home.social

#malvertising — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #malvertising, aggregated by home.social.

  1. @kitkat_blue @thomasfuchs Are there any good Chromium-based browsers which provide the functionality for which most current #Brave users presumably intend to attain by installing Brave?

    I need something to recommend or install for clients who want to replace Chrome or Edge with something familiar, while protecting them from #surveillance, #malvertising, and other ad- or tracking-based threats.

    A disenshittified Firefox fork + uBlock Origin works for those who are willing to adapt to a slightly different look and feel, but a lot of clients insist (in different words) on maintaining as close to the #Chromium UX as possible.

    #privacy

  2. @kitkat_blue @thomasfuchs Are there any good Chromium-based browsers which provide the functionality for which most current #Brave users presumably intend to attain by installing Brave?

    I need something to recommend or install for clients who want to replace Chrome or Edge with something familiar, while protecting them from #surveillance, #malvertising, and other ad- or tracking-based threats.

    A disenshittified Firefox fork + uBlock Origin works for those who are willing to adapt to a slightly different look and feel, but a lot of clients insist (in different words) on maintaining as close to the #Chromium UX as possible.

    #privacy

  3. @kitkat_blue @thomasfuchs Are there any good Chromium-based browsers which provide the functionality for which most current #Brave users presumably intend to attain by installing Brave?

    I need something to recommend or install for clients who want to replace Chrome or Edge with something familiar, while protecting them from #surveillance, #malvertising, and other ad- or tracking-based threats.

    A disenshittified Firefox fork + uBlock Origin works for those who are willing to adapt to a slightly different look and feel, but a lot of clients insist (in different words) on maintaining as close to the #Chromium UX as possible.

    #privacy

  4. @kitkat_blue @thomasfuchs Are there any good Chromium-based browsers which provide the functionality for which most current #Brave users presumably intend to attain by installing Brave?

    I need something to recommend or install for clients who want to replace Chrome or Edge with something familiar, while protecting them from #surveillance, #malvertising, and other ad- or tracking-based threats.

    A disenshittified Firefox fork + uBlock Origin works for those who are willing to adapt to a slightly different look and feel, but a lot of clients insist (in different words) on maintaining as close to the #Chromium UX as possible.

    #privacy

  5. @kitkat_blue @thomasfuchs Are there any good Chromium-based browsers which provide the functionality for which most current #Brave users presumably intend to attain by installing Brave?

    I need something to recommend or install for clients who want to replace Chrome or Edge with something familiar, while protecting them from #surveillance, #malvertising, and other ad- or tracking-based threats.

    A disenshittified Firefox fork + uBlock Origin works for those who are willing to adapt to a slightly different look and feel, but a lot of clients insist (in different words) on maintaining as close to the #Chromium UX as possible.

    #privacy

  6. Tracking TamperedChef Clusters via Certificate and Code Reuse

    Multiple threat clusters designated as CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110 have been distributing trojanized productivity software through malicious advertising campaigns since 2023. These applications, including PDF editors, calendars, and compression tools, appear legitimate but contain remote access capabilities enabling deployment of information stealers, proxy tooling, and RATs. The campaigns leverage code-signing certificates, remain dormant for weeks to months before activation, and affect organizations globally with over 4,000 samples identified across 100 variants. CL-CRI-1089 operations utilize Ukrainian, Malaysian, and British infrastructure with 34 unique code-signing entities, while CL-UNK-1090 demonstrates vertical integration between advertising agencies and malware creation using primarily Israeli infrastructure with 39 corporations involved. Distribution occurs through sophisticated malvertising employing professional websites, CDN delivery, and search engine optimization techniques.

    Pulse ID: 6a0dae41682ec38e55d1aa12
    Pulse Link: otx.alienvault.com/pulse/6a0da
    Pulse Author: AlienVault
    Created: 2026-05-20 12:51:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #InfoSec #Israel #Malvertising #Malware #OTX #OpenThreatExchange #PDF #Proxy #RAT #Trojan #UK #Ukr #Ukrainian #bot #AlienVault

  7. Tracking TamperedChef Clusters via Certificate and Code Reuse

    Multiple threat clusters designated as CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110 have been distributing trojanized productivity software through malicious advertising campaigns since 2023. These applications, including PDF editors, calendars, and compression tools, appear legitimate but contain remote access capabilities enabling deployment of information stealers, proxy tooling, and RATs. The campaigns leverage code-signing certificates, remain dormant for weeks to months before activation, and affect organizations globally with over 4,000 samples identified across 100 variants. CL-CRI-1089 operations utilize Ukrainian, Malaysian, and British infrastructure with 34 unique code-signing entities, while CL-UNK-1090 demonstrates vertical integration between advertising agencies and malware creation using primarily Israeli infrastructure with 39 corporations involved. Distribution occurs through sophisticated malvertising employing professional websites, CDN delivery, and search engine optimization techniques.

