#seopoisoning — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #seopoisoning, aggregated by home.social.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Grand Theft Auto VI hype leads to malware
Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.
Pulse ID: 6aa18179c7eb1a5f0426ed7a
Pulse Link: https://otx.alienvault.com/pulse/6aa18179c7eb1a5f0426ed7a
Pulse Author: AlienVault
Created: 2026-09-09 15:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault
-
Grand Theft Auto VI hype leads to malware
Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.
Pulse ID: 6aa18179c7eb1a5f0426ed7a
Pulse Link: https://otx.alienvault.com/pulse/6aa18179c7eb1a5f0426ed7a
Pulse Author: AlienVault
Created: 2026-09-09 15:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault
-
Grand Theft Auto VI hype leads to malware
Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.
Pulse ID: 6aa18179c7eb1a5f0426ed7a
Pulse Link: https://otx.alienvault.com/pulse/6aa18179c7eb1a5f0426ed7a
Pulse Author: AlienVault
Created: 2026-09-09 15:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault
-
Grand Theft Auto VI hype leads to malware
Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.
Pulse ID: 6aa18179c7eb1a5f0426ed7a
Pulse Link: https://otx.alienvault.com/pulse/6aa18179c7eb1a5f0426ed7a
Pulse Author: AlienVault
Created: 2026-09-09 15:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault
-
Grand Theft Auto VI hype leads to malware
Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.
Pulse ID: 6aa18179c7eb1a5f0426ed7a
Pulse Link: https://otx.alienvault.com/pulse/6aa18179c7eb1a5f0426ed7a
Pulse Author: AlienVault
Created: 2026-09-09 15:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DCRat #Encryption #InfoSec #InfoStealer #Malware #NjRAT #OTX #OpenThreatExchange #RAT #RansomWare #Russia #SEOPoisoning #SocialMedia #bot #AlienVault
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.
Pulse ID: 6aa13e05864a561a7db38073
Pulse Link: https://otx.alienvault.com/pulse/6aa13e05864a561a7db38073
Pulse Author: AlienVault
Created: 2026-09-09 11:07:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.
Pulse ID: 6aa13e05864a561a7db38073
Pulse Link: https://otx.alienvault.com/pulse/6aa13e05864a561a7db38073
Pulse Author: AlienVault
Created: 2026-09-09 11:07:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.
Pulse ID: 6aa13e05864a561a7db38073
Pulse Link: https://otx.alienvault.com/pulse/6aa13e05864a561a7db38073
Pulse Author: AlienVault
Created: 2026-09-09 11:07:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.
Pulse ID: 6aa13e05864a561a7db38073
Pulse Link: https://otx.alienvault.com/pulse/6aa13e05864a561a7db38073
Pulse Author: AlienVault
Created: 2026-09-09 11:07:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.
Pulse ID: 6aa13e05864a561a7db38073
Pulse Link: https://otx.alienvault.com/pulse/6aa13e05864a561a7db38073
Pulse Author: AlienVault
Created: 2026-09-09 11:07:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault
-
BengalSEO Campaign Exploits Bing Search Results
Meet BengalSEO, a notorious group that's been secretly manipulating Bing search results with sneaky Black Hat SEO tactics since at least 2015, luring victims into malware and tech-support scams. They're masters of creating fake support pages that look legit, but actually serve as traps.
#Bengalseo #BlackHatSeo #SeoPoisoning #MalwareOperations #TechsupportScams
-
The Gambling Goblin campaign turns Brazilian government websites into an SEO weapon. Suspected Gambling Goblin operators push illicit gambling pages.
#GamblingGoblin #EarthBerberoka #SEOPoisoning #LinuxMalware #Cybercrime
-
The Gambling Goblin campaign turns Brazilian government websites into an SEO weapon. Suspected Gambling Goblin operators push illicit gambling pages.
#GamblingGoblin #EarthBerberoka #SEOPoisoning #LinuxMalware #Cybercrime
-
The Gambling Goblin campaign turns Brazilian government websites into an SEO weapon. Suspected Gambling Goblin operators push illicit gambling pages.
#GamblingGoblin #EarthBerberoka #SEOPoisoning #LinuxMalware #Cybercrime
-
The Gambling Goblin campaign turns Brazilian government websites into an SEO weapon. Suspected Gambling Goblin operators push illicit gambling pages.
#GamblingGoblin #EarthBerberoka #SEOPoisoning #LinuxMalware #Cybercrime
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault
-
BengalSEO Part 1: Anatomy of the Operation
In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...
Pulse ID: 6a9d1727de29faddfa1c2a91
Pulse Link: https://otx.alienvault.com/pulse/6a9d1727de29faddfa1c2a91
Pulse Author: AlienVault
Created: 2026-09-06 07:32:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault
-
WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns.
#WeedHack #Minecraft #Malware #SEOPoisoning #McAfee #InfoStealer #Gaming #Cybersecurity
http://securityonline.info/weedhack-minecraft-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns.
#WeedHack #Minecraft #Malware #SEOPoisoning #McAfee #InfoStealer #Gaming #Cybersecurity
http://securityonline.info/weedhack-minecraft-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns.
