Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

AliGater Targets Outdated Windows Users

September 19, 2024
Reading Time: 2 mins read
in Alerts
AliGater Targets Outdated Windows Users

The “AliGater” malvertising campaign has emerged as a significant threat, specifically targeting users of outdated Windows systems, notably Windows 7 SP1 and 8.1, as well as older versions of Chrome in Europe. Researchers from Gen Digital have identified that this sophisticated platform exploits legitimate advertising networks, embedding harmful code within online ads to facilitate malware infections. This malvertising tactic poses challenges for both users and publishers, as infected advertisements can often evade detection.

The attack chain begins with malicious ads redirecting users to a domain named aligate.homes, where victims encounter a deceptive CAPTCHA loading a script called “captcha.js” from a dynamic shop domain. This script fingerprint the users by analyzing their system environment, such as architecture and browser version. It then delivers targeted exploits that take advantage of vulnerabilities in the V8 JavaScript engine (CVE-2023-2033) and Windows TrueType font parsing (CVE-2011-3402). This meticulous approach enables the attackers to tailor their exploits based on the specific weaknesses of the victim’s setup.

Once a user is compromised, the multi-stage payload deploys sophisticated techniques, including WebAssembly, XOR encryption, and shellcode injection, alongside process hollowing methods. The malware masquerades as legitimate Windows processes—such as “dllhost.exe” and “svchost.exe”—to evade detection while deploying the Lumma stealer, which is designed to harvest sensitive information from infected devices. AliGater also targets specific user agents, notably outdated versions of Chrome, thereby narrowing its focus on particularly vulnerable systems.

Interestingly, the infrastructure supporting AliGater displays characteristics reminiscent of the Magniber ransomware campaign, including similar targeting methods and syscall invocation techniques. This suggests a possible connection or shared codebase between the two threats, raising concerns about the potential for broader exploitation. As the AliGater campaign continues to evolve, it underscores the urgent need for users to update their operating systems and browsers to protect against sophisticated malware threats lurking in seemingly innocuous online ads.

Reference:
  • AliGater Malvertising Campaign Targets Outdated Windows Users in Europe
Tags: CAPTCHACHROMECyber AlertsCyber Alerts 2024Cyber threatsEuropeMalvertisingMalwareSeptember 2024Windows
ADVERTISEMENT

Related Posts

FreeDrain Phishing Steals Crypto Funds

FBI Warns Cybercriminals Exploit Routers

May 9, 2025
FreeDrain Phishing Steals Crypto Funds

X Scam Targets Crypto Users with Fake Ads

May 9, 2025
FreeDrain Phishing Steals Crypto Funds

FreeDrain Phishing Steals Crypto Funds

May 9, 2025
COLDRIVER Hackers Target Sensitive Data

COLDRIVER Hackers Target Sensitive Data

May 8, 2025
COLDRIVER Hackers Target Sensitive Data

Cisco Fixes Flaw in IOS Wireless Controller

May 8, 2025
COLDRIVER Hackers Target Sensitive Data

CoGUI Targets Consumer and Finance Brands

May 8, 2025

Latest Alerts

X Scam Targets Crypto Users with Fake Ads

FBI Warns Cybercriminals Exploit Routers

FreeDrain Phishing Steals Crypto Funds

CoGUI Targets Consumer and Finance Brands

COLDRIVER Hackers Target Sensitive Data

Cisco Fixes Flaw in IOS Wireless Controller

Subscribe to our newsletter

    Latest Incidents

    LockBit Ransomware Data Leaked After Hack

    Spanish Consumer Group Faces Cyberattack

    Education Giant Pearson Hit by Data Breach

    Masimo Cyberattack Disrupts Manufacturing

    Cyberattack Targets Tepotzotlán Facebook

    West Lothian Schools Hit by Ransomware

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial