#seopoisoning — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #seopoisoning, aggregated by home.social.
-
China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business
Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a for-profit cryptocurrency fraud business administered from the same control panel. Operating as a small development team with role-based access controls and documented roadmaps, the group recorded over one million implant check-ins, 580,000+ stolen browser cookies, and 2,300+ exfiltrated emails between February and May 2026. Espionage attacks targeted government entities in the Middle East, Southeast Asia, and South Asia with confirmed intrusions. The group deploys the Antino backdoor, a malicious Chrome/Firefox extension called 'PDF Viewer,' and a Linux implant named ClientKing targeting servers and routers. The financially motivated arm operates as a registered Hunan company running industrial-scale SEO poisoning funneling Chinese-speaking victims to fake cryptocurrency exchange sites.
Pulse ID: 6a7da6cbe879002fadce7e53
Pulse Link: https://otx.alienvault.com/pulse/6a7da6cbe879002fadce7e53
Pulse Author: AlienVault
Created: 2026-08-13 11:13:15Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Chrome #Cookies #CyberSecurity #Email #Espionage #FireFox #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #bot #cryptocurrency #AlienVault
-
APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Jewelbug is a China-based hackers-for-hire group conducting parallel operations: espionage campaigns targeting government ministries and militaries across the Middle East, Southeast Asia, and South Asia, alongside a cryptocurrency fraud business. Both missions operate from a single control panel called XG-Web, a browser-centric remote-access framework. The group's main implant is the Antino backdoor, complemented by a malicious browser extension disguised as 'PDF Viewer' and the ClientKing Linux/router implant. Their largest operation compromised over 15 government webmail tenants in a Middle Eastern country through a single watering-hole attack. The victim database recorded over one million implant check-ins and 580,000 stolen browser cookies within three months. Operators are linked to a registered Hunan Province company, with infrastructure supporting both espionage and commercial SEO poisoning operations targeting Chinese-speaking cryptocurrency users.
Pulse ID: 6a7daa9c80273555f3d3ccd1
Pulse Link: https://otx.alienvault.com/pulse/6a7daa9c80273555f3d3ccd1
Pulse Author: AlienVault
Created: 2026-08-13 11:29:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Browser #China #Chinese #Cookies #CyberSecurity #Espionage #Government #InfoSec #Linux #MiddleEast #OTX #OpenThreatExchange #PDF #RAT #SEOPoisoning #SouthAsia #Webmail #bot #cryptocurrency #AlienVault
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"
-
Fake Microsoft Teams and Google Meet downloads are being used to spread the #Oyster backdoor malware instead of the real apps via poisoned search results and malicious ads.
Read: https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/
#CyberSecurity #Malware #MicrosoftTeams #GoogleMeet #SEOpoisoning #Malvertising
-
Fake Microsoft Teams and Google Meet Downloads Spread Oyster Backdoor https://hackread.com/fake-microsoft-teams-google-meet-download-oyster-backdoor/ #MicrosoftTeams #CleanUpLoader #Cybersecurity #Malvertising #SEOPoisoning #CyberAttack #Broomstick #CyberProof #GoogleMeet #Security #backdoor #security #Malware #Oyster #WinSCP #PuTTY
