{"id":5087,"date":"2024-08-29T15:41:02","date_gmt":"2024-08-29T20:41:02","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/brazilian-ad-fraud-network-camu-hits-2-billion-daily-bid-requests"},"modified":"2024-08-29T15:41:02","modified_gmt":"2024-08-29T20:41:02","slug":"brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/29\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests\/","title":{"rendered":"Brazilian Ad Fraud Network &#8216;Camu&#8217; Hits 2B+ Daily Bid Requests"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt182430de0fdafffb\/66d0d222edc9727536e70b9e\/Camo-Iophius-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Earlier this year, a piracy network was fraudulently serving more than 2 billion online advertisements every day.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Camu&#8221; (short for &#8220;camuflagen&#8221; in Portuguese), based out of Brazil, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/malware-for-ad-fraud-gets-more-sophisticated\" rel=\"noopener\">trafficks in ad fraud<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on a mass scale. At its peak earlier this year, it was processing around 2.5 billion bid requests daily across 132 domains. As HUMAN Security researchers describe in a new report, that equates to approximately the ad traffic generated by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.humansecurity.com\/learn\/blog\/satori-threat-intelligence-alert-camu-cashes-out-ads-on-piracy-content\" rel=\"noopener\">the entire city of Atlanta, Georgia<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">HUMAN researchers have thrown a wet blanket over Camu since discovering it back in December 2023. Though it&#8217;s still active, it&#8217;s processing a measly 100 million bid requests daily.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The scheme works thanks to an entirely simple cookie-based redirection mechanism, which sends its users the movies and television shows they&#8217;re looking for, but pesky investigators to decoy sites.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Camu's Two Faces\">Camu&#8217;s Two Faces<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Camu&#8217;s piracy websites offer a similar user experience to any other standard piracy or pornography sites. When a visitor arrives on the site and clicks on the content they wish to view, they&#8217;re redirected to a second domain hosting it, amid an onslaught of advertisements (so-called &#8220;cashout sites&#8221;).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many of these advertisements are from perfectly honest companies that surely wouldn&#8217;t want to be associated with illegal content, if they knew about it. To keep them in the dark, Camu employs a rudimentary mechanism for ensuring that only their target audience ends up on their cashout sites.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The actors in this operation are abusing a very important part of the Internet wherein a domain has the ability to load differently, depending on different parameters,&#8221; explains HUMAN&#8217;s director of fraud operations, Will Herbig. &#8220;If I go to a domain on my computer, as opposed to on my mobile phone, it might load the page differently, and that&#8217;s OK. However, Camu is taking that and they&#8217;re abusing it in a way that is really hard to detect.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When a visitor to a piracy site gets redirected to a cashout site, they&#8217;re assigned a token. The token installs a cookie on their browser, which in a sense &#8220;admits&#8221; them to the cashout site with their content, and the ads.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Should anyone unwanted \u2014 say, a security researcher or an employee of an advertiser \u2014 arrive at the cashout domain via any other means, they would not possess that cookie, and therefore not be admitted to the site. Instead, they&#8217;d be redirected to a different, bland but ultimately innocuous site of one kind or another.<\/span><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_left\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests.png\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests.png?w=640&#038;ssl=1\" loading=\"lazy\" alt title><\/p>\n<p class=\"ContentImage-Link\">Source: HUMAN Security<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To obscure the relationships between its malicious domains and the piracy sites that serve them, Camu manipulates the information that would otherwise be transferred during the redirection process. Not only does it &#8220;scrub&#8221; any information alluding to the referring site, but it also adds false referral information to the landing domain&#8217;s URL, giving the appearance that a visitor landed there from a reputable site or search engine.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"How Ad Exchanges Enable Fraud\">How Ad Exchanges Enable Fraud<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As Herbig is quick to point out, &#8220;Besides Camu and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/shady-merry-go-round-ad-fraud-network-orgs-hemorrhaging-cash\" rel=\"noopener\">Merry-Go-Round,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> we&#8217;re tracking seven other operations that have a smaller but similar magnitude that are doing this type of thing.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The business has always been made easy by the degree to which online ad buying is automated, with middleman exchanges programmatically trafficking inventory between legitimate advertisers and sometimes less than legitimate buyers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Many companies only serve ads with companies that they have direct relationships with. That&#8217;s not completely foolproof, but that tends to be a safer way to do it.&#8221; Herbig explains. However, he adds, &#8220;the programmatic ecosystem is enormous. There are tens of thousands of publisher networks out there. Many of them are reputable, [however] there are threat actors that are trying to exploit this.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To cover for the problem introduced by middlemen ad exchanges, some advertisers turn to middlemen verification services. Unfortunately, some of these services have been shown to be <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/adalytics.io\/blog\/ai-brand-safety\" rel=\"noopener\">ineffective at best<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Ad fraud continues to be <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/ad-fraud-the-multibillion-dollar-cybercrime-cisos-might-overlook\" rel=\"noopener\">&#8216;highest ever&#8217; year after year<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, both in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/online-ad-fraud-exposed-advertisers-losing-6-3-billion-to-10-billion-per-year\" rel=\"noopener\">dollar amount<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and percentage of ad impressions,&#8221; laments independent ad fraud researcher Dr. Augustine Fou. &#8220;We have a few, occasional cases like this one that expose a tiny, tiny, but representative example of ad dollars going to the wrong places, like piracy sites. But piracy sites pale in comparison to the other horrific places ads have been shown to go to.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/brazilian-ad-fraud-network-camu-hits-2-billion-daily-bid-requests\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Earlier this year, a piracy network was fraudulently serving more<\/p>\n","protected":false},"author":12,"featured_media":5088,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/brazilian-ad-fraud-network-camu-hits-2b-daily-bid-requests-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5087"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5087\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5088"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}