    Pulse ID: 6a0dae41682ec38e55d1aa12
    Pulse Link: otx.alienvault.com/pulse/6a0da
    Pulse Author: AlienVault
    Created: 2026-05-20 12:51:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #InfoSec #Israel #Malvertising #Malware #OTX #OpenThreatExchange #PDF #Proxy #RAT #Trojan #UK #Ukr #Ukrainian #bot #AlienVault

  8. Tracking TamperedChef Clusters via Certificate and Code Reuse

    Multiple threat clusters designated as CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110 have been distributing trojanized productivity software through malicious advertising campaigns since 2023. These applications, including PDF editors, calendars, and compression tools, appear legitimate but contain remote access capabilities enabling deployment of information stealers, proxy tooling, and RATs. The campaigns leverage code-signing certificates, remain dormant for weeks to months before activation, and affect organizations globally with over 4,000 samples identified across 100 variants. CL-CRI-1089 operations utilize Ukrainian, Malaysian, and British infrastructure with 34 unique code-signing entities, while CL-UNK-1090 demonstrates vertical integration between advertising agencies and malware creation using primarily Israeli infrastructure with 39 corporations involved. Distribution occurs through sophisticated malvertising employing professional websites, CDN delivery, and search engine optimization techniques.

    Pulse ID: 6a0dae41682ec38e55d1aa12
    Pulse Link: otx.alienvault.com/pulse/6a0da
    Pulse Author: AlienVault
    Created: 2026-05-20 12:51:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #InfoSec #Israel #Malvertising #Malware #OTX #OpenThreatExchange #PDF #Proxy #RAT #Trojan #UK #Ukr #Ukrainian #bot #AlienVault

  9. Tracking TamperedChef Clusters via Certificate and Code Reuse

    Multiple threat clusters designated as CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110 have been distributing trojanized productivity software through malicious advertising campaigns since 2023. These applications, including PDF editors, calendars, and compression tools, appear legitimate but contain remote access capabilities enabling deployment of information stealers, proxy tooling, and RATs. The campaigns leverage code-signing certificates, remain dormant for weeks to months before activation, and affect organizations globally with over 4,000 samples identified across 100 variants. CL-CRI-1089 operations utilize Ukrainian, Malaysian, and British infrastructure with 34 unique code-signing entities, while CL-UNK-1090 demonstrates vertical integration between advertising agencies and malware creation using primarily Israeli infrastructure with 39 corporations involved. Distribution occurs through sophisticated malvertising employing professional websites, CDN delivery, and search engine optimization techniques.

    Pulse ID: 6a0dae41682ec38e55d1aa12
    Pulse Link: otx.alienvault.com/pulse/6a0da
    Pulse Author: AlienVault
    Created: 2026-05-20 12:51:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #InfoSec #Israel #Malvertising #Malware #OTX #OpenThreatExchange #PDF #Proxy #RAT #Trojan #UK #Ukr #Ukrainian #bot #AlienVault

  10. Tracking TamperedChef Clusters via Certificate and Code Reuse

    Multiple threat clusters designated as CL-CRI-1089, CL-UNK-1090, and CL-UNK-1110 have been distributing trojanized productivity software through malicious advertising campaigns since 2023. These applications, including PDF editors, calendars, and compression tools, appear legitimate but contain remote access capabilities enabling deployment of information stealers, proxy tooling, and RATs. The campaigns leverage code-signing certificates, remain dormant for weeks to months before activation, and affect organizations globally with over 4,000 samples identified across 100 variants. CL-CRI-1089 operations utilize Ukrainian, Malaysian, and British infrastructure with 34 unique code-signing entities, while CL-UNK-1090 demonstrates vertical integration between advertising agencies and malware creation using primarily Israeli infrastructure with 39 corporations involved. Distribution occurs through sophisticated malvertising employing professional websites, CDN delivery, and search engine optimization techniques.

