Monday, November 28, 2022

Google ads might be a security risk - Fudzilla

Last updated Monday, November 21, 2022 07:05 ET , Source: NewsService

Microsoft warning

Software King of the World Microsoft has warned that a Google Ads campaign is distributing compromise payloads, including the recently discovered Royal ransomware.

Microsoft spotted the updated malware delivery method in late October 2022, is tracking the group under the name DEV-0569.

The Microsoft Security Threat Intelligence team said in an analysis that DEV-0569 attacks show a pattern of "continuous innovation, with regular incorporation of new discovery techniques, defense evasion, and various post-compromise payloads, alongside increasing ransomware facilitation,".

The threat actor is known to rely on malvertising to point unsuspecting victims to malware downloader links that pose as software installers for legitimate apps like Adobe Flash Player, AnyDesk, LogMeIn, Microsoft Teams, and Zoom.

The malware downloader, a strain referred to as BATLOADER, is a dropper that functions as a conduit to distribute next-stage payloads. It has been observed to share overlaps with another malware called ZLoader.

A recent analysis of BATLOADER by eSentire and VMware called out the malware's stealth and persistence, in addition to its use of search engine optimization (SEO) poisoning to lure users to download the malware from compromised websites or attacker-created domains.

Alternatively, phishing links are shared through spam emails, fake forum pages, blog comments, and even contact forms present on targeted organizations' websites.

"DEV-0569 has used varied...

Read Full Story: https://news.google.com/__i/rss/rd/articles/CBMiQ2h0dHBzOi8vZnVkemlsbGEuY29tL25ld3MvNTU4NTctZ29vZ2xlLWFkcy1taWdodC1iZS1hLXNlY3VyaXR5LXJpc2vSAQA?oc=5

Your content is great. However, if any of the content contained herein violates any rights of yours, including those of copyright, please contact us immediately by e-mail at media[@]kissrpr.com.