Malware Disguised as AI Tools Affects Over 8,500 Small Businesses in SEO Poisoning Scheme

Published:

spot_img

The Dangers of SEO Poisoning in Cybersecurity

Cybersecurity threats continue to evolve, with recent reports highlighting a new malicious campaign that employs advanced search engine optimization (SEO) poisoning techniques. These tactics are designed to propagate a malware loader known as Oyster, which is also referred to as Broomstick or CleanUpLoader.

The Mechanics of the Campaign

According to research conducted by Arctic Wolf, the malicious activity involves promoting counterfeit websites that host trojanized versions of widely used software, such as PuTTY and WinSCP. Software professionals looking for these legitimate tools may unknowingly download infected versions, thereby compromising their systems.

Once infected, the malware sets up a backdoor, installing the Oyster/Broomstick loader which maintains persistence through a scheduled task. This task executes every three minutes and utilizes a malicious DLL file (twain_96.dll), indicating a sophisticated mechanism for maintaining its foothold on the infected device.

Notable Fake Domains

The campaign has been associated with several suspicious URLs designed to mimic legitimate software sites. Some of the known fake websites include:

  • updaterputty[.]com
  • zephyrhype[.]com
  • putty[.]run
  • putty[.]bet
  • puttyy[.]org

These domains are critical indicators of this ongoing threat, emphasizing the need for users to only download software from trusted sources and official vendor pages.

Widespread Impact on IT Tools

Experts suggest that the threat actors are targeting not just software utilities but also various IT tools, further emphasizing the importance of vigilance when searching for software online. Users must remain cautious and prioritize visiting verified websites to mitigate risks associated with malware.

Escalation of Phishing Attacks

The issue of SEO poisoning is not limited to one campaign; it aligns with a growing trend where cybercriminals manipulate search results related to artificial intelligence (AI) and other popular keywords. For example, users searching for AI-related tools have been directed to phishing pages through bogus ads. These sites often employ JavaScript to collect information from browsers, enabling attackers to further exploit user credentials.

In a recent campaign, malware was disguised as download links for Vidar and Lumma Stealer, packaged as password-protected ZIP files. These files contain an enormous NSIS installer, designed to masquerade as legitimate software and avoid detection by security systems.

The Expanding Scope of Cyber Threats

Data from cybersecurity firms like Kaspersky indicates that small and medium-sized businesses (SMBs) are increasingly targeted by these malicious operations. In just the first few months of 2025, around 8,500 SMB users faced cyberattacks where malware was disguised as familiar tools—ranging from popular applications like OpenAI’s ChatGPT to mainstays like Microsoft Office and Zoom.

Notably, Zoom emerged as a major target, accounting for a significant portion of unique malicious files observed during this period.

Techniques Employed by Attackers

These cyber campaigns often utilize search parameter injection tactics to mislead users. For instance, an attacker may redirect users searching for tech support for brands like Apple or Microsoft to fake help pages that contain fraudulent phone numbers.

What adds to the complexity of these attacks is that the misleading contact information is cleverly hidden, making it appear legitimate. This can lead users into unwittingly handing over sensitive information by calling the provided numbers.

The Broader Landscape of Malicious Advertising

Cybercriminals are not limiting their operations to just search engines; they are also leveraging platforms like Facebook to promote phishing attempts and malware distribution linked to cryptocurrency schemes. This expansive network of scams demonstrates how persistent and adaptable these attackers have become.

GhostVendors and Spurious Websites

Recent investigations reveal networks such as GhostVendors, which encompass thousands of websites that imitate popular brands to execute financial fraud. These sites frequently advertise real products that are never delivered, further complicating the landscape of online fraud.

Additionally, campaigns targeting consumers through fake marketplace ads tend to focus on stealing credit card information under the guise of processing legitimate orders. These ads are strategically launched and retracted quickly to evade detection, highlighting the relentless nature of these cyber threats.

Conclusion

The rise of SEO poisoning tactics showcases a significant shift in how cybercriminals seek to exploit vulnerabilities in web searches. By utilizing fake websites and misleading advertising practices, these threats pose a serious challenge to both individual users and organizations alike. Staying informed and cautious while navigating online resources remains essential to safeguarding against these evolving cyber threats.

spot_img

Related articles

Recent articles

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...

Quantum Cybersecurity Careers Emerge as Top Job Opportunity for the Next Decade

Guest Post By Sudiptaa Paul Choudhury is Chief Marketing Officer at QNu Labs, a global leader in quantum cybersecurity, TEDx speaker and a LinkedIn...

CVE-2025-66376 Exploited in Russian Cyberespionage Campaign Targeting Zimbra Webmail

Unit 42 has issued an advisory regarding a persistent cyberespionage campaign identified as CL-STA-1114, which targets Zimbra webmail systems. This campaign is attributed to...

New macOS malware exploits Telegram sessions to target cryptocurrency wallets, warns SlowMist

Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware...