#seopoisoning — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #seopoisoning, aggregated by home.social.
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Indicators extracted from public reporting. Source: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-fake-gaming-websites-seo-poisoning/
Pulse ID: 6a8cda10646ccdb0885a4aaf
Pulse Link: https://otx.alienvault.com/pulse/6a8cda10646ccdb0885a4aaf
Pulse Author: CyberHunter_NL
Created: 2026-08-24 23:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Malware #McAfee #Minecraft #OTX #OpenThreatExchange #RCE #SEOPoisoning #bot #CyberHunter_NL
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Indicators extracted from public reporting. Source: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-fake-gaming-websites-seo-poisoning/
Pulse ID: 6a8cda10646ccdb0885a4aaf
Pulse Link: https://otx.alienvault.com/pulse/6a8cda10646ccdb0885a4aaf
Pulse Author: CyberHunter_NL
Created: 2026-08-24 23:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Malware #McAfee #Minecraft #OTX #OpenThreatExchange #RCE #SEOPoisoning #bot #CyberHunter_NL
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Indicators extracted from public reporting. Source: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-fake-gaming-websites-seo-poisoning/
Pulse ID: 6a8cda10646ccdb0885a4aaf
Pulse Link: https://otx.alienvault.com/pulse/6a8cda10646ccdb0885a4aaf
Pulse Author: CyberHunter_NL
Created: 2026-08-24 23:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Malware #McAfee #Minecraft #OTX #OpenThreatExchange #RCE #SEOPoisoning #bot #CyberHunter_NL
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Indicators extracted from public reporting. Source: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-fake-gaming-websites-seo-poisoning/
Pulse ID: 6a8cda10646ccdb0885a4aaf
Pulse Link: https://otx.alienvault.com/pulse/6a8cda10646ccdb0885a4aaf
Pulse Author: CyberHunter_NL
Created: 2026-08-24 23:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Malware #McAfee #Minecraft #OTX #OpenThreatExchange #RCE #SEOPoisoning #bot #CyberHunter_NL
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Indicators extracted from public reporting. Source: https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-fake-gaming-websites-seo-poisoning/
Pulse ID: 6a8cda10646ccdb0885a4aaf
Pulse Link: https://otx.alienvault.com/pulse/6a8cda10646ccdb0885a4aaf
Pulse Author: CyberHunter_NL
Created: 2026-08-24 23:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Malware #McAfee #Minecraft #OTX #OpenThreatExchange #RCE #SEOPoisoning #bot #CyberHunter_NL
-
Malware Spreads via Fake Minecraft Clients Using SEO Poisoning
Malware is sneaking its way into gamers' computers through fake Minecraft clients, using clever tricks like search engine manipulation and spreading malicious links on popular platforms like Discord and YouTube. Over 6,300 attempts to access these malicious sites have already been blocked by McAfee Labs.
#SeoPoisoning #MalwareOperations #Minecraft #Discord #Mediafire
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
https://www.alojapan.com/1516807/tokyo-police-warn-of-new-scam-tactic-search-results-falsely-displaying-not-a-scam-ai-summaries-also-contaminated-biggo-finance/ Tokyo Police Warn of New Scam Tactic: Search Results Falsely Displaying “Not a Scam,” AI Summaries Also Contaminated — BigGo Finance #AISummary #jade #news #SEOPoisoning #SiteSearchSpam #SNSTypeInvestmentFraud #Tokyo #TokyoMetropolitanPoliceDepartmentCyberCrimeCountermeasuresDivision #TokyoMetropolitanPoliceDepartmentCyberSecurityCountermeasuresDivision #TokyoNews #X(formerlyTwitter) #東京 #東京都 The Tokyo Metropolitan Police Departme
-
https://www.alojapan.com/1516807/tokyo-police-warn-of-new-scam-tactic-search-results-falsely-displaying-not-a-scam-ai-summaries-also-contaminated-biggo-finance/ Tokyo Police Warn of New Scam Tactic: Search Results Falsely Displaying “Not a Scam,” AI Summaries Also Contaminated — BigGo Finance #AISummary #jade #news #SEOPoisoning #SiteSearchSpam #SNSTypeInvestmentFraud #Tokyo #TokyoMetropolitanPoliceDepartmentCyberCrimeCountermeasuresDivision #TokyoMetropolitanPoliceDepartmentCyberSecurityCountermeasuresDivision #TokyoNews #X(formerlyTwitter) #東京 #東京都 The Tokyo Metropolitan Police Departme
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
GPU mining malware spreads via SEO poisoning and AI chatbot manipulation
Beware of a sneaky malware that's spreading through manipulated AI chatbot responses and search engine poisoning, tricking users into downloading GPU mining malware. Victims unknowingly stumble upon malicious links while searching for popular software or getting recommendations from AI assistants.
