Dismiss this notice
ExpressVPN Valentines 2021 Giveaway - https://www.geeks.fyi/showthread.php?tid=14246

Dismiss this notice
Internet Download Manager Giveaway - https://www.geeks.fyi/showthread.php?tid=14245

Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Malware Loader Abuses Google SEO to Expand Payload Delivery
#1
Information 
Quote:The Gootloader malware loader, previously used for distributing the Gootkit malware family, has undergone what researchers call a “renaissance” when it comes to payload delivery.
 
New research released this week paints Gootloader as an increasingly sophisticated loader framework, which has now expanded the number of payloads its delivers beyond Gootkit (and in some cases, the previously-distributed REvil ransomware), to include the Kronos trojan and the Cobalt Strike commodity malware.
 
Gootloader is known for its multi-stage attack process, obfuscation tactics, and for using a known tactic for malware delivery called search engine optimization (SEO) poisoning. This technique leverages SEO-friendly terms in attacker-controlled websites, in order to rank them higher in Google’s search index. In the end, the method brings more eyeballs to the malicious sites, which contain links that launch the Gootloader attack chain.

“The malware delivery method pioneered by the threat actors behind the REvil ransomware and the Gootkit banking Trojan has been enjoying a renaissance of late, as telemetry indicates that criminals are using the method to deploy an array of malware payloads in South Korea, Germany, France, and across North America,” said Gabor Szappanos and Andrew Brandt, security researchers with Sophos Labs on Monday.

Read more: https://threatpost.com/malware-loader-go...ad/164377/
[-] The following 1 user Likes silversurfer's post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username:


Password:





[-]
Recent Posts
NSA: 5 Security Bugs Under Active Nation...
The Feds are warni...silversurfer — 08:04
Google Project Zero Cuts Bug Disclosure ...
Google Project Zer...silversurfer — 08:02
iOS Kids Game Morphs into Underground Cr...
A kids’ game calle...silversurfer — 08:00
BazarLoader Malware Abuses Slack, BaseCa...
The BazarLoader ma...silversurfer — 07:58
NoVirusThanks OSArmor v1.5.7
We've released a n...harlan4096 — 06:07

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (40)wapedDow
avatar (44)oapedDow
avatar (37)Sanchowogy
avatar (39)techlignub
avatar (38)Stevenmam
avatar (45)onlinbah
avatar (46)steakelask
avatar (40)Termoplenka
avatar (38)bycoPaist
avatar (44)pieloKat
avatar (38)ilyagNeexy
avatar (46)donitascene
avatar (46)Toligo
avatar (33)RobertUtelt

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>