#malvertizing — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #malvertizing, aggregated by home.social.
-
2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at https://www.malware-traffic-analysis.net/2026/05/11/index.html
-
2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at https://www.malware-traffic-analysis.net/2026/05/11/index.html
-
2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at https://www.malware-traffic-analysis.net/2026/05/11/index.html
-
2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at https://www.malware-traffic-analysis.net/2026/05/11/index.html
-
2026-05-11 (Monday) #Malvertizing: Another ad in Google search results leads to a page impersonating a Claude download but distributing #macOS #malware. A #pcap of the infection traffic, some of the indicators and associated files are available at https://www.malware-traffic-analysis.net/2026/05/11/index.html
-
The latest Quad9 Trends report with insights from our Director of #ThreatIntel for H2 2025 👉 https://quad9.net/news/blog/trends-h2-2025-cyber-insights/
-
The latest Quad9 Trends report with insights from our Director of #ThreatIntel for H2 2025 👉 https://quad9.net/news/blog/trends-h2-2025-cyber-insights/
-
The latest Quad9 Trends report with insights from our Director of #ThreatIntel for H2 2025 👉 https://quad9.net/news/blog/trends-h2-2025-cyber-insights/
-
The latest Quad9 Trends report with insights from our Director of #ThreatIntel for H2 2025 👉 https://quad9.net/news/blog/trends-h2-2025-cyber-insights/
-
The latest Quad9 Trends report with insights from our Director of #ThreatIntel for H2 2025 👉 https://quad9.net/news/blog/trends-h2-2025-cyber-insights/
-
Lumma Stealer – Tracking distribution channels – Source: securelist.com https://ciso2ciso.com/lumma-stealer-tracking-distribution-channels-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Cryptocurrencies #IncidentResponse #Windowsmalware #securelistcom #Trojanstealer #Infostealers #Malvertizing #TIandIRposts #Phishing #Telegram #CAPTCHA #Malware #Trojan #Lumma #SOC
-
Lumma Stealer – Tracking distribution channels – Source: securelist.com https://ciso2ciso.com/lumma-stealer-tracking-distribution-channels-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Cryptocurrencies #IncidentResponse #Windowsmalware #securelistcom #Trojanstealer #Infostealers #Malvertizing #TIandIRposts #Phishing #Telegram #CAPTCHA #Malware #Trojan #Lumma #SOC
-
Lumma Stealer – Tracking distribution channels – Source: securelist.com https://ciso2ciso.com/lumma-stealer-tracking-distribution-channels-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Cryptocurrencies #IncidentResponse #Windowsmalware #securelistcom #Trojanstealer #Infostealers #Malvertizing #TIandIRposts #Phishing #Telegram #CAPTCHA #Malware #Trojan #Lumma #SOC
-
Lumma Stealer – Tracking distribution channels – Source: securelist.com https://ciso2ciso.com/lumma-stealer-tracking-distribution-channels-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Cryptocurrencies #IncidentResponse #Windowsmalware #securelistcom #Trojanstealer #Infostealers #Malvertizing #TIandIRposts #Phishing #Telegram #CAPTCHA #Malware #Trojan #Lumma #SOC
-
Pirate Streaming Site Malware Campaign Infected One Million Devices
https://torrentfreak.com/pirate-streaming-site-malware-campaign-infected-one-million-devices-250310/
-
Pirate Streaming Site Malware Campaign Infected One Million Devices
https://torrentfreak.com/pirate-streaming-site-malware-campaign-infected-one-million-devices-250310/
-
Pirate Streaming Site Malware Campaign Infected One Million Devices
https://torrentfreak.com/pirate-streaming-site-malware-campaign-infected-one-million-devices-250310/
-
Pirate Streaming Site Malware Campaign Infected One Million Devices
https://torrentfreak.com/pirate-streaming-site-malware-campaign-infected-one-million-devices-250310/
-
Pirate Streaming Site Malware Campaign Infected One Million Devices
https://torrentfreak.com/pirate-streaming-site-malware-campaign-infected-one-million-devices-250310/
-
2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site
I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at https://www.linkedin.com/posts/unit42_2025-01-22-wednesday-a-malicious-ad-led-activity-7288213662329192450-ky3V/ and https://x.com/Unit42_Intel/status/1882448037030584611
Details on that infection are at: https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-01-22-IOCs-for-malware-from-fake-Microsoft-Teams-site.txt
The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.
