Ransomware gang targets Windows admins via PuTTy, WinSCP malvertising
ID: 3e7eadef-d2e9-5498-9c90-e04830675833
STIX ID: report--3e7eadef-d2e9-5498-9c90-e04830675833
Feed Name: Bleeping Computer
Threat Score
A malvertising campaign advertised fake Putty and WinSCP download sites (typosquatting domains) to deliver trojanized installers that use DLL sideloading to load a malicious python311.dll; the payload extracts and runs an encrypted Python script that installs the Sliver post-exploitation framework, enabling Cobalt Strike deployment, data exfiltration attempts, and an attempted ransomware encryptor (ransomware execution was reportedly blocked).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