#WeedHack #Minecraft #Malware #SEOPoisoning #McAfee #InfoStealer #Gaming #Cybersecurity
http://securityonline.info/weedhack-minecraft-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns.
#WeedHack #Minecraft #Malware #SEOPoisoning #McAfee #InfoStealer #Gaming #Cybersecurity
http://securityonline.info/weedhack-minecraft-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns.
#WeedHack #Minecraft #Malware #SEOPoisoning #McAfee #InfoStealer #Gaming #Cybersecurity
http://securityonline.info/weedhack-minecraft-malware/?utm_source=mastodon&utm_medium=jetpack_social
-
Malware Spreads via Fake Minecraft Clients Using SEO Poisoning
Malware is sneaking its way into gamers' computers through fake Minecraft clients, using clever tricks like search engine manipulation and spreading malicious links on popular platforms like Discord and YouTube. Over 6,300 attempts to access these malicious sites have already been blocked by McAfee Labs.
#SeoPoisoning #MalwareOperations #Minecraft #Discord #Mediafire
-
https://www.alojapan.com/1516807/tokyo-police-warn-of-new-scam-tactic-search-results-falsely-displaying-not-a-scam-ai-summaries-also-contaminated-biggo-finance/ Tokyo Police Warn of New Scam Tactic: Search Results Falsely Displaying “Not a Scam,” AI Summaries Also Contaminated — BigGo Finance #AISummary #jade #news #SEOPoisoning #SiteSearchSpam #SNSTypeInvestmentFraud #Tokyo #TokyoMetropolitanPoliceDepartmentCyberCrimeCountermeasuresDivision #TokyoMetropolitanPoliceDepartmentCyberSecurityCountermeasuresDivision #TokyoNews #X(formerlyTwitter) #東京 #東京都 The Tokyo Metropolitan Police Departme
-
https://www.alojapan.com/1516807/tokyo-police-warn-of-new-scam-tactic-search-results-falsely-displaying-not-a-scam-ai-summaries-also-contaminated-biggo-finance/ Tokyo Police Warn of New Scam Tactic: Search Results Falsely Displaying “Not a Scam,” AI Summaries Also Contaminated — BigGo Finance #AISummary #jade #news #SEOPoisoning #SiteSearchSpam #SNSTypeInvestmentFraud #Tokyo #TokyoMetropolitanPoliceDepartmentCyberCrimeCountermeasuresDivision #TokyoMetropolitanPoliceDepartmentCyberSecurityCountermeasuresDivision #TokyoNews #X(formerlyTwitter) #東京 #東京都 The Tokyo Metropolitan Police Departme
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
Fake Anthropic websites are being used to target #ClaudeCode users with a fileless infostealer campaign that steals browser credentials and evades detection.
Read: https://hackread.com/fake-anthropic-sites-fileless-infostealer-claude-code-users/
#CyberSecurity #Anthropic #Claude #AI #Infostealer #SEOPoisoning
-
GPU mining malware spreads via SEO poisoning and AI chatbot manipulation
Beware of a sneaky malware that's spreading through manipulated AI chatbot responses and search engine poisoning, tricking users into downloading GPU mining malware. Victims unknowingly stumble upon malicious links while searching for popular software or getting recommendations from AI assistants.
#SeoPoisoning #GpuMiningMalware #AiChatbotManipulation #MalwareOperations #EmergingThreats
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
📣🚨 Cybercriminals are using SEO poisoning and fake Gemini and Claude installer sites to infect developers with fileless malware, steal credentials, hijack sessions, and infiltrate corporate networks.
Read more: https://hackread.com/trojan-gemini-claude-installers-developers-seo-poisoning/
-
Iranian Hackers Deploy AI-Backed MiniFast Backdoor via Phishing and SEO Poisoning
Iranian hackers have escalated their cyber attacks, leveraging AI-powered tools to craft malware and targeting key sectors like aviation, defense, and telecommunications across the US, Europe, and the Middle East. Their sophisticated tactics, including phishing and SEO poisoning, have allowed them to spy on…
#IranianHackers #AibackedMalware #MinifastBackdoor #SeoPoisoning #Phishing
-
Iran-Linked Hackers Target US Aviation with Sophisticated Phishing and SEO Poisoning
Meet Nimbus Manticore, an Iran-linked hacking group that's back with a vengeance, using clever phishing and SEO poisoning tactics to target the US aviation industry in a series of sophisticated attacks. Their latest campaign, which ran from February to April 2026, marked a significant expansion into aviation,…
#IranlinkedHackers #UsAviation #Phishing #SeoPoisoning #OperationEpicFury
-
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Kong RAT: la nuova campagna di SEO poisoning con dropper NativeAOT .NET 10 che prende di mira gli sviluppatori cinesi
eSentire TRU ha documentato Kong RAT, un impianto modulare distribuito via installer contraffatti di FinalShell, Xshell, QuickQ e Clash. La catena a sei stadi sfrutta un dropper NativeAOT in .NET 10 — non analizzabile con i tool CLR classici — DLL sideloading su rc.exe, PEB masquerading come explorer.exe e shellcode eseguito via callback EnumWindows. Un salto di qualita rispetto alle campagne Gh0st/kkRAT. -
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.
IOCs:
000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"
-
"SEO Poisoning - Mon site se fait attaquer depuis un an"