Tag: Malicious Ads

Hackers Target macOS Users with Malicious Ads Spreading Stealer Malware
News

Hackers Target macOS Users with Malicious Ads Spreading Stealer Malware

Two distinct stealer malware programs, Atomic Stealer among them, are being delivered to Apple macOS users through fraudulent advertisements and fake websites. According to a research released on Friday by Jamf Threat Labs, while the continuous infostealer assaults that target macOS users may have taken varied approaches to infiltrate their targets' Macs, their ultimate objective is still the theft of confidential information. One such attack chain uses false advertisements to trick people into visiting websites that seem similar to Arc Browser ("airci[.]net") and download malware. It's interesting to note that trying to browse the malicious website directly results in an error, according to security researchers Ferdous Saljooki, Maggie Zirnhelt, and Jaron Bradley. It is only acc...
Malicious Ads Targeting Chinese Users with Fake Notepad++ and VNote Installers
News

Malicious Ads Targeting Chinese Users with Fake Notepad++ and VNote Installers

Malicious advertisements and fake links are being directed towards Chinese people searching for genuine software on search engines like Baidu, such as Notepad++ and VNote. The purpose of these attempts is to spread trojanized versions of the software and eventually launch Geacon, which is a Golang-based variant of Cobalt Strike. According to Kaspersky researcher Sergey Puzan, "the malicious site found in the notepad++ search is distributed through an advertisement block." Upon opening it, a perceptive viewer will quickly spot a humorous discrepancy: the graphic proudly displays Notepad++, while the website address has the line vnote. The title promotes a download of Notepad‐‐ (an analog of Notepad++, also released as open-source software). Notepad is really included with the package...
Malicious Ads on Google Target Chinese Users with Fake Messaging Apps
News

Malicious Ads on Google Target Chinese Users with Fake Messaging Apps

As part of an ongoing malvertising attack, Chinese-speaking users have been targeted by fraudulent Google advertising for restricted messaging apps such as Telegram. Malwarebytes' Jérôme Segura stated in a research released on Thursday that "the threat actor is abusing Google advertiser accounts to create malicious ads and pointing them to pages where unsuspecting users will download Remote Administration Trojan (RATs) instead." "Such programs give an attacker full control of a victim's machine and the ability to drop additional malware." It is important to note that the activity, known by the codename FakeAPP, is an extension of an earlier round of attacks that went after Hong Kong consumers who were looking for messaging apps like Telegram and WhatsApp read more Malicious Ads on G...