drahardja, to ai
@drahardja@sfba.social avatar

New SEO just dropped yo

“Google's new AI search results promotes sites pushing malware, scams”

#ai #scam #spam #malvertising #google

https://www.bleepingcomputer.com/news/google/googles-new-ai-search-results-promotes-sites-pushing-malware-scams/

th3_protoCOL, to random

WinSCP is a popular target for malware campaign abusing google ads. Here's one from this morning:

  1. Google search for winscp
  2. Click the first link, user redirection
    ➡️​ winscp-eng[.]org
    ➡️​ winscp-static-746341.c.cdn77[.]org
  3. Button click, malware download
    ➡️​ https[:]//parsecworks[.]org/us/downloads/WinSCP-6.1.2-Setup.exe

https://www.virustotal.com/gui/file/b503e810b31151f8d79bc0db2b46daddc53f27a2fd741c30355726892591e5b3/detection

#IOCs #malvertising #malware

VirusTotal submission report with a detection ratio of 1/63
Fake WinSCP site used to distribute malware

th3_protoCOL, to random

#malvertising themed around the gaming app "parsec"

Initial fake site: parsecus[.]net

Malware downloaded from: parsecworks[.]com

Digitally signed malware "parsec-windows.exe"

Both the distribution site and download url are hosted on 93.190.143.252

Google displaying malware ads above the true website for parsec
Screenshot of virus total, 3/63 vendors are detecting the file
Malware with a digital signature from SSL.com, signed 2 days prior on the 19th

briankrebs,

@th3_protoCOL Outstanding! Thank you. Mind if I reference these in a story?

th3_protoCOL,

@briankrebs of course! Looking forward to reading about it :)

cybersecboardrm, to Cybersecurity
jeromesegura, to random

Unknown stealer distributed via #Malvertising

C2: webvideoshareonline[.]com/bitrix/main.php

Sandbox with PCAP:
https://tria.ge/231219-3ne2xahbar/behavioral1

cc @da_667

avoidthehack, to wordpress

#WordPress hosting service Kinsta targeted by #Google phishing ads

Threat actors using Google Ads to lure people to fake Kinsta pages in an effort to steal hosting credentials. Be careful of where you click, even on "trusted" pages like Google search results.

Generally, it's best to avoid clicking on sites in the sponsored results of Google (or any search engine, really).

Using an adblocker prevents this section from loading in most cases.

#cybersecurity #phishing #security #googleads #malvertising

https://www.bleepingcomputer.com/news/security/wordpress-hosting-service-kinsta-targeted-by-google-phishing-ads/

funes, to infosec

A couple weeks back we noticed an uptick of incidents from trojanized Advanced IP Installer's delivered due to #malvertising. We tied it back to a group who were formerly a #darkside #ransomware affiliate according to Mandiant.

You may remember articles circulating about Bing's AI providing malvertising links. This is from the same campaign.

#infosec #malware #ioc #detectionengineering #threatintel #threathunting

https://www.connectwise.com/blog/cybersecurity/former-darkside-ransomware-affiliate-distributing-trojanized-installers-via-malvertising

funes,

Please, if you're a #sysadmin or otherwise work a support role, keep a repository of verified versions of tools you regularly use. Do not make "I just search Google and download it every time I need it" a part of your process.

jernej__s,

@funes At home I've got a huge download directory dating back to 2000, which has saved my ass several times.
At work I keep a much more organised repository of stuff I downloaded.

th3_protoCOL, to random

How can anyone reasonably expect a user to detect google ad abuse without visiting the malicious site?

Here's an example of a malicious google ad spoofing anydesk today.

This one redirects users to https[:]//anyowpdesk[.]com before downloading .msi malware:
https://www.virustotal.com/gui/file/9d85ae9e45556067d0b833144e7d9935936a3a3098fe65fc198409083a3a33a6/relations

#malvertising #malware #IOCs

Fake AnyDesk website

avoidthehack, to Cybersecurity

Associated Press, ESPN, CBS among top sites serving fake #virus alerts

Malvertising on top news sites.

Connected with threat actor "ScamClub." A large portion of this campaign targets mobile users.

-Insert my spiel about using an adblocker- Ads can be blocked in browsers, on devices, and on networks.

