Skip to main content

Manipulated Google ads push malware

  • April 27, 2023
  • 5 comments
  • 42 views

JMeixner
Forum|alt.badge.img+18

Malware is distributed through Google Ads and SEO poisoning that promote popular software like Zoom, Cisco AnyConnect, ChatGPT, and Citrix Workspace.

One campaign utilized a Google ad promoting - for example - a fake Cisco AnyConnect Secure Mobility Client download – hosted on a domain “appcisco[.]com”.

This site delivered a trojanized MSI installer. It installs the desired original application but installs different malware additionally.

https://www.bleepingcomputer.com/news/security/google-ads-push-bumblebee-malware-used-by-ransomware-gangs/

5 comments

Chris.Childerhose
Forum|alt.badge.img+21

It amazes me how they find ways even via ads to send out malware.  Thanks for sharing this and hopefully AV vendors are on top of it.


MicoolPaul
Forum|alt.badge.img+23

Just further proof that Ads ARE Malware 😆


dips
Forum|alt.badge.img+7
  • On the path to Greatness
  • April 28, 2023

One of a myriad of reasons to blocks ads, especially on corporate networks. 

Even Search Engine Ads end up becoming poisoned when searching for generic software installs. 


dloseke
Forum|alt.badge.img+8
  • Veeam Vanguard
  • April 28, 2023

Just further proof that Ads ARE Malware 😆

Yeah, it used to be in jest, but it really is true now.


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • April 28, 2023

One of a myriad of reasons to blocks ads, especially on corporate networks. 

Even Search Engine Ads end up becoming poisoned when searching for generic software installs. 

That’s the reason why I block ads at multiple places and don't like to make any exceptions. Malicious adds can always appear so the risk it just too high to allow them getting displayed.