logo

Fraudulent Slack ad shows malvertiser’s patience and skills

ID: e63cb543-e5cf-5b19-ba50-e0eb6bfda726

STIX ID: report--e63cb543-e5cf-5b19-ba50-e0eb6bfda726

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-08-21

Date Updated: 2026-04-28

...
...

Malwarebytes describes a stealthy malvertising campaign that used Google Ads, multiple redirect/click-tracking layers, and cloaking to impersonate Slack and deliver a SecTopRAT remote-access trojan with stealer capabilities; the report includes redirect chains, decoy domains (e.g., slack-windows-download.com), a payload SHA256, and the C2 IP 45.141.87.218, and notes reporting and defensive actions taken.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.