Google Dynamic Search Ads Abused to Unleash Malware ‘Deluge’

October 30, 2023 at 06:13PM A new method of using vulnerable websites to deliver malicious ads to search engine users has been discovered. The technique involves using Google’s “dynamic search ads” feature to pair targeted ads with searches. A compromised website was used to serve a fake software ad, overwhelming victims with malware. The researcher … Read more

Malvertising Campaign Targets Brazil’s PIX Payment System with GoPIX Malware

October 25, 2023 at 05:45AM The PIX instant payment system in Brazil has become a target for threat actors using a new malware called GoPIX. The attacks occur through malicious ads that appear when users search for “WhatsApp web” on search engines. The malware hijacks payment requests and replaces them with attacker-controlled strings. Similar campaigns … Read more

Fake KeePass site uses Google Ads and Punycode to push malware

October 19, 2023 at 02:18PM A Google Ads campaign has been discovered promoting a fake KeePass download site that distributes malware. Threat actors are using Punycode to make the domain appear official, posing a challenge for security-conscious users. The Punycode domain is visually similar to the legitimate KeePass domain but with a slight difference. The … Read more