{"id":3812,"date":"2024-05-30T08:00:00","date_gmt":"2024-05-30T13:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/shady-merry-go-round-ad-fraud-network-orgs-hemorrhaging-cash"},"modified":"2024-05-30T08:00:00","modified_gmt":"2024-05-30T13:00:00","slug":"shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/30\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash\/","title":{"rendered":"Shady &#8216;Merry-Go-Round&#8217; Ad Fraud Network Leaves Orgs Hemorrhaging Cash"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltcb7167b8db21fe2d\/66578302367a2261091da261\/carousel-geogphotos-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers have uncovered two ad fraud rings redirecting hundreds of millions of online ads daily to pop-up windows on less-than-reputable websites.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"http:\/\/ https:\/\/www.humansecurity.com\/learn\/blog\/satori-threat-intelligence-alert-merry-go-round-conceals-ads-from-users-and-brands\" rel=\"noopener\">report released on May 30<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Human Security collectively named the rings &#8220;Merry-Go-Round,&#8221; after the characteristic way they cycle around a small number of domains serving large volumes of ads.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At its peak, Merry-Go-Round&#8217;s advertising ouroboros was feeding unwitting Internet users 782 million ads every day. Today, the ongoing operation serves a still-significant 200 million ads per day, on average.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It&#8217;s actually pretty crazy, the scale and magnitude of this operation,&#8221; says Will Gerbig, director of fraud operations at Human Security. &#8220;To contextualize this: A typical user sees something like 5,000 ads per day. So that 780 million is [equivalent to] 150,000 people&#8217;s ad intake, on TV, their phone, the newspaper \u2014 for their entire day. That&#8217;s, what, the population of Jersey City?&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Swindling Companies for Their Ad Dollars\">Swindling Companies for Their Ad Dollars<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Internet users won&#8217;t be too chuffed by it, but companies have been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/online-ad-fraud-exposed-advertisers-losing-6-3-billion-to-10-billion-per-year\" rel=\"noopener\">losing gobs of money to ad fraud<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for as long as online ads have existed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The obscure marketplace for ad placement (where middlemen exchanges \u2014 so-called &#8220;ad tech&#8221; companies \u2014 programmatically facilitate the buying and selling of online real estate) creates distance between buyer and seller, which fraudsters have long used to their advantage. Bad guys have been known to run ads on staged websites, serve them to bots programmed to simulate real engagement, and more, raking in revenue while their suppliers are none the wiser.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Compared with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/russian-hackers-run-record-breaking-online-ad-fraud-operation\" rel=\"noopener\">standard-setters like Methbot<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Merry-Go-Round is rather simple, but still effective.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It begins with an overlay, laid invisibly atop a pirating, pornography, or other kind of website that most advertisers wouldn&#8217;t want to be associated with. Any click redirects the site&#8217;s visitor to a new browser window with the content they&#8217;re expecting, while the original window redirects to a Merry-Go-Round domain.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though unwilling to comment on attribution, Gerbig does note that &#8220;the websites would have to knowingly run this code to generate this kind of [scheme]. Most likely, there is some kind of revenue-generating agreement between the two parties.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While an Internet user goes about their idle day, the out-of-focus Merry-Go-Round window starts to cycle between domains. Every 60 seconds it loads a new one, each cramming in a boatload of ads. Shorter cycles, Gerbig notes, would be more likely to raise red flags. The process continues ad infinitum until the user notices and closes out the window.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It scales very quickly, because there are 100 ads on a page, and users are often distracted, so they&#8217;re going to be leaving these things open for some time,&#8221; Gerbig notes.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Beating Ad Fraud, the Easy Way\">Beating Ad Fraud, the Easy Way<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Merry-Go-Round is most sophisticated in its anti-detection techniques, using a number of measures to keep away advertisers, cyber analysts, and others who would stand in its way.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For example, the first pop-under domain served to users includes a bit of HTML code instructing search engines not to crawl the site, and not to investigate any links contained within it. Another bit of JavaScript code resets the referrer information typically tracked by online ads in order to obscure the relationships between different Merry-Go-Round domains, as well as their relationship with the websites that triggered the cycle in the first place.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Merry-Go-Round&#8217;s best trick is &#8220;cloaking,&#8221; a tactic common among ad fraudsters. If, say, a suspicious advertiser visits one of its domains directly, they&#8217;ll be presented with a simple, inoffensive site. Only if they come upon the domain via redirection will they see it in its true form.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Detecting and shutting down operations like Merry-Go-Round is difficult. Luckily for advertisers, there&#8217;s an easy way to avoid throwing your marketing budget down the toilet: Don&#8217;t outsource the work of ad placement to exchanges.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;One big thing that you can do is: Know who you&#8217;re buying inventory from,&#8221; Gerbig says. &#8220;The closer you are to your partners \u2014 the less transacting of inventory there is \u2014 the more likely it is you can avoid these [scams].&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/shady-merry-go-round-ad-fraud-network-orgs-hemorrhaging-cash\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers have uncovered two ad fraud rings redirecting hundreds of<\/p>\n","protected":false},"author":12,"featured_media":3813,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3812","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?fit=2560%2C1707&ssl=1",2560,1707,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?fit=2048%2C1365&ssl=1",2048,1365,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/shady-merry-go-round-ad-fraud-network-leaves-orgs-hemorrhaging-cash-scaled.jpg?fit=2560%2C1707&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3812"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3812\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3813"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}