A deeper look by Cisco Systems into the cyberattack that infected Yahoo users with malware appears to show a link between the attack and a suspicious affiliate traffic-pushing scheme with roots in Ukraine.
Yahoo said on Sunday that European users were served malicious advertisements, or ?malvertisements,? between Dec. 31 and last Saturday. If clicked, the advertisements directed users to websites that tried to install malicious software.
Cisco discovered that the malicious websites victims landed on are linked to hundreds of others that have been used in ongoing cyberattacks, said Jaeson Schultz, a threat research engineer.
Schultz looked at domains hosted within a large IP block that researchers observed Yahoo victims were redirected to, finding 393 others that matched a pattern.