home.social

#seopoisoning — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #seopoisoning, aggregated by home.social.

fetched live
  1. Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/pp

    Pulse ID: 6aa7b6b92f301028ac1edc54
    Pulse Link: otx.alienvault.com/pulse/6aa7b
    Pulse Author: CyberHunter_NL
    Created: 2026-09-14 08:56:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Deploy #SEOPoisoning #YouTube #OTX #CyberHunter_NL

  2. Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/pp

    Pulse ID: 6aa7b6b92f301028ac1edc54
    Pulse Link: otx.alienvault.com/pulse/6aa7b
    Pulse Author: CyberHunter_NL
    Created: 2026-09-14 08:56:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Deploy #SEOPoisoning #YouTube #OTX #CyberHunter_NL

  3. Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/pp

    Pulse ID: 6aa7b6b92f301028ac1edc54
    Pulse Link: otx.alienvault.com/pulse/6aa7b
    Pulse Author: CyberHunter_NL
    Created: 2026-09-14 08:56:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Deploy #SEOPoisoning #YouTube #OTX #CyberHunter_NL

  4. Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/pp

    Pulse ID: 6aa7b6b92f301028ac1edc54
    Pulse Link: otx.alienvault.com/pulse/6aa7b
    Pulse Author: CyberHunter_NL
    Created: 2026-09-14 08:56:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chrome #Deploy #SEOPoisoning #YouTube #OTX #CyberHunter_NL

  5. Grand Theft Auto VI hype leads to malware

    Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

    Pulse ID: 6aa18179c7eb1a5f0426ed7a
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault

  6. Grand Theft Auto VI hype leads to malware

    Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

    Pulse ID: 6aa18179c7eb1a5f0426ed7a
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault

  7. Grand Theft Auto VI hype leads to malware

    Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

    Pulse ID: 6aa18179c7eb1a5f0426ed7a
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault

  8. Grand Theft Auto VI hype leads to malware

    Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

    Pulse ID: 6aa18179c7eb1a5f0426ed7a
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault

  9. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

    A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.

    Pulse ID: 6aa13e05864a561a7db38073
    Pulse Link: otx.alienvault.com/pulse/6aa13
    Pulse Author: AlienVault
    Created: 2026-09-09 11:07:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault

  10. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

    A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.

    Pulse ID: 6aa13e05864a561a7db38073
    Pulse Link: otx.alienvault.com/pulse/6aa13
    Pulse Author: AlienVault
    Created: 2026-09-09 11:07:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault

  11. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

    A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.

    Pulse ID: 6aa13e05864a561a7db38073
    Pulse Link: otx.alienvault.com/pulse/6aa13
    Pulse Author: AlienVault
    Created: 2026-09-09 11:07:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault

  12. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

    A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.

    Pulse ID: 6aa13e05864a561a7db38073
    Pulse Link: otx.alienvault.com/pulse/6aa13
    Pulse Author: AlienVault
    Created: 2026-09-09 11:07:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault

  13. BengalSEO Campaign Exploits Bing Search Results

    Meet BengalSEO, a notorious group that's been secretly manipulating Bing search results with sneaky Black Hat SEO tactics since at least 2015, luring victims into malware and tech-support scams. They're masters of creating fake support pages that look legit, but actually serve as traps.

    osintsights.com/bengalseo-camp

    #Bengalseo #BlackHatSeo #SeoPoisoning #MalwareOperations #TechsupportScams

  14. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault

  15. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault

  16. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault

  17. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault

  18. Malware Spreads via Fake Minecraft Clients Using SEO Poisoning

    Malware is sneaking its way into gamers' computers through fake Minecraft clients, using clever tricks like search engine manipulation and spreading malicious links on popular platforms like Discord and YouTube. Over 6,300 attempts to access these malicious sites have already been blocked by McAfee Labs.

    osintsights.com/malware-spread

    #SeoPoisoning #MalwareOperations #Minecraft #Discord #Mediafire

  19. GPU mining malware spreads via SEO poisoning and AI chatbot manipulation

    Beware of a sneaky malware that's spreading through manipulated AI chatbot responses and search engine poisoning, tricking users into downloading GPU mining malware. Victims unknowingly stumble upon malicious links while searching for popular software or getting recommendations from AI assistants.

    osintsights.com/gpu-mining-mal

    #SeoPoisoning #GpuMiningMalware #AiChatbotManipulation #MalwareOperations #EmergingThreats

  20. 📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.

    Read more: hackread.com/trojan-gemini-cla

    #CyberSecurity #Malware #SEOpoisoning #AI #Gemini #Claude

  21. 📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.

    Read more: hackread.com/trojan-gemini-cla

    #CyberSecurity #Malware #SEOpoisoning #AI #Gemini #Claude

  22. 📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.

    Read more: hackread.com/trojan-gemini-cla

    #CyberSecurity #Malware #SEOpoisoning #AI #Gemini #Claude

  23. 📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.

