Hackers Poison SEO to Promote Malware in Top Search Results Targeting IT Admins
ID: 371bccfd-3473-5049-9f7a-ddfb4878ba3a
STIX ID: report--371bccfd-3473-5049-9f7a-ddfb4878ba3a
Feed Name: Cyber Press
**SEO poisoning leads to ransomware double-extortion:** Attackers poisoned search results to distribute trojanized IT utilities (notably a malicious RV-Tools installer) that installed a PowerShell/.NET backdoor (SMOKEDHAM). They conducted environment reconnaissance (whoami, systeminfo, nslookup, gpresult), collected credentials, used RDP/PsExec for lateral movement, deployed remote-access tools (rebranded Kickidler, KiTTY, AnyDesk), exfiltrated nearly a terabyte of data to AWS EC2 via WinSCP, and encrypted ESXi VMDKs in a double-extortion scheme; the report highlights associated TTPs and defensive controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
