They hired me to make them a website. I worked alongside an art director and a content creator. Everyday, the reoccurring question was, "what exactly do we do". I was disconnected from the sales staff and the marketing side, so I kept working on a basic WordPress site.
Six months in, we heard that the office was going to close. There was little to no warning, then a week later, we heard that the FCC raided the Florida home office for the CEO breaking tons of spam laws.
The overall structure of the company wasn't necessarily designed to keep people unaware of what they were doing. Instead, they had so many things that the company did, but most of the other "things" didnt make any money. When you boiled down the operations, you realized there was a small number of things that was hugely profitable (spam/toolbars), then a ton of other things that were nonsense and unprofitable.
I went for an interview at a startup, where the very charismatic CEO explained how their wonderful product helped website owners optimise their content based on their user's profiles. He forgot to mention that those profiles were built using all sorts of illegal and TOS-breaking practices to build display ads for gambling sites. I only found this out by accident, months after the (failed) interview, when talking about them with somebody at a meetup.
So I guess it's possible if the business has a specific strategy for doing it.
It might have just been that particular company at that time, but I've never worked with so many morally questionable people at one company. Never again.
He wasn't shocked to find that he personally had been writing an ad injector. He was shocked to find that the company he was working for made such software without his realizing it and that it derived most of its revenue from said software.
It's 50onRed, apparently. The article uses a font with Text Figures which makes '0's look like 'o's.
It's likely they weren't working on the actual ad injection itself, but rather the backend systems that select and count the ads. From that perspective it's just a matter of handling X requests per second, without it necessarily being clear where the traffic comes from.
When I worked at Adzerk, we'd be approached occasionally by companies doing this kind of garbage. They were always very good at disguising their actual traffic sources. Our sales team had to be very adept at asking the right questions to eliminate the shitty partners quickly.
Right out of school I worked at a company that builds deep packet inspection hardware and it seems like a dream job: good pay, smart people, interesting problems, reasonable schedule. Too bad about the product though.
Also I would strongly suspect that most traders of stolen goods (ad spots, in this case) would have a path for legitimately acquired merchandise as well, not only for plausible deniability but also because they sure would not mind paying their bills in a clean way, they just failed to resist the lure of the extra cash. With that in place, you'd have to actually work in the shady part to know about it, or have bird's eye numbers of the whole company where you might see that output does not match the legitimate input.