A huge online fraud operation is hijacking WordPress sites to send out 1.4 billion ad requests per day


- Researchers found a huge ad fraud scheme called Scallyway
- The scheme monetizes pirated sites through a series of redirects
- At its peak, there were 1.4 billion daily requests
Cybersecurity researchers from HUMAN have spotted a major ad fraud operation that leverages people’s interest in pirated content to generate ad revenue from otherwise non monetizable content.
In an in-depth report, HUMAN explained pirated websites don’t host ads because they would “run afoul of most advertisers’ policies”. Instead, they are partnering with hundreds of website owners (scammers, basically) who deploy a set of four WordPress plugins on their assets.
These plugins are collectively named Scallywag, and they are designed to do a couple of things, but mostly to load as many ads as possible, and make sure people stick around until they fully render. There are a couple of tactics to slow visitors down, from the “please wait” button that turns to “download now”, to fake CAPTCHAs and other methods. The plugins are called Soralink (released in 2016), Yu Idea (2017), WPSafeLink (2020), and Droplink (2022).
Choking the operation
After rendering the ad, visitors are again redirected and allowed to download the pirated content they were looking for.
By the time HUMAN discovered the operation, it counted 407 domains and 1.4 billion fraudulent ad requests – per day. It seems the strength is in numbers, since the fraudsters even made YouTube video tutorials, coaching other people on how to join:
“These extensions lower the barrier to entry for a would-be threat actor who wants to monetize content that wouldn’t generally be monetizable with advertising; indeed, several threat actors have published videos to coach others on setting up their own schemes,” HUMAN said.
The researchers moved in to report and block Scallywag traffic, and claim to have largely succeeded. The traffic allegedly shrunk by 95%, although the operation is not entirely dead since threat actors rotated domains and moved to other monetization models.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via BleepingComputer
You might also like
Researchers found a huge ad fraud scheme called Scallyway The scheme monetizes pirated sites through a series of redirects At its peak, there were 1.4 billion daily requests Cybersecurity researchers from HUMAN have spotted a major ad fraud operation that leverages people’s interest in pirated content to generate ad revenue…
Recent Posts
- A huge online fraud operation is hijacking WordPress sites to send out 1.4 billion ad requests per day
- Microsoft’s Xbox app is now available on LG smart TVs
- Meta rolls out live translations to all Ray-Ban smart glasses users
- Ripple cryptocurrency software library hit by major security issue, wallets under threat
- Roku unveils two new battery-powered security cameras
Archives
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010