Adform's Ad Script Compromised to Steal Cryptocurrency via Clipboard Hijack
Adform's advertising scripts were compromised in a supply-chain attack that hijacks clipboard cryptocurrency addresses to redirect funds to attackers.
Why it matters
Supply-chain compromises involving online advertising platforms can silently redirect cryptocurrency transactions, increasing the risk of financial theft without direct user interaction.
SOC impact
Monitor network traffic and endpoint clipboard activity for signs of unauthorized script injections or clipboard manipulation. Identify affected systems running Adform scripts and investigate unusual cryptocurrency transactions linked to these websites.
Recommended actions
- Identify assets running Adform advertising scripts
- Monitor clipboard activity on endpoints for unauthorized modifications
- Analyze network telemetry for suspicious script downloads
- Review logs for unusual cryptocurrency address changes
- Investigate anomalous outbound connections related to Adform scripts
Executive Summary
Adform, a prominent online advertising platform, experienced a supply-chain attack where malicious actors tampered with their ad scripts to replace cryptocurrency wallet addresses copied to users’ clipboards with attacker-controlled addresses. This technique redirects cryptocurrency transfers to unauthorized wallets, potentially resulting in financial loss for users interacting with websites embedding these compromised ads.
For security operations, this incident highlights the need to inspect not only direct system vulnerabilities but also third-party components like advertising scripts that have wide-reaching implications. Continuous monitoring for script integrity and clipboard manipulation is critical to detect and respond to such attacks that operate quietly within trusted ecosystems.
SOC Impact
Monitor network traffic and endpoint clipboard activity for signs of unauthorized script injections or clipboard manipulation. Identify affected systems running Adform scripts and investigate unusual cryptocurrency transactions linked to these websites.
Clipboard and Script Injection Monitoring
- Identify assets running Adform advertising scripts
- Monitor clipboard activity on endpoints for unauthorized modifications
- Analyze network telemetry for suspicious script downloads
- Review logs for unusual cryptocurrency address changes
- Investigate anomalous outbound connections related to Adform scripts
Why It Matters
Supply-chain compromises involving online advertising platforms can silently redirect cryptocurrency transactions, increasing the risk of financial theft without direct user interaction.