Security Experts Warn Against Fraudulent 'Java Update' Popup on Adult Sites

Security Experts Warn Against Fraudulent 'Java Update' Popup on Adult Sites

LOS ANGELES — Two months after warning of a surge in malvertising fraud targeting adult websites, internet security experts have determined that the bad actors behind it have switched tactics from “exploit kit delivery” to “social engineering” via a fake Java update screen.

As XBIZ reported back in September, the criminal modality of “malvertising,” where bad actors sneak malicious code into supposedly legitimate banner ads, made a comeback this year as people spend more time online — and on adult sites.

Security firm Malwarebytes explained the initial stage of this campaign — which they dubbed “Malsmoke” — as “ads [that] redirect visitors to sites that serve malicious code.”

“When viewed with Internet Explorer or Adobe Flash, the code can exploit critical vulnerabilities in unpatched versions of Internet Explorer,” Malwarebytes initially warned.

Today, Malwarebytes announced that “starting mid-October, the threat actors behind ‘Malsmoke’ appear to have phased out the exploit kit delivery chains in favor of a social engineering scheme instead. The new campaign is tricking visitors to adult websites with a fake Java update.”

This change is significant, according to the security firm, because “it drastically increases the target audience, no longer limiting it to Internet Explorer users running outdated software.”

One of the largest adult sites targeted by the malvertising hackers, according to Malwarebytes, is xHamster.

To read an elaborate explanation of this latest modality in online fraud, visit Malwarebytes.

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Ofcom: Age Assurance Going Live Across 'Thousands' of Porn Sites

U.K. communications regulator Ofcom said in a statement Thursday that providers of online pornography are implementing age assurance across “thousands of sites” accessible in the U.K., in response to Ofcom’s Online Safety Act (OSA) enforcement program.

ASGMax Debuts 'Roleplay' AI Chat Feature

Alpha Studio Group (ASG) has introduced the ASGmax Roleplay AI chat feature.

XBIZ Miami's Host Hotel Sold Out, General Registration Now Open

Guest rooms at XBIZ Miami’s exclusive conference venue, Nautilus Sonesta Miami Beach hotel in South Beach, are now completely sold out.

Adult Industry Educational, Networking Platform 'Imperfectly You' Launches

Imperfectly You, an educational and networking platform for adult industry workers, has officially launched.

Segpay to Launch News Network for High-Risk Merchants

Segpay has announced that it will launch the Segpay News Network (SNN) on April 15.

Age Verification Watch: Patching the Holes

This roundup provides an update on the latest news and developments on the age verification front as it impacts the adult industry.

Pineapple Support to Host Autism Spectrum Support Group

Pineapple Support is hosting a free online support group for performers and creators who are, or suspect they may be, on the autism spectrum.

ImLive Launches Revamped Member Loyalty Program

Cam platform ImLive has revamped its member loyalty program.

GoFundMe Set Up for Danny Ferretti's Medical Expenses

A GoFundMe campaign has been set up for Fangear founder Danny Ferretti, who requires extensive lung surgery.

Byborg Acquires Cuties AI

Byborg Enterprises has acquired adult artificial intelligence startup Cuties AI.

Show More