    Pulse ID: 6a0dae41682ec38e55d1aa12
    Pulse Link: otx.alienvault.com/pulse/6a0da
    Pulse Author: AlienVault
    Created: 2026-05-20 12:51:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CDN #CyberSecurity #InfoSec #Israel #Malvertising #Malware #OTX #OpenThreatExchange #PDF #Proxy #RAT #Trojan #UK #Ukr #Ukrainian #bot #AlienVault

  11. Malvertisers Exploit Code Signing in TamperedChef Malware Campaigns

    Meet the sneaky malware campaign that's been flying under the radar, leveraging polished marketing tactics and code signing to spread its malicious reach - with over 4,000 samples and 100 unique variants uncovered across three distinct clusters of activity.

    osintsights.com/malvertisers-e

    #TamperedchefMalware #CodeSigning #MalwareOperations #Malvertising #PaloAltoNetworks

  12. Malicious Android Apps Fuel 659M Daily Ad Fraud Bid Requests

    Meet Trapdoor, a massive ad fraud scam driven by 455 malicious Android apps that generated a whopping 659 million daily bid requests at its peak, all while hiding in plain sight as harmless utilities like PDF viewers and file managers. These fake apps tricked users into installing malware, unleashing a hidden ad fraud operation…

    osintsights.com/malicious-andr

    #AdFraud #Malvertising #AndroidMalware #MobileSecurity #EmergingThreats

  13. Donuts and Beagles: Fake Claude site spreads backdoor

    A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called Beagle through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. Beagle supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering AdaptixC2 framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.

    Pulse ID: 69fcc63f1dce161fc2f8380c
    Pulse Link: otx.alienvault.com/pulse/69fcc
    Pulse Author: AlienVault
    Created: 2026-05-07 17:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CrowdStrike #CyberSecurity #Encryption #InfoSec #Malvertising #OTX #OpenThreatExchange #PlugX #SentinelOne #SideLoading #Trellix #ZIP #bot #AlienVault

  14. Donuts and Beagles: Fake Claude site spreads backdoor

    A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called Beagle through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. Beagle supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering AdaptixC2 framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.

    Pulse ID: 69fcc63f1dce161fc2f8380c
    Pulse Link: otx.alienvault.com/pulse/69fcc
    Pulse Author: AlienVault
    Created: 2026-05-07 17:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CrowdStrike #CyberSecurity #Encryption #InfoSec #Malvertising #OTX #OpenThreatExchange #PlugX #SentinelOne #SideLoading #Trellix #ZIP #bot #AlienVault

  15. Donuts and Beagles: Fake Claude site spreads backdoor

    A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called Beagle through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. Beagle supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering AdaptixC2 framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.

    Pulse ID: 69fcc63f1dce161fc2f8380c
    Pulse Link: otx.alienvault.com/pulse/69fcc
    Pulse Author: AlienVault
    Created: 2026-05-07 17:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CrowdStrike #CyberSecurity #Encryption #InfoSec #Malvertising #OTX #OpenThreatExchange #PlugX #SentinelOne #SideLoading #Trellix #ZIP #bot #AlienVault

  16. Donuts and Beagles: Fake Claude site spreads backdoor

    A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called Beagle through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. Beagle supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering AdaptixC2 framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.

    Pulse ID: 69fcc63f1dce161fc2f8380c
    Pulse Link: otx.alienvault.com/pulse/69fcc
    Pulse Author: AlienVault
    Created: 2026-05-07 17:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CrowdStrike #CyberSecurity #Encryption #InfoSec #Malvertising #OTX #OpenThreatExchange #PlugX #SentinelOne #SideLoading #Trellix #ZIP #bot #AlienVault

  17. Donuts and Beagles: Fake Claude site spreads backdoor

    A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called Beagle through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. Beagle supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering AdaptixC2 framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.

    Pulse ID: 69fcc63f1dce161fc2f8380c
    Pulse Link: otx.alienvault.com/pulse/69fcc
    Pulse Author: AlienVault
    Created: 2026-05-07 17:05:03

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CrowdStrike #CyberSecurity #Encryption #InfoSec #Malvertising #OTX #OpenThreatExchange #PlugX #SentinelOne #SideLoading #Trellix #ZIP #bot #AlienVault

  18. Hackers are abusing the popularity of AI tools with a fake #ClaudeAI website that spreads a newly discovered backdoor called #Beagle. The campaign uses DLL sideloading, #malvertising, and trusted signed files to infect Windows systems.

    Read: hackread.com/hackers-fake-clau

    #Cybersecurity #Malware #ClaudeAI #ArtificialIntelligence

  19. Hackers are abusing the popularity of AI tools with a fake website that spreads a newly discovered backdoor called . The campaign uses DLL sideloading, , and trusted signed files to infect Windows systems.

    Read: hackread.com/hackers-fake-clau

  20. Hackers are abusing the popularity of AI tools with a fake #ClaudeAI website that spreads a newly discovered backdoor called #Beagle. The campaign uses DLL sideloading, #malvertising, and trusted signed files to infect Windows systems.

