Fake websites promoting widely used software have been leveraged by the Black Cat threat operation to deploy an information-stealing backdoor as part of a new SEO poisoning campaign, which has compromised nearly 277,800 Chinese hosts from Dec. 7 to Dec. 20, according to The Hacker News.Attacks involved the injection of illicit search results for Notepad++, which redirect to a phishing site that includes a download button that diverts to a GitHub-impersonating site, a report from the National Computer Network Emergency Response Technical Team/Coordination Center of China and Beijing Weibu Online showed. Downloading the ZIP archive from the counterfeit GitHub site launches an installer, which establishes a shortcut, which allows side-loading of an illicit DLL that deploys the backdoor.Aside from facilitating keystroke logging and browser data exfiltration, the malware also enables clipboard content extraction and host data theft, said the report, which warned users against clicking unknown links to curb potential compromise.
Malware, Threat Intelligence
New Black Cat SEO poisoning campaign spreads malware via software searches

(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds


