logo

New Spear-Phishing Attack Abusing Google Ads to Deliver EndRAT Malware

ID: 09a6f350-bcd2-5e05-a6f7-f2beba85b7cd

STIX ID: report--09a6f350-bcd2-5e05-a6f7-f2beba85b7cd

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Operation Poseidon is a targeted spear-phishing campaign attributed to the Konni APT that leverages legitimate Google ad redirection and compromised WordPress sites to deliver an EndRAT variant. The attackers use LNK shortcuts and AutoIt scripts to load the RAT directly into memory, and employ multiple evasion techniques—including invisible content padding, 1×1 tracking beacons, and embedding C2 addresses in advertising URL parameters—while the report provides specific artifacts (e.g., "endServer9688"/"endClient9688").

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.