logo

Hackers Poison SEO to Promote Malware in Top Search Results Targeting IT Admins

ID: 371bccfd-3473-5049-9f7a-ddfb4878ba3a

STIX ID: report--371bccfd-3473-5049-9f7a-ddfb4878ba3a

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2025-05-09

Date Updated: 2026-04-19

Author: Mandvi

...
...

**SEO poisoning leads to ransomware double-extortion:** Attackers poisoned search results to distribute trojanized IT utilities (notably a malicious RV-Tools installer) that installed a PowerShell/.NET backdoor (SMOKEDHAM). They conducted environment reconnaissance (whoami, systeminfo, nslookup, gpresult), collected credentials, used RDP/PsExec for lateral movement, deployed remote-access tools (rebranded Kickidler, KiTTY, AnyDesk), exfiltrated nearly a terabyte of data to AWS EC2 via WinSCP, and encrypted ESXi VMDKs in a double-extortion scheme; the report highlights associated TTPs and defensive controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.