Malicious ad distributes SocGholish malware to Kaiser Permanente employees
ID: 161eed8a-15c8-58ed-a0af-82718ddac6e8
STIX ID: report--161eed8a-15c8-58ed-a0af-82718ddac6e8
Feed Name: Malwarebytes Blog
Threat Score
Malwarebytes discovered a malicious Google Search Ad impersonating Kaiser Permanente’s HR portal that redirected users to a compromised bellonasoftware.com site hosting a SocGholish fake browser update; running the offered Update.js results in fingerprinting and may download follow-on tools like Cobalt Strike. The blog details the compromise, provides IoCs (phishing domain and SocGholish infrastructure), and advises caution with sponsored search results.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
