Manipulated Google ads push malware


Userlevel 7
Badge +17

Malware is distributed through Google Ads and SEO poisoning that promote popular software like Zoom, Cisco AnyConnect, ChatGPT, and Citrix Workspace.

One campaign utilized a Google ad promoting - for example - a fake Cisco AnyConnect Secure Mobility Client download – hosted on a domain “appcisco[.]com”.

This site delivered a trojanized MSI installer. It installs the desired original application but installs different malware additionally.

https://www.bleepingcomputer.com/news/security/google-ads-push-bumblebee-malware-used-by-ransomware-gangs/


5 comments

Userlevel 7
Badge +20

It amazes me how they find ways even via ads to send out malware.  Thanks for sharing this and hopefully AV vendors are on top of it.

Userlevel 7
Badge +20

Just further proof that Ads ARE Malware 😆

Userlevel 7
Badge +7

One of a myriad of reasons to blocks ads, especially on corporate networks. 

Even Search Engine Ads end up becoming poisoned when searching for generic software installs. 

Userlevel 7
Badge +6

Just further proof that Ads ARE Malware 😆

Yeah, it used to be in jest, but it really is true now.

Userlevel 7
Badge +14

One of a myriad of reasons to blocks ads, especially on corporate networks. 

Even Search Engine Ads end up becoming poisoned when searching for generic software installs. 

That’s the reason why I block ads at multiple places and don't like to make any exceptions. Malicious adds can always appear so the risk it just too high to allow them getting displayed.

Comment