-
Account Takeover Scams Surge as FBI Reports Over $262 Million in Losses https://thecyberexpress.com/account-takeover-fraud-sees-sharp-spike/ #InternetCrimeComplaintCenter(IC3) #phishingdomainsandwebsites #AccountTakeover(ATO)fraud #MultifactorAuthentication #TheCyberExpressNews #socialengineering #phishingwebsites #AccountTakeover #BlackFridaySale #TheCyberExpress #FirewallDaily #SEOpoisoning #Governance #CyberNews #ATOFraud #FBI
-
SEO Poisoning Attack Hits Windows Users With Hiddengh0st and Winos Malware https://hackread.com/seo-poisoning-attack-windows-hiddengh0st-winos-malware/ #ScamsandFraud #Cybersecurity #SEOPoisoning #CyberAttack #Hiddengh0st #Security #Malware #China #Fraud #Winos #Scam
-
🚨 SEO poisoning alert! Watch what you download as #Windows users are being targeted with fake search results that lead to installers containing Hiddengh0st and Winos malware
Read: https://hackread.com/seo-poisoning-attack-windows-hiddengh0st-winos-malware/
-
Hackers Are Poisoning Google Search Results for AI Tools to Deliver Infostealer Malware https://thecyberexpress.com/poisoning-google-search-results-infostealers/ #GoogleSearchResults #TheCyberExpressNews #LummaInfostealer #VidarInfostealer #TheCyberExpress #FirewallDaily #SEOpoisoning #CyberNews #AItools
-
Hacklink Market Linked to SEO Poisoning Attacks in Google Results – Source:hackread.com https://ciso2ciso.com/hacklink-market-linked-to-seo-poisoning-attacks-in-google-results-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #ScamsandFraud #PhishingScam #SEOPoisoning #CyberAttack #CyberCrime #Hacklink #Hackread #malware #Google #Fraud #Scam
-
Hacklink Market Linked to SEO Poisoning Attacks in Google Results https://hackread.com/hacklink-market-seo-poisoning-attacks-google-results/ #ScamsandFraud #Cybersecurity #PhishingScam #SEOPoisoning #CyberAttack #CyberCrime #Hacklink #Malware #Google #Fraud #Scam
-
Cybercriminals are abusing #Google's search rankings using a black market service called #Hacklink, facilitating much more than #SEOPoisoning.
Read: https://hackread.com/hacklink-market-seo-poisoning-attacks-google-results/
-
On parlait la semaine passée des faux Keepass poussés via publicité Google malveillante (malvertising)...
Voici un autre exemple tout chaud, spotté par BleepingComputer : une fausse version de l'outil open-source Zenmap (Nmap), ainsi qu’un faux WinMTR, sont utilisés pour livrer le malware Bumblebee.
⬇️
Cette fois via "SEO poisoning" sur Google & Bing. (C’est une technique qui consiste à manipuler les résultats des moteurs de recherche pour faire apparaître en tête de page de faux sites — souvent très bien imités — afin de piéger les internautes)
Ici, les attaquants ont cloné les pages de téléchargement de Zenmap (l’interface graphique de Nmap) et WinMTR (outil de traceroute réseau), deux utilitaires très utilisés par les pros de l’IT.Les sites en question (zenmap[.]pro, winmtr[.]org) semblaient parfaitement légitimes.
Mais les installeurs .msi proposés contiennent en réalité un loader du malware Bumblebee, furtif et non détecté par la majorité des antivirus (VirusTotal donne quasi tout vert).Ce que fait Bumblebee :
Installe l’outil promis… mais avec une DLL infectée.
Ouvre une backdoor : profilage de la victime, puis possible déploiement de ransomware, infostealers, ou d’autres malwares.
Idéal pour une attaque en deux temps (initial access + mouvement latéral).
