Taking down the IP2Scam tech support campaign

IP2Scam tech support campaigns use malvertising to push visitors to browser locker pages. The operators rotate infrastructure and impersonate brands to misdirect users, while researchers tracked the activity and coordinated takedown efforts with hosting providers. #IP2Scam #browlock #malvertising #BongaCash #Tomsguide #NewYorkPost #DigitalOcean #Choopa

Keypoints

  • The IP2Scam campaign targets visitors of adult sites and redirects them to fake warning pages via malicious ads.
  • The browser locker (“browlock”) is customized per browser/user agent to present slightly different templates for Windows, Mac, Chrome, and Firefox.
  • New servers are created and rotated continuously to sustain the malvertising campaigns.
  • Cloking domains impersonate brands (e.g., BongaCash, Tom’s Guide, New York Post) to filter traffic before redirecting to the browlock.
  • Researchers traced about 10 months of telemetry to map infrastructure and shared data with Digital Ocean and The Constant Company (Choopa).
  • A publicized mechanism exists (not disclosed here) to programmatically retrieve new browlock server IP addresses as they come.
  • Efforts emphasize disrupting lead generation flows to hinder the scammers, with cooperation from hosting providers rather than relying on arrests alone.

MITRE Techniques

  • [T1189] Drive-by Compromise – Target users to adult sites and redirect them to fake warning pages via malicious ads. “to target users to adult sites and redirect them to fake warning pages via malicious ads.”
  • [T1583] Acquire Infrastructure – New servers come up as needed and are pushed dynamically via ongoing malvertising campaigns. “New servers come up as needed and are pushed dynamically via ongoing malvertising campaigns.”
  • [T1036] Masquerading – The cloaking part consists of a decoy website named after a known brand whose purpose is to filter traffic and redirect if the user matches a certain set of criteria. “The cloaking part consists of a decoy website named after a known brand whose purpose is to filter traffic and redirect if the user matches a certain set of criteria.”

Indicators of Compromise

  • [Cloaking Domains] Decoy domains used to filter traffic and redirect to browlock – newsjump.xyz, newsmaven.xyz, and 17 more domains
  • [Browlock IPs by ASN and timestamp] Browlock infrastructure hosted on cloud providers – DigitalOcean, Choopa

Read more: https://blog.malwarebytes.com/threat-intelligence/2022/06/taking-down-the-ip2scam-tech-support-campaign/