HELLFIRE https://www.bleepingcomputer.com/news/security/scallywag-ad-fraud-operation-generated-14-billion-ad-requests-per-day/ A large-scale ad fraud operation called ‘Scallywag’ is monetizing pirating and URL shortening sites through specially crafted WordPress plugins that generate billions of daily fraudulent requests. Scallywag was uncovered by bot and fraud detection firm HUMAN, which mapped a network of 407 domains supporting the operation that peaked at 1.4 billion fraudulent ad requests per day. HUMAN’s efforts to block and report Scallywag traffic have resulted in its shrinking by 95%, although the threat actors have shown resilience by rotating domains and moving to other monetization models. … Scallywag is a fraud-as-a-service operation built around four WordPress plugins that help cybercriminals generate money from risky and low-quality sites. The WordPress plugins created by the operation are Soralink (released in 2016), Yu Idea (2017), WPSafeLink (2020), and Droplink (2022). … The redirection process takes the visitor through intermediary, ad-heavy pages that generate fraudulent impressions for the Scallywag operators, and end up on a page hosting the promised content (software or movie). The intermediary sites are WordPress sites running the Scallywag add-ons. Those handle the redirect logic, loading of ads, CAPTCHA, timer, and the cloaking mechanism, which shows a clean blog on ad platform checks. … FWIW… Regards
egeezer HELLFIRE I had noticed that whenever I used a phone number as search terms, a bunch of WordPress link results were returned that, without even following them, were fake clickbait.