Skip to main content

Manipulated Google ads push malware


JMeixner
Forum|alt.badge.img+17
  • On the path to Greatness
  • 2650 comments

Malware is distributed through Google Ads and SEO poisoning that promote popular software like Zoom, Cisco AnyConnect, ChatGPT, and Citrix Workspace.

One campaign utilized a Google ad promoting - for example - a fake Cisco AnyConnect Secure Mobility Client download – hosted on a domain “appcisco[.]com”.

This site delivered a trojanized MSI installer. It installs the desired original application but installs different malware additionally.

https://www.bleepingcomputer.com/news/security/google-ads-push-bumblebee-malware-used-by-ransomware-gangs/

5 comments

Chris.Childerhose
Forum|alt.badge.img+21

It amazes me how they find ways even via ads to send out malware.  Thanks for sharing this and hopefully AV vendors are on top of it.


MicoolPaul
Forum|alt.badge.img+23

Just further proof that Ads ARE Malware 😆


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments
  • April 28, 2023

One of a myriad of reasons to blocks ads, especially on corporate networks. 

Even Search Engine Ads end up becoming poisoned when searching for generic software installs. 


dloseke
Forum|alt.badge.img+8
  • Veeam Vanguard
  • 1447 comments
  • April 28, 2023
MicoolPaul wrote:

Just further proof that Ads ARE Malware 😆

Yeah, it used to be in jest, but it really is true now.


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1352 comments
  • April 28, 2023
dips wrote:

One of a myriad of reasons to blocks ads, especially on corporate networks. 

Even Search Engine Ads end up becoming poisoned when searching for generic software installs. 

That’s the reason why I block ads at multiple places and don't like to make any exceptions. Malicious adds can always appear so the risk it just too high to allow them getting displayed.


Comment