logo

Malicious ad distributes SocGholish malware to Kaiser Permanente employees

ID: 161eed8a-15c8-58ed-a0af-82718ddac6e8

STIX ID: report--161eed8a-15c8-58ed-a0af-82718ddac6e8

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-12-16

Date Updated: 2026-04-28

...
...

Malwarebytes discovered a malicious Google Search Ad impersonating Kaiser Permanente’s HR portal that redirected users to a compromised bellonasoftware.com site hosting a SocGholish fake browser update; running the offered Update.js results in fingerprinting and may download follow-on tools like Cobalt Strike. The blog details the compromise, provides IoCs (phishing domain and SocGholish infrastructure), and advises caution with sponsored search results.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.