making malicious detection more difficult (than when campaigns are run from private servers instead of known ad networks). Because the ads ran via known ad networks, they appeared on popular and trusted websites.

On June 28th, the number of ad impressions increased dramatically targeting users in the UK, Italy, Switzerland, and other countries based on their IP address with the malicious payload, according to security researchers at GeoEdge. From the initial Adidas ad, users were auto-redirected to a malicious fake ad in the colors, logo, and language of each user's Internet Service Provider (ISP) asking them to complete a short survey. Upon completion of the survey, a congratulatory message was triggered announcing that each user won a free mobile phone for which they must submit their email and credit card details.

This is where innocent users fell pretty to the malvertising scam.

To avoid detection, the malvertisers behind Morphixx implemented a fingerprinting process to avoid detection mechanisms by loading a creativeJS file which allows the project to be downloaded quickly and cached across different sites using the same version of libraries. Next, the malicious script is loaded – an obfuscated script to set up the URL for the initiation of the redirect script.

Security researchers at GeoEdge, utilizing the company's patented behavioral code analysis technology, content and deep landing page analysis, and advanced malware detection, uncovered the Morphixx malvertising credit card scam in Europe. The landing page with prizes and comments from 127 people, many including profile pictures, highlights the sophistication of the Morphixx malvertising efforts.

Given the elaborate personalization of the content, including branding from the user's ISP, the percent of users who fall victim to such a scam can be as high as 1 – 2%, according to GeoEdge.

The campaign in Japan, also detected by GeoEdge's security research team, was identical, indicating that both efforts are from the same cybercriminal organization. The number of ads served in Japan was greater than in Europe, undoubtedly influenced by the fact that Japan is a cyber-secure country and users tend to be more trusting than in Europe or North America.

On Sunday, September 6th, in the early morning hours, the Morphixx malicious credit card scam struck in the US, according to GeoEdge's security research team.

"The Morphixx malvertising credit card scam was run by an advanced and well-funded group of cybercriminals, judging by the sophistication of the ad implementation and personalization, the timing of the ads for less than 24 hours during the weekend when fewer security employees are working, and the fact that these campaigns have run across so many geographies and time zones," said Liran Lavi, Security Team Lead, GeoEdge. "These cybercriminals either have a network to monetize the stolen credit cards quickly OR are selling the credit card numbers on the dark web – not things teen hackers typically attempt."

"The only way to block increasingly sophisticated and payment-based malicious ad attacks like Morphixx is through continuous and real-time advanced malware detection utilizing patented behavioral code technology," added Liran from GeoEdge.

About GeoEdge
GeoEdge is the premier provider of ad verification and transparency solutions for the online and mobile advertising ecosystem. The company's mission is to protect the integrity of the digital advertising ecosystem and to preserve a quality experience for users. It ensures high ad quality and verifies that sites and apps offer a clean, safe, and engaging user experience. GeoEdge guards against non-compliance, malware, inappropriate content, data leakage, operational, and performance issues.‎ Leading publishers, ad platforms, exchanges, and networks rely on GeoEdge's automated ad verification solutions to ‎monitor and protect their ad inventory – without sacrificing revenue. The company was founded in 2010 by a team with more than two decades of hands-on technical and online media experience. To learn more, visit http://www.geoedge.com

SOURCE GeoEdge

Related Links

http://www.geoedge.com

Modal title

Contact PRWeb

  • 11AM ET Sunday – 8PM ET Friday
  • Contact Us

About PRWeb

  • About PRWeb
  • Partners
  • Partnership Programs
  • Editorial Guidelines
  • Resources

Why PRWeb

  • Why PRWeb
  • How It Works
  • Who Uses It
  • Pricing

Accounts

  • Create a Free Account
  • Log in
  • Contact Us

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Center
  • ProfNet
Cision Distribution Helpline
888-776-0942
  • Legal
  • Site Map
  • RSS
  • Cookie Settings
Copyright © 2025 Cision US Inc.