From The ad blocker that injects ads | Imperva:

 

 

Imperva Research Labs has uncovered a new ad injection campaign by an ad blocker extension available on both Chrome and Opera browsers called AllBlock.

 

The campaign was targeting users of some of the largest websites, using its elevated installation privileges at the browser level to inject Javascript into the user’s application experience. 

 

How it works

 

AllBlock directs the browser to load specific ad content pop-ups and sidebar ads from sites and content providers where the hacker is paid per click. The user is forced to click on these ads to make them disappear from their screen, unknowingly contributing money to the cyber criminals’ advertising campaign.

 

This ad injection campaign is hard to detect because the developer has included code to monitor and understand when debugging tools are being used. It then tries to hide its activity by clearing the debug log console output every 100ms, making it appear as if there is no activity.

 

For more details, you can read this technical blog post.

 

Imperva Research Labs believes it has not found the origin of the attack, and that there is a larger campaign taking place that may utilise different delivery methods and more extensions.