logo

Spear-Phishing Campaign Leverages Google Ads to Distribute EndRAT Malware

ID: 6792c3e1-2980-5fbc-af80-edeff9866c36

STIX ID: report--6792c3e1-2980-5fbc-af80-edeff9866c36

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-19

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Genians Security Center details "Operation Poseidon," an advanced spear-phishing campaign attributed to the Konni APT that abuses advertising redirect infrastructure (Google DoubleClick and Naver) to mask links and lead victims to compromised WordPress sites hosting EndRAT. The attack delivers a compressed archive containing a malicious LNK that executes an AutoIt script to load AutoIt3.exe and an in-memory EndRAT payload, with reuse of C2 infrastructure, multiple IoCs provided, and recommended mitigations including EDR behavioral detection, URL sandboxing, and threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.