Bing ad for NordVPN leads to SecTopRAT
ID: 50a2b0e3-4cb6-5071-9f52-6e9883501fcf
STIX ID: report--50a2b0e3-4cb6-5071-9f52-6e9883501fcf
Feed Name: Malwarebytes Blog
A recent malvertising campaign on Bing impersonated NordVPN using lookalike domains and a malicious ad that redirected users to a convincing fake site offering a direct download. The distributed file (NordVPNSetup.exe) contained both a legitimate installer and a SecTopRAT Remote Access Trojan which injects into MSBuild.exe and connects to a C2 server (45.141.87.216); the report lists malicious domains (nordivpn.xyz, besthord-vpn.com), a SHA256 for the fake installer, and remediation actions taken (reports to providers and Dropbox takedown).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