    Read more: hackread.com/trojan-gemini-cla

    #CyberSecurity #Malware #SEOpoisoning #AI #Gemini #Claude

  24. Iranian Hackers Deploy AI-Backed MiniFast Backdoor via Phishing and SEO Poisoning

    Iranian hackers have escalated their cyber attacks, leveraging AI-powered tools to craft malware and targeting key sectors like aviation, defense, and telecommunications across the US, Europe, and the Middle East. Their sophisticated tactics, including phishing and SEO poisoning, have allowed them to spy on…

    osintsights.com/iranian-hacker

    #IranianHackers #AibackedMalware #MinifastBackdoor #SeoPoisoning #Phishing

  25. Iran-Linked Hackers Target US Aviation with Sophisticated Phishing and SEO Poisoning

    Meet Nimbus Manticore, an Iran-linked hacking group that's back with a vengeance, using clever phishing and SEO poisoning tactics to target the US aviation industry in a series of sophisticated attacks. Their latest campaign, which ran from February to April 2026, marked a significant expansion into aviation,…

    osintsights.com/iran-linked-ha

    #IranlinkedHackers #UsAviation #Phishing #SeoPoisoning #OperationEpicFury

  26. Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi

    eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT.

    insicurezzadigitale.com/kong-r

  27. Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi

    eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT.

    insicurezzadigitale.com/kong-r

  28. Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi

    eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT.

    insicurezzadigitale.com/kong-r

  29. Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi

    eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT.

    insicurezzadigitale.com/kong-r

  30. Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.

    IOCs:
    000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning

  31. Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.

    IOCs:
    000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning

  32. Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.

    IOCs:
    000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning

  33. Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.

    IOCs:
    000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning

  34. 🎯 Threat Intelligence
    ===================

    Executive summary: Recent reporting attributes an SEO poisoning campaign to the BlackCat/ALPHV threat actor, describing manipulation of search results for popular software to steer victims to malicious download pages. The source links the activity to a coordinated effort to replace legitimate installers or mirrors with attacker-controlled payloads. The article does not publish sample IoCs, hashes, or C2 addresses.

    Technical details:
    • Reported technique: SEO poisoning (search-result manipulation) to surface malicious pages for popular software keywords.
    • Delivery vector described: attacker-controlled download pages or mirrors that host malicious installers or archived payloads instead of legitimate binaries.
    • Payloads: the source indicates distribution of malware via these fake downloads, but does not enumerate specific families, hashes, or signatures in the published material.

    🔹 Attack Chain Analysis
    • Initial Access (Search poisoning): Malicious pages are promoted or optimized to appear in search results for targeted software queries.
    • Delivery (Malicious download pages): Victim navigates to a malicious page presented as a legitimate download source.
    • Execution (User installs): Victim executes the downloaded installer or archive, triggering payload execution.
    • Post-execution (Payload activity): Article reports general payload delivery but does not detail post-execution TTPs or ransom/logical behavior tied to BlackCat.

    Analysis:
    The reporting highlights the operational focus on search-engine manipulation rather than email or exploit-based vectors. This approach targets users seeking popular software and relies on social engineering and deceptive hosting. Attribution to BlackCat/ALPHV is asserted by the source; supporting telemetry or forensic artifacts were not published alongside the write-up.

    Detection:
    The source did not provide concrete detection signatures or sample IoCs. Observables to monitor (reported conceptually) include unusual download hosts surfaced for common software keywords, discrepancies between file checksums and vendor-published hashes, and new domains mimicking legitimate distribution sites. The article stops short of publishing detection rules.

    Mitigation and limitations:
    The published material does not include vendor patches, CVEs, or defensive playbooks. The report emphasizes the attack vector (SEO poisoning) and documents BlackCat attribution but lacks technical artifacts for signature-based detection. This limits immediate operational response based on the article alone.

    References:
    The source article is the primary reference cited by this summary. No CVE identifiers, IoCs, or sample hashes were released with that report.

    🔹 BlackCat #ALPHV #SEOpoisoning #malvertising #malware

    🔗 Source: thehackernews.com/2026/01/blac

  35. Fake Microsoft Teams and Google Meet downloads are being used to spread the #Oyster backdoor malware instead of the real apps via poisoned search results and malicious ads.

    Read: hackread.com/fake-microsoft-te

    #CyberSecurity #Malware #MicrosoftTeams #GoogleMeet #SEOpoisoning #Malvertising

  36. Fake Microsoft Teams and Google Meet downloads are being used to spread the #Oyster backdoor malware instead of the real apps via poisoned search results and malicious ads.

    Read: hackread.com/fake-microsoft-te

    #CyberSecurity #Malware #MicrosoftTeams #GoogleMeet #SEOpoisoning #Malvertising

  37. Fake Microsoft Teams and Google Meet downloads are being used to spread the #Oyster backdoor malware instead of the real apps via poisoned search results and malicious ads.

    Read: hackread.com/fake-microsoft-te

    #CyberSecurity #Malware #MicrosoftTeams #GoogleMeet #SEOpoisoning #Malvertising