• For Enquiry
  • 847-868-9253
  • 847-868-9208
  • Home
  • Why Choose CIO Landing?
    • Our Team
    • Success Stories
    • ‘8 Things’ We Do Better
    • Partners & Certifications
    • Our Services
  • Industry Expertise
    • Manufacturing
    • Medical
    • Education
    • Financial Services
    • Non-Profit
    • Law Firms
  • IT Solutions
    • Co-Managed Service
    • Managed IT Services
    • IT Support
      • On Demand Services
      • Office Moves & Wiring
      • Security
    • Server Management
    • Backup & Disaster Recovery
    • Cloud Services
    • CIO & IT Consulting
    • Cybersecurity Services
    • VoIP
    • Managed Firewall
    • Microsoft 365
      • Microsoft 365 Plans
        • Small Business
        • Enterprise
        • Education
    • Hardware & Software Sales
    • Email & Spam Protection
  • Resources
    • Free Copy Of New Book
    • Blog
    • Newsletter
    • Video Tips
      • Video Tips Archive
    • Free Cloud Report
    • IT Buyers Guide
    • Cybersecurity Crisis Report
    • Network Audit
    • COVID 19 Resources
    • In The NEWS
    • Online Training
  • About Us
    • Our Mission
    • Leadership
    • Teams
    • Referral Program
    • Press Releases
      • CIO Landing: More Than Just an IT
      • Small businesses can have an IT department too
      • CIO Landing, Inc. has joined forces with Banc Certified Merchant Services (BCMS).
    • Affiliations
    • Careers
      • Job Descriptions
    • FAQs
    • Causes We Support
    • Privacy Policy
    • Terms & Conditions
  • Locations
    • Northfield, IL
    • Northbrook, IL
    • Chicago, IL
    • Miami, FL
  • Support
✕
Why Network Security Is More Important Than Ever
February 22, 2023
How To Get More Productivity Out Of Every Employee (And Make Them Happier About It)
February 23, 2023

AWS Warns Against Malvertising Targeting Users

February 23, 2023

Cybersecurity company Sentinel Labs has discovered a new malvertising campaign targeting AWS users. Sentinel Labs warns that cybercriminals have established a campaign on Google Ads programs that take users to a fake landing page to steal their credentials and other details.

What Is a Malvertising Campaign?
A malvertising campaign is a digital ad intended to inject malicious code when clicked. It is complex and challenging to carry out, as shown by the investigation carried out by Sentinel Labs on Jan. 30, 2023.

The malicious ad appears second in most search results after typing “aws” in the search bar, making it look credible. It avoided Google’s fraud detection systems by using redirections of its landing page.

“The ad itself goes to a hop domain, which is an actor-controlled blogger website,” says Tom Hegel, the senior threat researcher in Sentinel Labs.

Users land on a page designed to phish for their credentials. After submitting, visitors are redirected to the legitimate landing page of AWS. It is an effort to evade detection by the most cautious users and automated monitors.

Furthermore, the fake landing page asks victims to select if they are root or IAM users. That helps the cybercriminals categorize the value of the stolen data.

They use JavaScript code to take it further and disable controls like right clicks, keyboard shortcuts, and middle mouse button clicks. Researchers speculate that this was to discourage potential victims from navigating away from the landing page.

Actions Taken
According to the investigation, the attackers are probably Brazilian. CloudFlare received the report and promptly shut down the malicious account connected to the campaign. However, Google ads were still active during that time.

Criminals would try to leverage legitimate platforms to conduct their nefarious activities. It gives their campaign a fake veil of credibility. Who would think that an ad shown and sponsored by Google would be malicious?

Protecting Your Business Credentials 
Businesses need to have their team take training regarding cybersecurity and how to identify potential threats. You can never be too careful when on the internet, whether it is surfing, researching, or communicating with someone.

All it takes is one click for an attack to be successful. And that is what criminals count on, that single second you let your guard down. Do not give them that opportunity.

Share
50
taylor
taylor

Related posts

March 10, 2025

The Hidden Threat: How Gift Card Scams Are Targeting Businesses Like Yours


Read more
February 11, 2025

CIO Landing Named to CRN’s MSP 500 List for 2025—For the Third Year in a Row!


Read more
December 4, 2024

Unlocking the Power of Windows 11: Tips for Maximum Productivity


Read more
© 2025 All Rights Reserved | Powered by CIO Landing