• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Home
  • Contact Us

iHash

News and How to's

  • Smart GPS Tracker for $21

    Smart GPS Tracker  for $21
  • The 2023 Leadership Essentials Master Class Bundle for $29

    The 2023 Leadership Essentials Master Class Bundle for $29
  • WisperSEO: Lifetime Subscription for $49

    WisperSEO: Lifetime Subscription for $49
  • The 2023 Complete Linux E-Degree Training Bundle for $29

    The 2023 Complete Linux E-Degree Training Bundle for $29
  • The Essential 2024 MBA Bundle for $39

    The Essential 2024 MBA Bundle for $39
  • News
    • Rumor
    • Design
    • Concept
    • WWDC
    • Security
    • BigData
  • Apps
    • Free Apps
    • OS X
    • iOS
    • iTunes
      • Music
      • Movie
      • Books
  • How to
    • OS X
      • OS X Mavericks
      • OS X Yosemite
      • Where Download OS X 10.9 Mavericks
    • iOS
      • iOS 7
      • iOS 8
      • iPhone Firmware
      • iPad Firmware
      • iPod touch
      • AppleTV Firmware
      • Where Download iOS 7 Beta
      • Jailbreak News
      • iOS 8 Beta/GM Download Links (mega links) and How to Upgrade
      • iPhone Recovery Mode
      • iPhone DFU Mode
      • How to Upgrade iOS 6 to iOS 7
      • How To Downgrade From iOS 7 Beta to iOS 6
    • Other
      • Disable Apple Remote Control
      • Pair Apple Remote Control
      • Unpair Apple Remote Control
  • Special Offers
  • Contact us

Malicious Google Ads Trick WinSCP Users into Installing Malware

Nov 17, 2023 by iHash Leave a Comment

Nov 17, 2023NewsroomMalvertising / Malware

Threat actors are leveraging manipulated search results and bogus Google ads that trick users who are looking to download legitimate software such as WinSCP into installing malware instead.

Cybersecurity company Securonix is tracking the ongoing activity under the name SEO#LURKER.

“The malicious advertisement directs the user to a compromised WordPress website gameeweb[.]com, which redirects the user to an attacker-controlled phishing site,” security researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov said in a report shared with The Hacker News.

The threat actors are believed to leverage Google’s Dynamic Search Ads (DSAs), which automatically generates ads based on a site’s content to serve the malicious ads that take the victims to the infected site.

Cybersecurity

The ultimate goal of the complex multi-stage attack chain is to entice users into clicking on the fake, lookalike WinSCP website, winccp[.]net, and download the malware.

“Traffic from the gaweeweb[.]com website to the fake winsccp[.]net website relies on a correct referrer header being set properly,” the researchers said. “If the referrer is incorrect, the user is ‘Rickrolled’ and is sent to the infamous Rick Astley YouTube video.”

The final payload takes the form of a ZIP file (“WinSCP_v.6.1.zip”) that comes with a setup executable, which, when launched, employs DLL side-loading to load and execute a DLL file named python311.dll that’s present within the archive.

The DLL, for its part, downloads and executes a legitimate WinSCP installer to keep up the ruse, while stealthily dropping Python scripts (“slv.py” and “wo15.py”) in the background to activate the malicious behavior. It’s also responsible for setting up persistence.

Both the Python scripts are designed to establish contact with a remote actor-controlled server to receive further instructions that allow the attackers to run enumeration commands on the host.

“Given the fact that the attackers were leveraging Google Ads to disperse malware, it can be believed that the targets are limited to anyone seeking WinSCP software,” the researchers said.

“The geoblocking used on the site hosting the malware suggests that those in the U.S. are victims of this attack.”

Cybersecurity

This is not the first time Google’s Dynamic Search Ads have been abused to distribute malware. Late last month, Malwarebytes lifted the lid on a campaign that targets users searching for PyCharm with links to a hacked website hosting a rogue installer that paves the way for the deployment of information-stealing malware.

Malvertising has grown in popularity among cybercriminals in the past few years, with numerous malware campaigns using the tactic for attacks in recent months.

Earlier this week, Malwarebytes revealed an uptick in credit card skimming campaigns in October 2023 that’s estimated to have compromised hundreds of e-commerce websites with an aim to steal financial information by injecting convincing counterfeit payment pages.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Source link

Share this:

  • Facebook
  • Twitter
  • Pinterest
  • LinkedIn

Filed Under: Security Tagged With: ads, computer security, cyber attacks, cyber news, cyber security news, cyber security news today, cyber security updates, cyber updates, data breach, google, hacker news, hacking news, how to hack, information security, Installing, Malicious, Malware, network security, ransomware malware, software vulnerability, the hacker news, Trick, Users, WinSCP

Special Offers

  • Smart GPS Tracker for $21

    Smart GPS Tracker  for $21
  • The 2023 Leadership Essentials Master Class Bundle for $29

    The 2023 Leadership Essentials Master Class Bundle for $29
  • WisperSEO: Lifetime Subscription for $49

    WisperSEO: Lifetime Subscription for $49
  • The 2023 Complete Linux E-Degree Training Bundle for $29