#malware #cybersecurity #infosec #security #malvertising

https://www.malwarebytes.com/blog/threat-intelligence/2023/11/associated-press-espn-cbs-among-top-sites-serving-fake-virus-alerts

avoidthehack,

@avoidthehack For recommendations on blocking ads (including domains known to serve trackers and #malware), I spell it out here:

#privacy #security #adblock #adblocker

https://avoidthehack.com/how-to-block-ads

MisuseCase, to security
@MisuseCase@twit.social avatar

Hey @leo glad to hear in the latest episode of :steve: (Episode 949) that is not just a way of reducing annoyance but also a feature because of the proliferation of .

I say all the time on here that using an is a way of protecting yourself because ad delivery platforms are a huge vector for malware and . This would be largely fixable if the owners of these platforms cared, but they don’t.

techygeek, to Cybersecurity
jeromesegura, to random

The KeePass #malvertising is back on (from the same advertiser as previously).

New domain: keeqass[.]com
New malware C2: 11234jkhfkujhs[.]xyz

cc @dangoodin

image/png
image/png

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 👀 Tracking Unauthorized Access to 's Support System
➝ 🔓 🇯🇵 discloses impacting customers in 149 countries
➝ 🔓 🧬 Hacker leaks millions more user records on forum
➝ 🔓 🇨🇳 D-Link confirms data breach after employee attack
➝ 🔓 💰 Fined $13.5 Million Over 2017 Data Breach
➝ 🇺🇦 🧹 Ukrainian activists hack Trigona gang, wipe servers
➝ 🇺🇸 🇰🇵 FBI: Thousands of Remote IT Workers Sent Wages to to Help Fund Weapons Program
➝ 🇮🇳 ☁️ targets , tech support in nationwide crackdown
➝ 🇵🇸 🇮🇷 -linked app offers window into cyber infrastructure, possible links to Iran
➝ 👮🏻‍♂️ 🥷🏻 Police seize leak site
➝ 🇰🇵 North Korean Hackers Exploiting Recent Vulnerability
➝ 🇨🇳 🇷🇺 replaces as top
➝ 🇺🇦 📡 CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks
➝ 🇫🇷 🇪🇸 frees the two biggest Spanish hackers
➝ 🇺🇸 ⚓️ Ex-Navy IT head gets 5 years for selling people’s data on
➝ 🇨🇭 🗳️ ’s e-voting system has predictable implementation blunder
➝ 🔓 🏭 Critical Vulnerabilities Expose ​​ HMIs to Attacks
➝ 🔓 🏭 Industrial Router Possibly Exploited in Attacks
➝ 🦠 🇻🇳 Fake job offers on push malware
➝ 🦠 Google-hosted leads to fake site that looks genuine
➝ 🦠 💬 still a hotbed of activity — Now APTs join the fun
➝ 🦠 🕵🏻‍♂️ SpyNote: Beware of This Android that Records Audio and Phone Calls
➝ 🛍️ 🦠 will now scan sideloaded apps for malware at install time
➝ 💬 🔐 on the way, but as usual, for Android first
➝ 🇷🇺 🗂️ Pro-Russian Hackers Exploiting Recent Vulnerability in New Campaign
➝ 🗓️ ❌ Signal Pours Cold Water on Zero-Day Exploit Rumors
➝ 🔓 💥 warns of new XE actively exploited in attacks

📚 This week's recommended reading is: "RTFM: Red Team Field Manual v2" by Ben Clark and Nicholas Downer

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-422023

jbzfn, to infosec
@jbzfn@mastodon.social avatar

🔎 Google-hosted malvertising leads to fake Keepass site that looks genuine
➥Ars Technica

「 There’s no surefire way to detect either malicious Google ads or punycode-encoded URLs. Posting ķeepass[.]info into all five major browsers leads to the imposter site. When in doubt, people can open a new browser tab and manually type the URL, but that’s not always feasible when they’re long 」

https://arstechnica.com/security/2023/10/google-hosted-malvertising-leads-to-fake-keepass-site-that-looks-genuine/

#Infosec #GoogleAds #Malvertising #Punycode

itnewsbot, to security

Google-hosted malvertising leads to fake Keepass site that looks genuine - Enlarge (credit: Miragec/Getty Images)

Google has been caught ... - https://arstechnica.com/?p=1977141 #malvertising #security #punycode #malware #biz#google

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines