LIVE · cybersecurity feed
Live wire
malvertisingmedium

Malvertising Scams Proliferate Across APAC Via Social Media Ads

Bitdefender Labs has identified a significant malvertising operation targeting the Asia-Pacific region. The campaign utilizes paid advertisements on Meta platforms to distribute scams, with over 12,000 campaigns observed across 13 countries. Health and finance-related scams are the most prevalent, contributing significantly to the overall campaign volume.

zeroday.news · 60d ago

Bitdefender Labs has identified a widespread malvertising network operating across 13 countries in the Asia-Pacific (APAC) region, distributing over 12,000 scam campaigns through paid advertisements on Meta platforms. Between January and April 2026, researchers Alexandra Svetlana Dinulica and Vlad Mihai Sireanu observed more than 400,000 ad sightings associated with these campaigns.

The fraudulent advertisements, while varied in content, consistently employ similar underlying tactics. Health and finance-related scams collectively account for 37.3% of all observed campaigns, with health scams making up 19% and finance scams 18%. Other categories include entertainment, home, gambling, courses, beauty, and software. Australia alone was the target of 52% of the identified scam campaigns.

Researchers noted three primary cross-country patterns: fake application downloads, scandal-driven phishing, and AI-themed investment scams. Scammers frequently reuse infrastructure, fake landing pages, redirect chains, and campaign templates across different countries and scam categories.

The typical attack flow begins with a seemingly legitimate paid ad, often featuring trusted brands, well-known personalities, or credible-looking news sources. In some instances, the ad preview even displays a legitimate domain. Upon clicking, users are redirected through one or more intermediary pages before arriving at a fraudulent website, a phishing form designed to steal credentials, or a malicious download. These final destinations are frequently rotated to evade detection.

Health-themed scams exploit consumer fears and vulnerabilities through emotionally persuasive narratives, fabricated expert authority, and pseudo-scientific claims. These campaigns promote unverified remedies, insurance "loopholes," and wellness products using false testimonials, conspiracy theories, manipulated medical data, and misleading urgency. Common tactics include impersonating medical professionals, claiming "suppressed" solutions, using newly created suspicious domains, and employing lead-generation funnels. Examples include scams related to sleep disorders, anti-snoring devices, "whistleblower doctor" respiratory remedies, health insurance "hacks," and weight loss supplements.

Financial scams often involve impersonating legitimate platforms such as Binance, TradingView, or Wise. These ads may offer bonuses, premium upgrades, or desktop application downloads, leading to fake sites designed to steal credentials or install malware. This pattern has been observed in Vietnam, Japan, Bangladesh, Thailand, Malaysia, New Zealand, and the Philippines, often utilizing near-identical infrastructure.

Another financial scam tactic involves creating fake "breaking news" stories featuring central banks, economists, or celebrities to induce urgent clicks. Campaigns linked to the Reserve Bank of Australia, Bank Negara Malaysia, and celebrity figures in Japan and Bangladesh have been identified. AI-themed investment scams, the third pattern, promise "AI-powered insights," "stock diagnostics," or automated strategies rather than direct profits.

While Australia sees more polished and convincing scams, often posing as breaking news or using familiar names, India experiences a higher volume of similar messages pushed through numerous fake accounts. Southeast Asian markets combine both approaches, with fake apps, investment offers, and impersonated brands appearing across multiple countries with minor adjustments. Localized strategies are also employed, such as using local languages and public figures in Bangladesh, real financial data in Singapore to legitimize fake tools, and low-cost offers in Indonesia to initiate conversations that quickly move to private messages.

Despite these regional variations, the underlying system remains interconnected, with the same fake apps, investment scam types, and even accounts appearing in multiple countries. Many campaigns are designed for cross-border operation or spill into new markets as they gain traction, indicating a cohesive and adaptive malvertising ecosystem.

malvertisingscamsapacsocial mediameta
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.