The exercise #pcap is at https://www.malware-traffic-analysis.net/2025/01/22/index.html
-
2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site
I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at https://www.linkedin.com/posts/unit42_2025-01-22-wednesday-a-malicious-ad-led-activity-7288213662329192450-ky3V/ and https://x.com/Unit42_Intel/status/1882448037030584611
Details on that infection are at: https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-01-22-IOCs-for-malware-from-fake-Microsoft-Teams-site.txt
The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.
The exercise #pcap is at https://www.malware-traffic-analysis.net/2025/01/22/index.html
-
2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site
I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at https://www.linkedin.com/posts/unit42_2025-01-22-wednesday-a-malicious-ad-led-activity-7288213662329192450-ky3V/ and https://x.com/Unit42_Intel/status/1882448037030584611
Details on that infection are at: https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-01-22-IOCs-for-malware-from-fake-Microsoft-Teams-site.txt
The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.
The exercise #pcap is at https://www.malware-traffic-analysis.net/2025/01/22/index.html
-
2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site
I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at https://www.linkedin.com/posts/unit42_2025-01-22-wednesday-a-malicious-ad-led-activity-7288213662329192450-ky3V/ and https://x.com/Unit42_Intel/status/1882448037030584611
Details on that infection are at: https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-01-22-IOCs-for-malware-from-fake-Microsoft-Teams-site.txt
The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.
The exercise #pcap is at https://www.malware-traffic-analysis.net/2025/01/22/index.html
-
2025-01-22 (Wednesday): Traffic Analysis Exercise: Download from fake software site
I've posted a traffic analysis exercise based on the same type of #Malvertizing I wrote about for my employer at https://www.linkedin.com/posts/unit42_2025-01-22-wednesday-a-malicious-ad-led-activity-7288213662329192450-ky3V/ and https://x.com/Unit42_Intel/status/1882448037030584611
Details on that infection are at: https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-01-22-IOCs-for-malware-from-fake-Microsoft-Teams-site.txt
The exercise infection happened on the same day, but it's based on a site impersonating Google Authenticator instead of Microsoft Teams.
The exercise #pcap is at https://www.malware-traffic-analysis.net/2025/01/22/index.html
-
Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages
🧊 Infection Chain:
➡️ Google search for "adobe reader"
↪️ Google ad click
↪️ TDS redirect: `likhs299us[.]tech`
🎣 Fake website: vvw-adobe[.]top
↪️ Download of malware from firebase (.zip containing a .iso)
🗄️ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso#IcedID C2: plivetrakoy[.]com
#IOCs:
🔗 https://www.virustotal.com/gui/file/be9ac59a6b2ea2bf55a57aec8a993a9ff77e5f6ad92531ff3cdbb7ac35295cef/content
🔗 https://www.virustotal.com/gui/ip-address/46.173.218.229/relations
#ThreatIntel #Malware #CTI -
Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages
🧊 Infection Chain:
➡️ Google search for "adobe reader"
↪️ Google ad click
↪️ TDS redirect: `likhs299us[.]tech`
🎣 Fake website: vvw-adobe[.]top
↪️ Download of malware from firebase (.zip containing a .iso)
🗄️ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso#IcedID C2: plivetrakoy[.]com
#IOCs:
🔗 https://www.virustotal.com/gui/file/be9ac59a6b2ea2bf55a57aec8a993a9ff77e5f6ad92531ff3cdbb7ac35295cef/content
🔗 https://www.virustotal.com/gui/ip-address/46.173.218.229/relations
#ThreatIntel #Malware #CTI -
Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages
🧊 Infection Chain:
➡️ Google search for "adobe reader"
↪️ Google ad click
↪️ TDS redirect: `likhs299us[.]tech`
🎣 Fake website: vvw-adobe[.]top
↪️ Download of malware from firebase (.zip containing a .iso)
🗄️ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso#IcedID C2: plivetrakoy[.]com
#IOCs:
🔗 https://www.virustotal.com/gui/file/be9ac59a6b2ea2bf55a57aec8a993a9ff77e5f6ad92531ff3cdbb7ac35295cef/content
