Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign

A threat actor identified as D-Shortiez has been conducting a malvertising campaign exploiting a WebKit browser feature. This campaign targets iOS Safari users, redirecting them to fraudulent pages, utilizing a back-button hijack that prevents users from…

A threat actor identified as D-Shortiez has been conducting a malvertising campaign exploiting a WebKit browser feature. This campaign targets iOS Safari users, redirecting them to fraudulent pages, utilizing a back-button hijack that prevents users from leaving the compromised site.

The malvertising strategy employed by D-Shortiez involves forced redirects, a common tactic in online ad fraud. However, the introduction of a back-button hijack distinguishes this campaign, rendering users unable to navigate away from malicious destinations.

Ad platforms and browser developers have generally enhanced their defenses against such attacks, but malvertisers continue to leverage small technical advantages. These may include browser behavior quirks, ad platform filtering gaps, or script execution edge cases, cumulatively enhancing the campaign's effectiveness.

Confiant analysts have identified D-Shortiez as a key actor in these forced redirect campaigns, which guide victims through malicious click-chains. The group's payload begins with standard fingerprinting and tracking functions. A notable feature is a nested try/catch block, beginning at line 211, which handles the forced redirection by simultaneously initiating multiple redirect attempts.

A threat actor identified as D-Shortiez has been conducting a malvertising campaign exploiting a WebKit browser feature.
Derek Vaughn · Thehackingpost

The campaign has delivered over 300 million malicious ad impressions in the past six months, primarily targeting users in the United States, Canada, and parts of Europe. iOS users are the primary focus.

D-Shortiez exploits the browser's popstate event to prevent navigation away from scam pages on Safari. The payload uses window.top.history.pushState() to insert a fake entry into the browser’s history stack. An onpopstate event handler then redirects any back-button press to the scam URL.

While the script behaves normally in most browsers, it effectively traps users on iOS Safari, preventing them from leaving the fraudulent pages. Apple has addressed this vulnerability through a Safari security update identified as HT213600, released on January 23, 2023.

Advertisement

iOS and Safari users should promptly install the security update HT213600 to mitigate this vulnerability. Security and ad operations teams are advised to audit ad supply chains for redirect-based payloads and block known D-Shortiez domains at the DNS and network levels. These domains span several top-level domains, including .shop , .site , .homes , .beauty , .skin , .boats , and .cyou .

For further information, please refer to the detailed analysis on the Confiant blog .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories