GeoEdge security researcher Moriya Pedael is presenting "LANJack: Turning Ads into IoT Recon Tools" on Wednesday, August 5 at 10:15 a.m. in Oceanside D, Level 2.
LANJack is a malvertising campaign GeoEdge's Security Research Lab disclosed on December 22, 2025 that weaponizes online ads to reconnoiter your local network. The core technique is DNS rebinding, which lets a malicious ad-served site bypass browser network isolation by re-resolving its domain to internal or local IP addresses.
From there the attacker can probe and interact with devices normally unreachable from the public internet: routers, IP cameras, and other IoT gear.
Unlike typical malvertising that just redirects to scam or phishing pages, LANJack runs an active attack directly in the browser, delivered through legitimate, branded programmatic ads with no malware install and no user action beyond being served the ad.
GeoEdge described it as the first known large-scale DNS-rebinding attack delivered silently through programmatic advertising.
GeoEdge has history here, having previously exposed the first ad-based cyberattack aimed specifically at home-network IoT devices back in 2021. LANJack is the evolution of that threat model, and it should worry anyone thinking about ad-tech security, DNS rebinding defenses, or IoT exposure on home and enterprise networks.
Anyone here running DNS rebinding protection at the resolver level?
submitted by /u/_cybersecurity_ to r/pwnhub
[link] [comments]
Source: r/pwnhub · by /u/_cybersecurity_