🔗 https://www.virustotal.com/gui/ip-address/46.173.218.229/relations
#ThreatIntel #Malware #CTI -
Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages
🧊 Infection Chain:
➡️ Google search for "adobe reader"
↪️ Google ad click
↪️ TDS redirect: `likhs299us[.]tech`
🎣 Fake website: vvw-adobe[.]top
↪️ Download of malware from firebase (.zip containing a .iso)
🗄️ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso#IcedID C2: plivetrakoy[.]com
#IOCs:
🔗 https://www.virustotal.com/gui/file/be9ac59a6b2ea2bf55a57aec8a993a9ff77e5f6ad92531ff3cdbb7ac35295cef/content
🔗 https://www.virustotal.com/gui/ip-address/46.173.218.229/relations
#ThreatIntel #Malware #CTI -
Sophos has observed new IcedID #malvertizing campaigns themed around adobe & other popular software packages
🧊 Infection Chain:
➡️ Google search for "adobe reader"
↪️ Google ad click
↪️ TDS redirect: `likhs299us[.]tech`
🎣 Fake website: vvw-adobe[.]top
↪️ Download of malware from firebase (.zip containing a .iso)
🗄️ Setup_Win_<timestamp>.zip / Setup_Win_<timestamp>.iso#IcedID C2: plivetrakoy[.]com
#IOCs:
🔗 https://www.virustotal.com/gui/file/be9ac59a6b2ea2bf55a57aec8a993a9ff77e5f6ad92531ff3cdbb7ac35295cef/content
🔗 https://www.virustotal.com/gui/ip-address/46.173.218.229/relations
#ThreatIntel #Malware #CTI -
Sophos has observed new #IcedID activity stemming from malvertizing.
Infection Chain:
➡️ Google search for “slack”
↪️ Malicious ad click #malvertizing
↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
➡️ Download:setup_win_13-12-2022_17-15-46.zip, which contained the filesetup_win_13-12-2022_17-15-46.msiRundll32 was then invoked, referencing a DLL staged under
%APPDATA%\Local\Temp\tmp*.dllConnections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)
Seemingly related lure sites can be found via URLScan - https://urlscan.io/search/#www-*.top
-
Sophos has observed new #IcedID activity stemming from malvertizing.
Infection Chain:
➡️ Google search for “slack”
↪️ Malicious ad click #malvertizing
↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
➡️ Download:setup_win_13-12-2022_17-15-46.zip, which contained the filesetup_win_13-12-2022_17-15-46.msiRundll32 was then invoked, referencing a DLL staged under
%APPDATA%\Local\Temp\tmp*.dllConnections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)
Seemingly related lure sites can be found via URLScan - https://urlscan.io/search/#www-*.top
-
Sophos has observed new #IcedID activity stemming from malvertizing.
Infection Chain:
➡️ Google search for “slack”
↪️ Malicious ad click #malvertizing
↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
➡️ Download:setup_win_13-12-2022_17-15-46.zip, which contained the filesetup_win_13-12-2022_17-15-46.msiRundll32 was then invoked, referencing a DLL staged under
%APPDATA%\Local\Temp\tmp*.dllConnections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)
Seemingly related lure sites can be found via URLScan - https://urlscan.io/search/#www-*.top
-
Sophos has observed new #IcedID activity stemming from malvertizing.
Infection Chain:
➡️ Google search for “slack”
↪️ Malicious ad click #malvertizing
↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
➡️ Download:setup_win_13-12-2022_17-15-46.zip, which contained the filesetup_win_13-12-2022_17-15-46.msiRundll32 was then invoked, referencing a DLL staged under
%APPDATA%\Local\Temp\tmp*.dllConnections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)
Seemingly related lure sites can be found via URLScan - https://urlscan.io/search/#www-*.top
-
Sophos has observed new #IcedID activity stemming from malvertizing.
Infection Chain:
➡️ Google search for “slack”
↪️ Malicious ad click #malvertizing
↪️ Redirect 1: dasaert[.]fun/slack/index[.]php
↪️ Redirect 2: www-slack[.]top/downloads/windows/ (Registrar: AS29470 🇷🇺)
➡️ Download:setup_win_13-12-2022_17-15-46.zip, which contained the filesetup_win_13-12-2022_17-15-46.msiRundll32 was then invoked, referencing a DLL staged under
%APPDATA%\Local\Temp\tmp*.dllConnections initiated with the C2 server: 143.198.92[.]88 (resolving to domain estrabornhot[.]com)
Seemingly related lure sites can be found via URLScan - https://urlscan.io/search/#www-*.top