March Madness Ads, Scams, And Malware
ID: 3b3ef95e-87c6-521d-b1a1-8b05ba94c21d
STIX ID: report--3b3ef95e-87c6-521d-b1a1-8b05ba94c21d
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ describes a surge of March Madness-themed scams: fake NCAA bracket downloads and fraudulent streaming sites that deliver malware and adware. Analysts observed a signed EXE (linked to BERSHNET LLC) and another downloader that retrieves supplemental payloads; both collect system telemetry and POST it to CloudFlare-hosted command-and-control servers. The report also highlights numerous auto-generated, ad-filled .tk blogs and SEO-poisoning used to funnel users to malicious downloads or fake plug-ins, and advises caution while searching or clicking tournament-related links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
