Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
BlackCat Brings Bad Luck Using Google Ads
Facebook   X   LinkedIn   Email

BlackCat Brings Bad Luck Using Google Ads

December 17, 2023

Trend Micro researchers recently identified that a notorious ransomware group is using various malvertising tricks within Google Ads to distribute fake WinSCP installers. They are using Targeted Attack Detection (TAD) service. What is that, you say? This means that if you click on an infected ad that you see on your webpage, your network could get a bad case of cat scratch fever. Let’s break it down a bit more.

Google Ads are all over the internet. When they are clicked, Google helps boost sales for the advertisers by targeting audiences with ads that are more relevant to them. You know that time you were emailing a friend about a particular product and suddenly an ad for it showed up on the side of the webpage you were viewing? That’s Google working its technological magic and helping drive traffic to its advertisers’ websites.

In this case, threat actors, particularly the Blackcat Ransomware group (also known as ALPHV) are taking advantage of this type of ad display to launch malvertising campaigns against those looking for the WinSCP product. They are using WinSCP as their keywords to drive traffic to their malicious websites. WinSCP is a free file manager product that supports various file types. They exploit keyword hijacking to trap search engine users with malicious ads and distribute malware right under their noses.

Keyword hijacking, or sometimes called brand hijacking or ad hijacking, happens when one company uses another company’s keywords or brand name in a Google AdWords pay-per-click campaign. For example, you search for “Rayban Sunglasses.” You expect to go to websites that sell actual Rayban sunglasses. With keyword hijacking, cybercriminals put up their own websites using those keywords and drive traffic to their sites. So, you may get some legitimate places to buy the sunglasses, the criminals do whatever they can to get their page at the top of the list, where users are more likely to click.

In this case, those landing on the malicious page are sent to another site that is a cloned one of the legitimate WinSCP website. There is a download link that will install all kinds of tools that can disable anti-virus solutions and allow the group access to the system.

Fortunately, there are ways to avoid this.

Mitigation Techniques:

  • Awareness that this is possible and is actively happening will go a long way to protecting all systems. Educating employees and others about identifying and avoiding potential phishing attacks is key.
  • Keep an eye on logs and activities happening within the network. Determine what “regular” day-to-day traffic is on your network and watch for anomalies.
  • Have an incident response plan in place and keep it updated. Follow it if the time comes.

Wanted! Nighttime Bandit Steals PII Using Google Ads

Scams & Phishing

Wanted! Nighttime Bandit Steals PII Using Google Ads

Users that are searching for popular software have recently become the targets of malvertising which leverages Google Ads to install Trojan versions of Raccoon Stealer and Vidar. These malware versions are sneakily hidden within Google advertising…you know; those advertisements you see on the side of your browser window or plastered all over social media. This bandit, if clicked, will then proceed to install malware on your device. Guardio Labs has dubbed this "MasquerAd." Clever, isn't it? READ FULL STORY

What Is The Price Of The Average Data Breach? Awareness Training May Be The Key To Prevention

Corporate Security

What Is The Price Of The Average Data Breach? Awareness Training May Be The Key To Prevention

The price tag for a data breach went up this year, way up. Although the global average cost per breach is now a whopping $3.86 million, the average cost for the U.S. is $8.64 million, the most expensive in the world. IBM’s “2020 Cost of a Data Breach” report sheds light on the growing financial costs of a breach, having increased by more than $2 million each over the past two years. The report also finds employees are the costly reason behind enterprise data breaches. READ FULL STORY

Malvertising Campaign Tracks Down Our Payment Card Info Using USPS

Scams & Phishing

Malvertising Campaign Tracks Down Our Payment Card Info Using USPS

The fewer items we receive via the U.S. Postal Service (USPS) these days, the more excited we get when we do get packages delivered by the service. Well, cybercriminals are always up to something and now they are trying to take away our excitement when we go get the mail. Researchers at Malwarebytes provided a detailed process of how a recently discovered malvertising campaign works and helps criminals track down our payment card information for their own use. READ FULL STORY

Home Depot Ads Provide Unhelpful Tech Support

Scams & Phishing

Home Depot Ads Provide Unhelpful Tech Support

During quarantine, a lot of people decided they will do home improvement projects. I can attest, as I think my neighbor completely rebuilt his house over the past year; it’s a constant roar of power tools over there, every day. He’s not alone. Many people head over to Home Depot to get all of those materials to finish those do-it-yourself projects, but may want to purchase online and pickup, or just have it shipped. Easy enough to do and hackers are already on top of it. READ FULL STORY

Fake Update Ads Steal Your Passwords

Scams & Phishing

Fake Update Ads Steal Your Passwords

We know the cyber-cheats are always out there using every trick in the book to steal our money, identities and whatever else they can get their hands on. So, the next time you’re alerted to a software update, especially one appearing in an online ad, it’s time to step back and take a closer look before tapping “Download.” A latest malvertising campaign lures users into downloading a fake software update. The now custom, improved malware is being used at this very moment and surely will continue doing damage well into the new year. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...