logo

March Madness Ads, Scams, And Malware

ID: 3b3ef95e-87c6-521d-b1a1-8b05ba94c21d

STIX ID: report--3b3ef95e-87c6-521d-b1a1-8b05ba94c21d

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ describes a surge of March Madness-themed scams: fake NCAA bracket downloads and fraudulent streaming sites that deliver malware and adware. Analysts observed a signed EXE (linked to BERSHNET LLC) and another downloader that retrieves supplemental payloads; both collect system telemetry and POST it to CloudFlare-hosted command-and-control servers. The report also highlights numerous auto-generated, ad-filled .tk blogs and SEO-poisoning used to funnel users to malicious downloads or fake plug-ins, and advises caution while searching or clicking tournament-related links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.