Skip to content
Threat Feed

Tag

Seo-Poisoning

4 briefs RSS
high threat

CL-CRI-1171 Pay-Per-Install Infrastructure and Malware Campaign

The CL-CRI-1171 threat actor operates a large-scale pay-per-install marketplace, leveraging SEO poisoning and YouTube gaming lures to deploy a persistent multi-payload loader used to distribute malware including Insomnia RAT and ARKTunnel.

WinDirStat CL-CRI-1171 ppi malware seo-poisoning loader remote-access-trojan c2
1r 2t 5i
high advisory

GPU Mining Malware Spreads via SEO Poisoning and AI Chatbots

A cryptojacking campaign targets systems with high-performance GPUs using SEO poisoning and manipulated AI chatbot recommendations, distributing malware disguised as legitimate software utilities to establish persistence and evade detection before deploying GPU mining programs.

Microsoft Defender +8 cryptojacking seo-poisoning process-hollowing persistence defense-evasion gpu-mining windows
3r 6t 1i
high advisory

Cryptojacking Campaign Abusing ScreenConnect and SEO Poisoning

An active cryptojacking campaign uses SEO poisoning, AI chatbot interactions, and ScreenConnect abuse to target high-performance PCs, aiming to maximize GPU mining yield and establish persistent remote access for potential data theft or ransomware attacks.

ScreenConnect cryptojacking seo-poisoning dll-sideloading
2r 1t 1i
high threat

Nimbus Manticore Resurfaces During Operation Epic Fury with New Techniques

Nimbus Manticore, an Iranian IRGC-affiliated threat actor, resurfaced during Operation Epic Fury, employing AppDomain Hijacking, SEO poisoning, and a new MiniFast backdoor while targeting the aviation and software sectors.

Setup.exe +3 Nimbus Manticore nimbus-manticore irgc appdomain-hijacking seo-poisoning minijunk minifast infostealer
2r 3t