Incidents

Search poisoning, again

Another day, another disaster, this time a big earthquake on Haiti, and once again, the bad guys are exploiting this subject to poison search results so that those looking for some news get lead to a page offering a rogue AV solution. We’re detecting this rogue software, and all its variants, as UDS:DangerousObject.Multi.Generic.

Our colleagues at Sunbelt Software have identified more than 50 search items used on search engines to lead the user to a malicious page. This isn’t exclusive to Google – Yahoo! results also are affected by the same trick:

Another interesting fact is you only get redirected to the malicious page offering the rogue AV if the referral link originated in a search engine page. If you try to directly access the URL, you’ll see a clean page:

Search poisoning, again

Search poisoning, again

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Reports

Crypto wasted: BlueNoroff’s ghost mirage of funding and jobs

Kaspersky GReAT experts dive deep into the BlueNoroff APT’s GhostCall and GhostHire campaigns. Extensive research detailing multiple malware chains targeting macOS, including a stealer suite, fake Zoom and Microsoft Teams clients and ChatGPT-enhanced images.

Mem3nt0 mori – The Hacking Team is back!

Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.

Mysterious Elephant: a growing threat

Kaspersky GReAT experts describe the latest Mysterious Elephant APT activity. The threat actor exfiltrates data related to WhatsApp and employs tools such as BabShell and MemLoader HidenDesk.