Threat Advisory

Hackers Using Google Ads to Spread FatalRAT Malware Disguised as Popular Apps

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers discovered that those who speak Chinese in Southeast and East Asia are the focus of a recent fraudulent Google Ads campaign that infects targeted computers with remote access trojans like FatalRAT. In order to carry out the assaults, pirate websites carrying trojanized installers are bought add spaces to show up in Google search results that send users looking for popular apps to them. The attacks most crucial component is the development of copycat websites with typosquatted domains. In order to spread the malicious installer, attacker attempts to maintain the pretence by installing the legitimate software while also dropping a loader that launches FatalRAT.[/subscribe_to_unlock_form]

Summary:

Researchers discovered that those who speak Chinese in Southeast and East Asia are the focus of a recent fraudulent Google Ads campaign that infects targeted computers with remote access trojans like FatalRAT. In order to carry out the assaults, pirate websites carrying trojanized installers are bought add spaces to show up in Google search results that send users looking for popular apps to them. The attacks most crucial component is the development of copycat websites with typosquatted domains. In order to spread the malicious installer, attacker attempts to maintain the pretence by installing the legitimate software while also dropping a loader that launches FatalRAT.[emaillocker id="1283"]

 

 

Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2023/02/hackers-using-google-ads-to-spread.html

[/emaillocker]
crossmenu