Fraudulent Slack ad shows malvertiser’s patience and skills
ID: e63cb543-e5cf-5b19-ba50-e0eb6bfda726
STIX ID: report--e63cb543-e5cf-5b19-ba50-e0eb6bfda726
Feed Name: Malwarebytes Blog
Threat Score
Malwarebytes describes a stealthy malvertising campaign that used Google Ads, multiple redirect/click-tracking layers, and cloaking to impersonate Slack and deliver a SecTopRAT remote-access trojan with stealer capabilities; the report includes redirect chains, decoy domains (e.g., slack-windows-download.com), a payload SHA256, and the C2 IP 45.141.87.218, and notes reporting and defensive actions taken.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