    The 2023 Complete Linux E-Degree Training Bundle for $29
  • The Essential 2024 MBA Bundle for $39

    The Essential 2024 MBA Bundle for $39

Reader Interactions

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Primary Sidebar

  • Facebook
  • GitHub
  • Instagram
  • Pinterest
  • Twitter
  • YouTube

More to See

Elastic’s Lisa Jones-Huff reveals how she thrives in a startup atmosphere

Elastic’s Lisa Jones-Huff reveals how she thrives in a startup atmosphere

Dec 6, 2023 By iHash

Generative AI Report – 12/6/2023

Dec 6, 2023 By iHash

Tags

* Apple attacks Cisco computer security cyber attacks cyber crime cyber news cybersecurity Cyber Security cyber security news cyber security news today cyber security updates cyber threats cyber updates data data breach data breaches google hacker hacker news Hackers hacking hacking news how to hack incident response information security iOS 7 iOS 8 iPhone Malware microsoft network security ransomware ransomware malware risk management security security breaches security vulnerabilities software vulnerability the hacker news Threat update video web applications

Latest

Smart GPS Tracker for $21

Expires June 11, 2123 07:59 PST Buy now and get 31% off KEY FEATURES The Smart GPS Tracker is the perfect solution for keeping track of your belongings or loved ones. Using global positioning (GPS) technology and a secure Bluetooth-compatible signal, the tracker ensures real-time updates on your item’s location, accessible through the app. With […]

The 2023 Leadership Essentials Master Class Bundle for $29

Expires June 12, 2024 23:59 PST Buy now and get 62% off The Science of Leadership KEY FEATURES Looking to take your leadership skills to the next level? The Science of Leadership course provides a unique and evidence-based approach to leadership. With a focus on scientific insights, this course will help you understand what drives […]

Threat Actors Can Leverage AWS STS to Infiltrate Cloud Accounts

Dec 06, 2023NewsroomAccess Management / Cloud Security Threat actors can take advantage of Amazon Web Services Security Token Service (AWS STS) as a way to infiltrate cloud accounts and conduct follow-on attacks. The service enables threat actors to impersonate user identities and roles in cloud environments, Red Canary researchers Thomas Gardner and Cody Betsworth said […]

Apple Podcasts names Wiser Than Me the 2023 Show of the Year

December 5, 2023 UPDATE Apple Podcasts names Wiser Than Me the 2023 Show of the Year Julia Louis-Dreyfus and Lemonada Media’s founders reflect on a standout first season At the outset of Wiser Than Me with Julia Louis-Dreyfus from Lemonada Media, Hollywood legend Jane Fonda recalled the sudden revelation she had on the eve of her 59th birthday: that she […]

What are Restricted Settings in Android?

Restricted Settings in Android 13 and 14

With each new version of the Android operating system, new features are added to protect users from malware. For example, Android 13 introduced Restricted Settings. In this post, we’ll discuss what this feature involves, what it’s designed to protect against, and how effectively it does its job (spoiler: not very well). What are Restricted Settings? […]

The 2023 Machine Learning for Absolute Beginners E-Degree Program for $29

Expires June 13, 2123 23:59 PST Buy now and get 90% off KEY FEATURES AI-ML for Absolute Beginners E-Degree is curated keeping in mind all the freshers, college students, hobbyists, and all those who want to learn Artificial Intelligence from the get-go. The e-degree comprises basic tools & technologies such as Python, Numpy, SciPy, Pandas, […]

Jailbreak

Pangu Releases Updated Jailbreak of iOS 9 Pangu9 v1.2.0

Pangu has updated its jailbreak utility for iOS 9.0 to 9.0.2 with a fix for the manage storage bug and the latest version of Cydia. Change log V1.2.0 (2015-10-27) 1. Bundle latest Cydia with new Patcyh which fixed failure to open url scheme in MobileSafari 2. Fixed the bug that “preferences -> Storage&iCloud Usage -> […]

Apple Blocks Pangu Jailbreak Exploits With Release of iOS 9.1

Apple has blocked exploits used by the Pangu Jailbreak with the release of iOS 9.1. Pangu was able to jailbreak iOS 9.0 to 9.0.2; however, in Apple’s document on the security content of iOS 9.1, PanguTeam is credited with discovering two vulnerabilities that have been patched.

Pangu Releases Updated Jailbreak of iOS 9 Pangu9 v1.1.0

  Pangu has released an update to its jailbreak utility for iOS 9 that improves its reliability and success rate.   Change log V1.1.0 (2015-10-21) 1. Improve the success rate and reliability of jailbreak program for 64bit devices 2. Optimize backup process and improve jailbreak speed, and fix an issue that leads to fail to […]

Activator 1.9.6 Released With Support for iOS 9, 3D Touch

  Ryan Petrich has released Activator 1.9.6, an update to the centralized gesture, button, and shortcut manager, that brings support for iOS 9 and 3D Touch.

Copyright iHash.eu © 2023
We use cookies on this website. By using this site, you agree that we may store and access cookies on your device. Accept Read More
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT