logo

Malicious Google Ads Pushing Fake IP Scanner Software with Hidden Backdoor

ID: 935ddd0a-048e-51e0-a03a-6b369cc4f105

STIX ID: report--935ddd0a-048e-51e0-a03a-6b369cc4f105

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-18

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Zscaler ThreatLabz identified a Google Ads-driven malvertising campaign (≈45 typosquatted domains mimicking IP scanner tools) distributing a new Windows backdoor called MadMxShell. Delivery uses a ZIP containing Advanced-ip-scanner.exe and IVIEWERS.dll; the DLL performs process hollowing, unpacks OneDrive.exe and Secur32.dll, abuses DLL sideloading to run shellcode, establishes persistence via scheduled tasks, disables Microsoft Defender, and uses DNS MX queries (subdomain-encoded FQDNs) to communicate with C2 (litterbolo.com).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.