Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign
A threat actor identified as D-Shortiez has been conducting a malvertising campaign exploiting a WebKit browser feature. This campaign targets iOS Safari users, redirecting them to fraudulent pages, utilizing a back-button hijack that prevents users from…
A threat actor identified as D-Shortiez has been conducting a malvertising campaign exploiting a WebKit browser feature. This campaign targets iOS Safari users, redirecting them to fraudulent pages, utilizing a back-button hijack that prevents users from leaving the compromised site.
The malvertising strategy employed by D-Shortiez involves forced redirects, a common tactic in online ad fraud. However, the introduction of a back-button hijack distinguishes this campaign, rendering users unable to navigate away from malicious destinations.
Ad platforms and browser developers have generally enhanced their defenses against such attacks, but malvertisers continue to leverage small technical advantages. These may include browser behavior quirks, ad platform filtering gaps, or script execution edge cases, cumulatively enhancing the campaign's effectiveness.
Confiant analysts have identified D-Shortiez as a key actor in these forced redirect campaigns, which guide victims through malicious click-chains. The group's payload begins with standard fingerprinting and tracking functions. A notable feature is a nested try/catch block, beginning at line 211, which handles the forced redirection by simultaneously initiating multiple redirect attempts.
A threat actor identified as D-Shortiez has been conducting a malvertising campaign exploiting a WebKit browser feature.
The campaign has delivered over 300 million malicious ad impressions in the past six months, primarily targeting users in the United States, Canada, and parts of Europe. iOS users are the primary focus.
D-Shortiez exploits the browser's popstate event to prevent navigation away from scam pages on Safari. The payload uses window.top.history.pushState() to insert a fake entry into the browser’s history stack. An onpopstate event handler then redirects any back-button press to the scam URL.
While the script behaves normally in most browsers, it effectively traps users on iOS Safari, preventing them from leaving the fraudulent pages. Apple has addressed this vulnerability through a Safari security update identified as HT213600, released on January 23, 2023.
iOS and Safari users should promptly install the security update HT213600 to mitigate this vulnerability. Security and ad operations teams are advised to audit ad supply chains for redirect-based payloads and block known D-Shortiez domains at the DNS and network levels. These domains span several top-level domains, including .shop , .site , .homes , .beauty , .skin , .boats , and .cyou .
For further information, please refer to the detailed analysis on the Confiant blog .
Based on reporting by Cyber Security News.
