Skip to content
  Sunday 22 June 2025
  • Home
  • Attack
  • Malware
  • Cloud
  • Data
  • Technology
  • World of tech
Trending
August 17, 2023New LABRAT Campaign Exploits GitLab Flaw for Cryptojacking and Proxyjacking Activities March 25, 2025Hackers Use .NET MAUI to Target Indian and Chinese Users with Fake Banking, Social Apps October 1, 2024AI-Powered Rhadamanthys Stealer Targets Crypto Wallets with Image Recognition February 27, 2024HSCC Issues Cyber ‘Call to Action’ Plan for Health Sector June 28, 2023A.I. is not all hype. It’s the ‘fourth industrial revolution playing out,’ says Wedbush’s Dan Ives October 18, 2024Webinar on Building a Strong Data Security Posture June 4, 2024Elon Musk ordered Nvidia to ship thousands of AI chips reserved for Tesla to X and xAI March 1, 2024Stages of LockBit Grief: Anger, Denial, Faking Resurrection? August 15, 2023Gigabud RAT Android Banking Malware Targets Institutions Across Countries March 11, 2025HHS Investigators Get New Mission Under Trump: Root Out DEI
  • Home
  • Attack
  • Malware
  • Cloud
  • Data
  • Technology
  • World of tech
  Attack  New Malvertising Campaign Distributing Trojanized IT Tools via Google and Bing Search Ads
Attack

New Malvertising Campaign Distributing Trojanized IT Tools via Google and Bing Search Ads

adminadmin—July 27, 20230
FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail


Jul 27, 2023THNMalvertising / Software Security

Malvertising Campaign

A new malvertising campaign has been observed leveraging ads on Google Search and Bing to target users seeking IT tools like AnyDesk, Cisco AnyConnect VPN, and WinSCP, and trick them into downloading trojanized installers with an aim to breach enterprise networks and likely carry out future ransomware attacks.

Dubbed Nitrogen, the “opportunistic” activity is designed to deploy second-stage attack tools such as Cobalt Strike, Sophos said in a Wednesday analysis.

Nitrogen was first documented by eSentire in June 2023, detailing an infection chain that redirects users to compromised WordPress sites hosting malicious ISO image files that ultimately culminate in the delivery of Python scripts and Cobalt Strike Beacons onto the targeted system.

Then earlier this month, Trend Micro uncovered a similar attack sequence in which a fraudulent WinSCP application functioned as a stepping stone for a BlackCat ransomware attack.

“Throughout the infection chain, the threat actors use uncommon export forwarding and DLL preloading techniques to mask their malicious activity and hinder analysis,” Sophos researchers Gabor Szappanos, Morgan Demboski, and Benjamin Sollman said.

UPCOMING WEBINAR

More stories

Europol Shuts Down Six DDoS-for-Hire Services Used in Global Attacks

May 7, 2025

Iranian Nation-State Actor OilRig Targets Israeli Organizations

September 22, 2023

Turla Group Deploys LunarWeb and LunarMail Backdoors in Diplomatic Missions

May 15, 2024

New Android Trojan “BlankBot” Targets Turkish Users’ Financial Data

August 5, 2024

Shield Against Insider Threats: Master SaaS Security Posture Management

Worried about insider threats? We’ve got you covered! Join this webinar to explore practical strategies and the secrets of proactive security with SaaS Security Posture Management.

Join Today

The Python scripts, once launched, establish a Meterpreter reverse TCP shell, thereby allowing threat actors to remotely execute code on the infected host, as well as download a Cobalt Strike Beacon to facilitate post-exploitation.

“Abuse of pay-per-click advertisements displayed in search engine results has become a popular tactic among threat actors,” the researchers said. “The threat actors are trying to cast a wide net to lure unsuspecting users seeking certain IT utilities.”

Malvertising

The findings also come against the backdrop of a spike in cybercriminals using paid advertisements to lure users to malicious sites and trick them into downloading a variety of malware such as BATLOADER, EugenLoader (aka FakeBat), and IcedID, which are then used to spread information stealers and other payloads.

To make matters worse, Sophos said it found on prominent criminal marketplaces a “significant number of advertisements for, and discussion about, SEO poisoning, malvertising, and related services” as well as sellers offering compromised Google Ads accounts.

This illustrates that “marketplaces users have a keen interest in SEO poisoning and malvertising” and that “it also negates the difficulty of trying to bypass email filters and convincing users to click a link or download and open an attachment.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

FacebookTwitterPinterestLinkedInTumblrRedditVKWhatsAppEmail

admin

NBCUniversal’s Peacock streaming service is growing, thanks to live sports
Count of Organizations Affected by MOVEit Attacks Passes 515
Related posts
  • Related posts
  • More from author
Attack

Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages

June 21, 20250
Attack

Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms

June 20, 20250
Attack

Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider

June 20, 20250
Load more

Whoops, you're not connected to Mailchimp. You need to enter a valid Mailchimp API key.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Read also
Attack

Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages

June 21, 20250
Malware

Court Ditches HIPAA Reproductive Health Info Privacy Rule

June 21, 20250
Malware

Aflac attack – GovInfoSecurity

June 20, 20250
Malware

AdaCore Merges With CodeSecure for Unified Developer Tools

June 20, 20250
Malware

Anubis Ransomware’s Puzzling New Tactic

June 20, 20250
Malware

‘The Largest Data Breach in History’ That Wasn’t

June 20, 20250
Load more

Recent Posts

  • Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages
  • Court Ditches HIPAA Reproductive Health Info Privacy Rule
  • Aflac attack – GovInfoSecurity
  • AdaCore Merges With CodeSecure for Unified Developer Tools
  • Anubis Ransomware’s Puzzling New Tactic

    © 2022
    • Home
    • Attack
    • Cloud
    • Data
    • Malware
    • Technology
    • World of tech
    • Privacy
    • Contact