logo

Ransomware gang targets Windows admins via PuTTy, WinSCP malvertising

ID: 3e7eadef-d2e9-5498-9c90-e04830675833

STIX ID: report--3e7eadef-d2e9-5498-9c90-e04830675833

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-05-18

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A malvertising campaign advertised fake Putty and WinSCP download sites (typosquatting domains) to deliver trojanized installers that use DLL sideloading to load a malicious python311.dll; the payload extracts and runs an encrypted Python script that installs the Sliver post-exploitation framework, enabling Cobalt Strike deployment, data exfiltration attempts, and an attempted ransomware encryptor (ransomware execution was reportedly blocked).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.