I'm about 10 weeks into a "user experience" experiment with #vextrio - starting with compromised sites and accepting all push notifications. I posted several of those already on the team account @InfobloxThreatIntel
VexTrio User Experience 5/N
Fake news is another consequences of VexTrio and similar actors. Qurium connected VexTrio to Russian disinformation in October.
In my sacrificial phone I've run into numerous "news" sites that are a complex mix of clickbait, ads, and disinformation. I think I have a pretty good BS detector, but I've found myself on fairly complex fact checking missions since I started this experience.
The other problem is once you visit a compromised website you are immediately thrown into a world where even the major news feed, say from Google, is filled with trash that wasn't there before. It's easy to see how people's beliefs can be manipulated simply by making the wrong click at the wrong time.
Most of the fake news or alarmist headlines I've seen came after visiting the initial infected website… meaning,
* I went to a compromised site,
* Was asked to accept push notifications,
* was redirected to something like a "your machine is infected" scareware,
* Had a polluted new feed and follow on push notifications with disinformation
I have had a few cases where the compromised site redirected immediately to a "news" site. These are filled with undated articles that can be difficult to fact check. Here's a few images from a recent one.
* Did Putin say he couldn't win the war? I doubt it.
* Is the US going to cancel the $20 and $50 bills. Nope. That was easy to check.
#dns #infoblox #threatintel #cybercrime #fakenews #cybersecurity #adtech #adware #infosec