    Read: hackread.com/hackers-fake-clau

    #Cybersecurity #Malware #ClaudeAI #ArtificialIntelligence

  21. Hackers are abusing the popularity of AI tools with a fake #ClaudeAI website that spreads a newly discovered backdoor called #Beagle. The campaign uses DLL sideloading, #malvertising, and trusted signed files to infect Windows systems.

    Read: hackread.com/hackers-fake-clau

    #Cybersecurity #Malware #ClaudeAI #ArtificialIntelligence

  22. Hackers are abusing the popularity of AI tools with a fake #ClaudeAI website that spreads a newly discovered backdoor called #Beagle. The campaign uses DLL sideloading, #malvertising, and trusted signed files to infect Windows systems.

    Read: hackread.com/hackers-fake-clau

    #Cybersecurity #Malware #ClaudeAI #ArtificialIntelligence

  23. Malicious Site Exploits AI Interest to Deploy Beagle Backdoor

    Beware of a fake website masquerading as Anthropic's Claude interface, tricking users into downloading a 505 MB ZIP archive that unleashes a new, previously undocumented Windows backdoor called Beagle. This malicious campaign uses a convincing imitation of the legitimate site to spread the infection.

    osintsights.com/malicious-site

    #BeagleBackdoor #AiMalware #WindowsMalware #Malvertising #DllSideloading

  24. MakeUseOf: Homebrew users are accidentally downloading malware instead of the real app. “A malicious Google ad campaign is targeting users of a popular free, open-source software package manager for macOS and Linux that simplifies installing, updating, and managing command-line tools. Your password and personal data could be at serious risk.”

    https://rbfirehose.com/2026/05/05/makeuseof-homebrew-users-are-accidentally-downloading-malware-instead-of-the-real-app/
  25. MakeUseOf: Homebrew users are accidentally downloading malware instead of the real app. “A malicious Google ad campaign is targeting users of a popular free, open-source software package manager for macOS and Linux that simplifies installing, updating, and managing command-line tools. Your password and personal data could be at serious risk.”

    https://rbfirehose.com/2026/05/05/makeuseof-homebrew-users-are-accidentally-downloading-malware-instead-of-the-real-app/
  26. MakeUseOf: Homebrew users are accidentally downloading malware instead of the real app. “A malicious Google ad campaign is targeting users of a popular free, open-source software package manager for macOS and Linux that simplifies installing, updating, and managing command-line tools. Your password and personal data could be at serious risk.”

    https://rbfirehose.com/2026/05/05/makeuseof-homebrew-users-are-accidentally-downloading-malware-instead-of-the-real-app/
  27. MakeUseOf: Homebrew users are accidentally downloading malware instead of the real app. “A malicious Google ad campaign is targeting users of a popular free, open-source software package manager for macOS and Linux that simplifies installing, updating, and managing command-line tools. Your password and personal data could be at serious risk.”

    https://rbfirehose.com/2026/05/05/makeuseof-homebrew-users-are-accidentally-downloading-malware-instead-of-the-real-app/
  28. MakeUseOf: Homebrew users are accidentally downloading malware instead of the real app. “A malicious Google ad campaign is targeting users of a popular free, open-source software package manager for macOS and Linux that simplifies installing, updating, and managing command-line tools. Your password and personal data could be at serious risk.”

    https://rbfirehose.com/2026/05/05/makeuseof-homebrew-users-are-accidentally-downloading-malware-instead-of-the-real-app/
  29. And now a funny commentary. This guy from India or Russia or whatever spent quite literally 3-4 HOURS with my 93-year-old mom trying to get her to install stuff, share her screen, and get through a password change. In that time she managed to install 2 apps and change TWO passwords. That’s it.

    He should have been some kind of priest, rabbi, or imam or something. Patience. Of. A. Saint. Sad to think of this amazing super power going to waste on a life of crime.

    I have to do these things with her and I can’t get them done any faster than that. But I don’t have the stamina to go 4 hours in the ring with her. 😜 This guy is impressive.
    #identitytheft #malvertising #security

  30. And now a funny commentary. This guy from India or Russia or whatever spent quite literally 3-4 HOURS with my 93-year-old mom trying to get her to install stuff, share her screen, and get through a password change. In that time she managed to install 2 apps and change TWO passwords. That’s it.

    He should have been some kind of priest, rabbi, or imam or something. Patience. Of. A. Saint. Sad to think of this amazing super power going to waste on a life of crime.

    I have to do these things with her and I can’t get them done any faster than that. But I don’t have the stamina to go 4 hours in the ring with her. 😜 This guy is impressive.
    #identitytheft #malvertising #security