Threat Advisory

Malicious Ads on Google Target Chinese Users with Fake Messaging Apps

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A recent surge in malicious ad campaigns has targeted Chinese-speaking users, enticing them with offers related to popular messaging applications like Telegram and LINE, despite these apps being heavily restricted or banned in China. The campaign, primarily disseminated through Google's advertising platform, aims to distribute Remote Administration Trojans (RATs) disguised as legitimate software downloads. the threat actor leverages Google's infrastructure, including Google Docs and Google Sites, to host malicious links and redirect unsuspecting users. This strategy underscores the challenge of enforcing digital restrictions in an interconnected online environment where users seek to bypass censorship using tools like VPNs.[/subscribe_to_unlock_form]

Summary:

A recent surge in malicious ad campaigns has targeted Chinese-speaking users, enticing them with offers related to popular messaging applications like Telegram and LINE, despite these apps being heavily restricted or banned in China. The campaign, primarily disseminated through Google's advertising platform, aims to distribute Remote Administration Trojans (RATs) disguised as legitimate software downloads. the threat actor leverages Google's infrastructure, including Google Docs and Google Sites, to host malicious links and redirect unsuspecting users. This strategy underscores the challenge of enforcing digital restrictions in an interconnected online environment where users seek to bypass censorship using tools like VPNs.[emaillocker id="1283"]

The malicious ads originate from two Nigerian-associated advertiser accounts, Interactive Communication Team Limited and Ringier Media Nigeria Limited, suggesting a potential takeover by threat actors. The infrastructure supporting these campaigns relies heavily on Google services, facilitating the distribution of malware payloads, predominantly in MSI format. These payloads often employ DLL side-loading techniques, combining legitimate applications with malicious DLLs to evade detection. the threat actor utilizes techniques consistent with known RATs like PlugX and Gh0st RAT, indicating a sophisticated and adaptable approach to malware distribution. Online forums dedicated to cybersecurity monitoring in China have identified these campaigns, labeling them as FakeAPP and highlighting the threat actor's focus on quantity over quality in deploying new payloads and infrastructure.

The malvertising campaigns targeting users in regions with stringent digital regulations underscores the challenges of enforcing online restrictions. By exploiting popular messaging platforms and leveraging Google's advertising infrastructure, threat actors can effectively distribute malware to unsuspecting users. Despite efforts to notify relevant parties and implement detection measures, such as those by researcher, users are advised to remain vigilant, particularly when downloading files disguised as legitimate documents. The persistence and adaptability of threat actors, combined with the anonymity and reach afforded by online advertising platforms, necessitate continued vigilance and collaboration among cybersecurity stakeholders to mitigate the impact of such malicious campaigns.

Threat Profile:

 

 

References:

The following reports contain further technical details:

https://thehackernews.com/2024/01/malicious-ads-on-google-target-chinese.html

[/emaillocker]
crossmenu