
This is to keep you in the loop on something related to the Ad Server. We were contacted by the FBI this morning. Our ad server is on a list of targets by a known group of hackers. The explanation from the FBI is below: "Here's some background information that brought the FBI to the ARRL: Since May, 2020 the FBI has been investigating the Greenflash Sundown Exploit Kit and malvertising campaign named Tag Barnakle. Tag Barnakle is the naming convention given by the security firm Confiant for actors exploiting advertisement servers in order to facilitate the distribution of malware. According to Confiant, Tag Barnakle takes advantage of vulnerable advertisement servers in order to allow the actors to hijack legitimate advertisement traffic, and divert it to PropellerAds. The FBI has identified the advertising server at domain ads.arrl.org as historically being compromised by Tag Barnakle actors. Open source research for the domain ads.arrl.org revealed it was historically associated with the domain avacaelum.com. This domain is known to have been used by Tag Barnakle actors." We have been successful in creating an environment that is capable of responding to attacks and neutralizing them so that they no longer affect members. We have not advertised or shared our capability as we do not want the hackers to build an exploit that goes around what we've built. Another interesting note: we are redeploying the server that previously ran the ad server. When we returned that servers access to the Internet, within minutes it came under attack. We are now logging thousands of attempted login hacks on that server. Once we change the IP address, that will no longer be an issue but it is clear that the hackers want to force their way back into that server. It is also worth noting that this has been going on for years, not months. I am guessing that only recently their efforts to push their PropellerAds links have become more aggressive making their presence more noticeable to members. Those are the headlines. If you have any specific questions, please let me know.