Bad Actors Using Google & Bing Advertising Networks to Spread Malware
Bad actors are using Google and Bing’s advertising networks to spread malware in an effort “to compromise business networks.”
Security firm Sophos made the discovery, dubbing the malware campaign “Nitrogen.” Sophos says Nitrogen “is a primarily opportunistic attack campaign abusing Google and Bing ads to target users seeking certain IT tools, with the goal of gaining access to enterprise environments to deploy second-stage attack tools such as Cobalt Strike.”
The company goes on to describe how the malware campaign works:
The observed infection chain starts with malvertising via Google and Bing Ads to lure users to compromised WordPress sites and phishing pages impersonating popular software distribution sites, where they are tricked into downloading trojanized ISO installers.
When downloaded, the installers sideload the malicious NitrogenInstaller DLL containing a legitimate software application bundled with a malicious Python execution environment. The Python package uses Dynamic Link Library (DLL) preloading to execute the malicious NitrogenStager file, which connects to the threat actor’s command-and-control (C2) servers to drop both a Meterpreter shell and Cobalt Strike Beacons onto the targeted system. Throughout the infection chain, the threat actors use uncommon export forwarding and DLL preloading techniques to mask their malicious activity and hinder analysis.
The infection chain involves multiple stages and components, which are still under analysis at this writing.
Cisco AnyConnect, WinSCP, and TreeSize downloads are three that are specifically being targeted by the malware campaign.
Sophos recommends taking basic steps to avoid the malware, such as not clicking download links in search advertisements, using an ad blocker to hide such ads altogether, and making sure downloaded files have the appropriate file extension.
Of course, the report raises significant questions about the security measures — or lack thereof — that Google and Bing’s advertising networks offer.
-
Amazon Is Shutting DPReview.comAI's Disruption of SEO: Adapting to a New Era of Search and User BehaviorAmazon Unveils GameGoogle Cracking Down On 'Site Reputation Abuse'Google Shows Social Profiles On SERPsGoogle Cracking Down On 'Site Reputation Abuse'Google Warns Advertisers Could Lose Customer Match Access for ViolationsX Is Back in Brazil in Major Loss for Free SpeechJay Z and Beyonce May Have Pulled 'A Jedi Mind Trick' On UsGoogle Agrees to Tackle Fake Reviews In the UK
Next article:Here's A Look At Which E
- ·After 20 Years, Yahoo Directory Gets The Axe
- ·X Inches Toward Profitability: Investor Optimism Grows Amid Debt Sale and AI Integration
- ·SEC Targets Elon Musk for Sanctions, Sparking Claims of Political Bias
- ·Use This Trick to Avoid YouTube TV Price Hike for Six Months
- ·Pinterest Android App Gets An Update
- ·YouTube Music Loses SESAC License
- ·Fubo and Disney's Hulu + Live TV Are Merging
- ·Transforming Raw Data into Strategic Decisions: The Role of Expert Data Science Consulting
- ·Facebook Will Probably Continue to Pump Out Standalone Apps
- ·A Technical Look at Modern Web Search
- ·How to Identify Your Target Audience Effectively In Marketing Strategies
- ·Blackberry Sells Cylance to Arctic Wolf
- ·FBI & DOJ Investigating ByteDance & TikTok's Surveillance of Journalists
- ·Bug Caused Some LinkedIn Accounts to Lose Followers
- ·X's Premium+ Subscription Gets a Price Hike
- ·Bluesky Tops 10 Million Users