#SeoPoisoning #GpuMiningMalware #AiChatbotManipulation #MalwareOperations #EmergingThreats
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
Iranian Hackers Deploy AI-Backed MiniFast Backdoor via Phishing and SEO Poisoning
Iranian hackers have escalated their cyber attacks, leveraging AI-powered tools to craft malware and targeting key sectors like aviation, defense, and telecommunications across the US, Europe, and the Middle East. Their sophisticated tactics, including phishing and SEO poisoning, have allowed them to spy on…
#IranianHackers #AibackedMalware #MinifastBackdoor #SeoPoisoning #Phishing
-
Iran-Linked Hackers Target US Aviation with Sophisticated Phishing and SEO Poisoning
Meet Nimbus Manticore, an Iran-linked hacking group that's back with a vengeance, using clever phishing and SEO poisoning tactics to target the US aviation industry in a series of sophisticated attacks. Their latest campaign, which ran from February to April 2026, marked a significant expansion into aviation,…
#IranlinkedHackers #UsAviation #Phishing #SeoPoisoning #OperationEpicFury
-
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"
-
🎯 Threat Intelligence
===================Executive summary: Recent reporting attributes an SEO poisoning campaign to the BlackCat/ALPHV threat actor, describing manipulation of search results for popular software to steer victims to malicious download pages. The source links the activity to a coordinated effort to replace legitimate installers or mirrors with attacker-controlled payloads. The article does not publish sample IoCs, hashes, or C2 addresses.
Technical details:
• Reported technique: SEO poisoning (search-result manipulation) to surface malicious pages for popular software keywords.
• Delivery vector described: attacker-controlled download pages or mirrors that host malicious installers or archived payloads instead of legitimate binaries.
• Payloads: the source indicates distribution of malware via these fake downloads, but does not enumerate specific families, hashes, or signatures in the published material.🔹 Attack Chain Analysis
• Initial Access (Search poisoning): Malicious pages are promoted or optimized to appear in search results for targeted software queries.
• Delivery (Malicious download pages): Victim navigates to a malicious page presented as a legitimate download source.
• Execution (User installs): Victim executes the downloaded installer or archive, triggering payload execution.
• Post-execution (Payload activity): Article reports general payload delivery but does not detail post-execution TTPs or ransom/logical behavior tied to BlackCat.Analysis:
The reporting highlights the operational focus on search-engine manipulation rather than email or exploit-based vectors. This approach targets users seeking popular software and relies on social engineering and deceptive hosting. Attribution to BlackCat/ALPHV is asserted by the source; supporting telemetry or forensic artifacts were not published alongside the write-up.Detection:
The source did not provide concrete detection signatures or sample IoCs. Observables to monitor (reported conceptually) include unusual download hosts surfaced for common software keywords, discrepancies between file checksums and vendor-published hashes, and new domains mimicking legitimate distribution sites. The article stops short of publishing detection rules.Mitigation and limitations:
The published material does not include vendor patches, CVEs, or defensive playbooks. The report emphasizes the attack vector (SEO poisoning) and documents BlackCat attribution but lacks technical artifacts for signature-based detection. This limits immediate operational response based on the article alone.References:
The source article is the primary reference cited by this summary. No CVE identifiers, IoCs, or sample hashes were released with that report.🔹 BlackCat #ALPHV #SEOpoisoning #malvertising #malware
🔗 Source: https://thehackernews.com/2026/01/black-cat-behind-seo-poisoning-malware.html
-
Fake Microsoft Teams and Google Meet downloads are being used to spread the #Oyster backdoor malware instead of the real apps via poisoned search results and malicious ads.
Read: https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/
#CyberSecurity #Malware #MicrosoftTeams #GoogleMeet #SEOpoisoning #Malvertising
-
Fake Microsoft Teams and Google Meet downloads are being used to spread the #Oyster backdoor malware instead of the real apps via poisoned search results and malicious ads.
Read: https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/
#CyberSecurity #Malware #MicrosoftTeams #GoogleMeet #SEOpoisoning #Malvertising
-
Fake Microsoft Teams and Google Meet downloads are being used to spread the #Oyster backdoor malware instead of the real apps via poisoned search results and malicious ads.
Read: https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/
#CyberSecurity #Malware #MicrosoftTeams #GoogleMeet #SEOpoisoning #Malvertising
-
Fake Microsoft Teams and Google Meet downloads are being used to spread the #Oyster backdoor malware instead of the real apps via poisoned search results and malicious ads.
Read: https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/
#CyberSecurity #Malware #MicrosoftTeams #GoogleMeet #SEOpoisoning #Malvertising
-
Fake Microsoft Teams and Google Meet downloads are being used to spread the #Oyster backdoor malware instead of the real apps via poisoned search results and malicious ads.
Read: https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/
#CyberSecurity #Malware #MicrosoftTeams #GoogleMeet #SEOpoisoning #Malvertising
-
Fake Microsoft Teams and Google Meet Downloads Spread Oyster Backdoor https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/ #MicrosoftTeams #CleanUpLoader #Cybersecurity #Malvertising #SEOPoisoning #CyberAttack #Broomstick #CyberProof #GoogleMeet #Security #backdoor #security #Malware #Oyster #WinSCP #PuTTY
-
Fake Microsoft Teams and Google Meet Downloads Spread Oyster Backdoor https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/ #MicrosoftTeams #CleanUpLoader #Cybersecurity #Malvertising #SEOPoisoning #CyberAttack #Broomstick #CyberProof #GoogleMeet #Security #backdoor #security #Malware #Oyster #WinSCP #PuTTY
-
Fake Microsoft Teams and Google Meet Downloads Spread Oyster Backdoor https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/ #MicrosoftTeams #CleanUpLoader #Cybersecurity #Malvertising #SEOPoisoning #CyberAttack #Broomstick #CyberProof #GoogleMeet #Security #backdoor #security #Malware #Oyster #WinSCP #PuTTY
-
Fake Microsoft Teams and Google Meet Downloads Spread Oyster Backdoor https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/ #MicrosoftTeams #CleanUpLoader #Cybersecurity #Malvertising #SEOPoisoning #CyberAttack #Broomstick #CyberProof #GoogleMeet #Security #backdoor #security #Malware #Oyster #WinSCP #PuTTY
-
Account Takeover Scams Surge as FBI Reports Over $262 Million in Losses https://thecyberexpress.com/account-takeover-fraud-sees-sharp-spike/ #InternetCrimeComplaintCenter(IC3) #phishingdomainsandwebsites #AccountTakeover(ATO)fraud #MultifactorAuthentication #TheCyberExpressNews #socialengineering #phishingwebsites #AccountTakeover #BlackFridaySale #TheCyberExpress #FirewallDaily #SEOpoisoning #Governance #CyberNews #ATOFraud #FBI
-
Account Takeover Scams Surge as FBI Reports Over $262 Million in Losses https://thecyberexpress.com/account-takeover-fraud-sees-sharp-spike/ #InternetCrimeComplaintCenter(IC3) #phishingdomainsandwebsites #AccountTakeover(ATO)fraud #MultifactorAuthentication #TheCyberExpressNews #socialengineering #phishingwebsites #AccountTakeover #BlackFridaySale #TheCyberExpress #FirewallDaily #SEOpoisoning #Governance #CyberNews #ATOFraud #FBI
-
Account Takeover Scams Surge as FBI Reports Over $262 Million in Losses https://thecyberexpress.com/account-takeover-fraud-sees-sharp-spike/ #InternetCrimeComplaintCenter(IC3) #phishingdomainsandwebsites #AccountTakeover(ATO)fraud #MultifactorAuthentication #TheCyberExpressNews #socialengineering #phishingwebsites #AccountTakeover #BlackFridaySale #TheCyberExpress #FirewallDaily #SEOpoisoning #Governance #CyberNews #ATOFraud #FBI
-
Account Takeover Scams Surge as FBI Reports Over $262 Million in Losses https://thecyberexpress.com/account-takeover-fraud-sees-sharp-spike/ #InternetCrimeComplaintCenter(IC3) #phishingdomainsandwebsites #AccountTakeover(ATO)fraud #MultifactorAuthentication #TheCyberExpressNews #socialengineering #phishingwebsites #AccountTakeover #BlackFridaySale #TheCyberExpress #FirewallDaily #SEOpoisoning #Governance #CyberNews #ATOFraud #FBI