Gumtree serving up exploit kit to users
Jerome Segura, a security researcher at Malwarebytes Labs, has announced that the company found Australia's most popular classifieds site, Gumtree.com.au, serving the Angler Exploit Kit to visitors.
The site is Australia's eleventh most popular website. SimilarWeb estimates the website attracts nearly 50 million views a month.
Detailing an attack on a Sydney legal firm, Segura said the hackers set up a subdomain in the company's infrastructure which the attackers used to host the exploit kit. It was from there that they displayed both legitimate and malicious advertisements to confused advertising networks.