Black Hat SEO Leveraged to Distribute Malware
ID: d5d7ff10-0349-59f0-be55-986ba99f9e81
STIX ID: report--d5d7ff10-0349-59f0-be55-986ba99f9e81
Feed Name: Zscaler Security Research Blog
This report documents a search-engine poisoning campaign that lures users to fraudulent file-hosting pages and delivers an obfuscated multi-stage malware installer. The attack chain includes referral checks to evade researchers, nested password-protected ZIP archives (password hidden in an image), execution of a setup that installs legitimate GPG alongside a malicious libgcrypt-20.dll used for DLL sideloading, process hollowing of explorer.exe, PowerShell-based retrieval and multilayer deobfuscation of payloads, and the deployment of a malicious browser extension for persistence and further malicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