[Source]
⬇️
📰 "Fake Zenmap. WinMRT sites target IT staff with Bumblebee malware — BleepingComputer"
👇
https://www.bleepingcomputer.com/news/security/fake-zenmap-winmrt-sites-target-it-staff-with-bumblebee-malware/ -
New SEO Poisoning Campaign Targeting IT Admins With Malware https://hackread.com/seo-poisoning-campaign-hit-it-admins-with-malware/ #SocialEngineering #Cybersecurity #Vulnerability #CyberAttacks #SEOPoisoning #CyberAttack #Security #Malware #Scam
-
New SEO Poisoning Campaign Targeting IT Admins With Malware – Source:hackread.com https://ciso2ciso.com/new-seo-poisoning-campaign-targeting-it-admins-with-malware-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #SocialEngineering #cybersecurity #Vulnerability #CyberAttacks #SEOPoisoning #CyberAttack #Hackread #security #malware #Scam
-
Employee Monitoring Software Kickidler Weaponized in Sophisticated Ransomware Attacks
#Cybersecurity #Ransomware #Kickidler #Spyware #Infosec #VMware #ThreatIntel #DataBreach #SEOpoisoning
-
Fake DeepSeek AI Installers, Websites, and Apps Spreading Malware https://hackread.com/fake-deepseek-ai-installers-websites-apps-malware/ #ArtificialIntelligence #ScamsandFraud #Cybersecurity #SEOPoisoning #DeepSeekR1 #Security #DeepSeek #Malware #Chatbot #Fraud #Scam #AI
-
Over 350 High-Profile Websites Hit by 360XSS Attack https://hackread.com/over-350-high-profile-websites-hit-by-360xss-attack/ #Cybersecurity #Vulnerability #CyberAttacks #SEOPoisoning #CyberAttack #Security #360XSS #Krpano #XSS
-
Por favor, expandir lo máximo posible entre vuestros conocidos el mensaje de que no copien nunca nada desde el navegador tras ejecutar Windows + R porque te lo dice un pop-up. No. Caca. Windows + R y después Control + V no, estás ejecutando un comando de powershell malicioso.
Un problema está siendo esto de los loaders con el Click-Fix, se está extendiendo como la pólvora este vector de ataque. Yo creo que los grupos criminales no se han puesto con esto antes porque es difícil entrar así, necesitas la complicidad activa del usuario, cómo va ser buena idea decirle a la gente "oye, ábrete el ejecutor de comandos y pega este comando que te doy y dale a enter para ejecutarlo en tu equipo", no es como el engaño fácil del click del phishing. Pero oye, quién iba a decir que todo el mundo sigue las instrucciones y lo ejecuta.
Estamos teniendo una oleada de esta técnica, por increíble que parezca.
-
SEO Poisoning: How Cybercriminals Are Turning Search Engines into Traps https://hackread.com/seo-poisoning-how-scammers-search-engines-traps/ #Cybersecurity #Searchengine #SEOPoisoning #Technology #Security #Google #Scam #SEO
-
Cybercriminals Launch SEO Poisoning Attack to Lure Shoppers to Fake Online Stores https://gbhackers.com/seo-poisoning-fake-sites/ #FakeEcommerceSites #CyberSecurityNews #SEOPoisoning #BlackhatSEO #CyberCrime #Malware
-
Gootloader Malware Targets Bengal Cat Lovers By Poisoning Google Search Results https://cybersecuritynews.com/gootloader-targets-bengal-cat-lovers/ #BengalCatLoversTargeted #CyberSecurityNews #GootloaderMalware #SEOPoisoning #CyberAttack #Malware
-
Are You Googling This? You Could Be Walking Into a Cyber Trap https://thecyberexpress.com/seo-poisoning-australia/ #AreBengalCatslegalinAustralia #SEOPoisoningAttacks #TheCyberExpressNews #TheCyberExpress #FirewallDaily #MarketReports #GoogleSearch #SEOpoisoning #MalwareNews #HackerNews #GootLoader #CyberNews #Australia #Sophos
-
Chinese DragonRank Hackers Exploit Global Windows Servers in SEO Fraud https://hackread.com/chinese-dragonrank-hackers-windows-servers-seo-fraud/ #Cybersecurity #CyberAttacks #SEOPoisoning #CyberAttack #DragonRank #Security #Malware #Windows #China
-
Fake GlobalProtect VPN Downloads Used to Spread WikiLoader Malware https://hackread.com/fake-globalprotect-vpn-downloads-wikiloader-malware/ #Cybersecurity #GlobalProtect #SEOPoisoning #CyberAttack #WailingCrab #WikiLoader #Security #Malware #Scam #SEO #VPN