#seopoisoning — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #seopoisoning, aggregated by home.social.
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.
Pulse ID: 6aa13e05864a561a7db38073
Pulse Link: https://otx.alienvault.com/pulse/6aa13e05864a561a7db38073
Pulse Author: AlienVault
Created: 2026-09-09 11:07:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault
-
BengalSEO Campaign Exploits Bing Search Results
Meet BengalSEO, a notorious group that's been secretly manipulating Bing search results with sneaky Black Hat SEO tactics since at least 2015, luring victims into malware and tech-support scams. They're masters of creating fake support pages that look legit, but actually serve as traps.
#Bengalseo #BlackHatSeo #SeoPoisoning #MalwareOperations #TechsupportScams
-
The Gambling Goblin campaign turns Brazilian government websites into an SEO weapon. Suspected Gambling Goblin operators push illicit gambling pages.
#GamblingGoblin #EarthBerberoka #SEOPoisoning #LinuxMalware #Cybercrime
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault