home.social

#seopoisoning — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #seopoisoning, aggregated by home.social.

fetched live
  1. Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/pp

    Pulse ID: 6aa7b6b92f301028ac1edc54
    Pulse Link: otx.alienvault.com/pulse/6aa7b
    Pulse Author: CyberHunter_NL
    Created: 2026-09-14 08:56:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Deploy #SEOPoisoning #YouTube #OTX #CyberHunter_NL

  2. Grand Theft Auto VI hype leads to malware

    Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

    Pulse ID: 6aa18179c7eb1a5f0426ed7a
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault

  3. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

    A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.

    Pulse ID: 6aa13e05864a561a7db38073
    Pulse Link: otx.alienvault.com/pulse/6aa13
    Pulse Author: AlienVault
    Created: 2026-09-09 11:07:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault

  4. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault

  5. Fake Anthropic websites are being used to target users with a fileless infostealer campaign that steals browser credentials and evades detection.

    Read: hackread.com/fake-anthropic-si

  6. 📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.

    Read more: hackread.com/trojan-gemini-cla

  7. Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi

    eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT.

    insicurezzadigitale.com/kong-r

  8. Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.

    IOCs:
    000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning

  9. Fake Microsoft Teams and Google Meet downloads are being used to spread the backdoor malware instead of the real apps via poisoned search results and malicious ads.

    Read: hackread.com/fake-microsoft-te

  10. Attackers are turning Google results into malware delivery systems, using fake software installers and sponsored ads to plant backdoors inside organizations. In this episode of Cyberside Chats, Sherri Davidoff and Matt Durrin unpack the latest SEO poisoning and malvertising research and share actionable defenses.

    From ad blocking to safer browsing habits, learn how to protect your team from the poisoned web. Listen to the podcast: chatcyberside.com/e/search-res

    Watch the video: youtu.be/xKKA1ikoZ-4

    #SEOpoisoning #Malvertising #Cybersecurity #Software #Advertising #Phishing #PoisonedWeb

  11. 🚨 SEO poisoning alert! Watch what you download as users are being targeted with fake search results that lead to installers containing Hiddengh0st and Winos malware

    Read: hackread.com/seo-poisoning-att

  12. On parlait la semaine passée des faux Keepass poussés via publicité Google malveillante (malvertising)...

    Voici un autre exemple tout chaud, spotté par BleepingComputer : une fausse version de l'outil open-source Zenmap (Nmap), ainsi qu’un faux WinMTR, sont utilisés pour livrer le malware Bumblebee.
    ⬇️
    Cette fois via "SEO poisoning" sur Google & Bing. (C’est une technique qui consiste à manipuler les résultats des moteurs de recherche pour faire apparaître en tête de page de faux sites — souvent très bien imités — afin de piéger les internautes)
    Ici, les attaquants ont cloné les pages de téléchargement de Zenmap (l’interface graphique de Nmap) et WinMTR (outil de traceroute réseau), deux utilitaires très utilisés par les pros de l’IT.

    Les sites en question (zenmap[.]pro, winmtr[.]org) semblaient parfaitement légitimes.
    Mais les installeurs .msi proposés contiennent en réalité un loader du malware Bumblebee, furtif et non détecté par la majorité des antivirus (VirusTotal donne quasi tout vert).

    Ce que fait Bumblebee :

    • Installe l’outil promis… mais avec une DLL infectée.

    • Ouvre une backdoor : profilage de la victime, puis possible déploiement de ransomware, infostealers, ou d’autres malwares.

    • Idéal pour une attaque en deux temps (initial access + mouvement latéral).

    [Source]
    ⬇️
    📰 "Fake Zenmap. WinMRT sites target IT staff with Bumblebee malware — BleepingComputer"
    👇
    bleepingcomputer.com/news/secu

    #SEOpoisoning #Bumblebee #Nmap #cyberveille

  13. Por favor, expandir lo máximo posible entre vuestros conocidos el mensaje de que no copien nunca nada desde el navegador tras ejecutar Windows + R porque te lo dice un pop-up. No. Caca. Windows + R y después Control + V no, estás ejecutando un comando de powershell malicioso.

    Un problema está siendo esto de los loaders con el Click-Fix, se está extendiendo como la pólvora este vector de ataque. Yo creo que los grupos criminales no se han puesto con esto antes porque es difícil entrar así, necesitas la complicidad activa del usuario, cómo va ser buena idea decirle a la gente "oye, ábrete el ejecutor de comandos y pega este comando que te doy y dale a enter para ejecutarlo en tu equipo", no es como el engaño fácil del click del phishing. Pero oye, quién iba a decir que todo el mundo sigue las instrucciones y lo ejecuta.

    Estamos teniendo una oleada de esta técnica, por increíble que parezca.

    #ciberseguridad #seopoisoning #clickfix