crep1x(@crep1x) 's Twitter Profile Photo

A threat actor spreads using Google via websites impersonating the Advanced IP scanner download page.

It has probably been targeting IT admins (valuable hosts) for several months.

Distribution infra of 40+ domain names:
advancd-ip-scanner.]com

⬇️

A threat actor spreads #DanaBot using Google #malvertising via websites impersonating the Advanced IP scanner download page.

It has probably been targeting IT admins (valuable hosts) for several months.

Distribution infra of 40+ domain names:
advancd-ip-scanner.]com

⬇️
account_circle
SwiftOnSecurity(@SwiftOnSecurity) 's Twitter Profile Photo

Me watching attackers pawn everybody through malvertising lures towards IT staff, meanwhile all our users have uBlock Origin forced in Edge, Chrome, and Firefox.

Me watching attackers pawn everybody through malvertising lures towards IT staff, meanwhile all our users have uBlock Origin forced in Edge, Chrome, and Firefox.
account_circle
Oktsec(@oktsec) 's Twitter Profile Photo

Malvertising injects malicious code into legit ads, exploiting ad network & browser vulnerabilities. When users interact, it redirects to malicious sites or downloads malware. Keep software updated & use ad-blockers! 🚫🖥️

account_circle
Cuser(@Cuser07) 's Twitter Profile Photo

X
A malicious ad appears on my timeline🤣
im-token[.]us -> hxxps://im-token[.]us/down/imtoken.apk -> 738d0e0def50ddf40df81ed4ed2faf50e8a8db196360826e39e69de8981ed8aa
Collect and send mnemonic to remote server
C2: api.bvip[.]dev
MalwareHunterTeam

X #Malvertising #FakeWallet
A malicious ad appears on my timeline🤣
im-token[.]us -> hxxps://im-token[.]us/down/imtoken.apk -> 738d0e0def50ddf40df81ed4ed2faf50e8a8db196360826e39e69de8981ed8aa
Collect and send mnemonic to remote server
C2: api.bvip[.]dev
@malwrhunterteam
account_circle
OpsMatters(@opsmatters_uk) 's Twitter Profile Photo

The latest update for includes 'Top Tax Scams of 2024 Your Organization Should Watch Out For' and 'Malvertising Campaigns Surged in 2023'.

opsmtrs.com/3ZJvoEF

account_circle
crep1x(@crep1x) 's Twitter Profile Photo

A threat actor distributes the C2 framework via websites impersonating Advanced IP scanner / WinSCP / Putty, likely using malvertising.

Distribution website:
hxxps://advanced-ip-scann.]org/av/download.php

Sliver C2:
94.156.65.]115:8443

⬇️

A threat actor distributes the #Sliver C2 framework via websites impersonating Advanced IP scanner / WinSCP / Putty, likely using malvertising.

Distribution website:
hxxps://advanced-ip-scann.]org/av/download.php

Sliver C2:
94.156.65.]115:8443

⬇️
account_circle
CyberPreserve(@CyberPreserve) 's Twitter Profile Photo

✔️The attack chains use scripts loaded from the threat actor-controlled server ('jscdnpack[.]com'). This specifically targets a page structure that is common to several banks.

✔️The malware is delivered to targets by some other means like phishing emails or malvertising.

✔️The attack chains use scripts loaded from the threat actor-controlled server ('jscdnpack[.]com'). This specifically targets a page structure that is common to several banks.

✔️The malware is delivered to targets by some other means like phishing emails or malvertising.
account_circle
Microsoft Threat Intelligence(@MsftSecIntel) 's Twitter Profile Photo

Microsoft has detected Danabot (Storm-1044) infections leading to hands-on-keyboard activity by ransomware operator Storm-0216 (Twisted Spider, UNC2198), culminating in the deployment of Cactus ransomware. In this campaign, Danabot is distributed via malvertising.

account_circle
Gabriele Orini(@greenplan_it) 's Twitter Profile Photo

What are these? Developed in Delphi🤔

joesandbox.com/analysis/14046…

(now offline)
https[:]//traclom1[.]buzz/uptodate/data[.]zip
https[:]//www.checkthedifference[.]online/updates/info[.]zip

Perhaps related to some malvertising activities?

RussianPanda 🐼 🇺🇦 Yogesh Londhe crep1x

What are these? Developed in Delphi🤔

joesandbox.com/analysis/14046…

(now offline)
https[:]//traclom1[.]buzz/uptodate/data[.]zip
https[:]//www.checkthedifference[.]online/updates/info[.]zip

Perhaps related to some malvertising activities?

@RussianPanda9xx @suyog41 @crep1x
account_circle
Joe Stocker(@ITguySoCal) 's Twitter Profile Photo

I think I speak for all corporate enterprises here. We want to see advertisements in the start menu. Malvertising is not a concern for any of us. 🤦‍♂️

account_circle
RSK Cyber Security(@RSKCyberSec) 's Twitter Profile Photo

exploit Facebook ads & hijacked pages to push fake AI services like MidJourney, OpenAI's SORA & -5, and DALL-E. They're spreading password-stealing malware. Malvertising schemes impersonate popular AI platforms, offering sneak peeks of fake features.

account_circle
CR1337(@cryptonator1337) 's Twitter Profile Photo

🚨Hackers deploy crypto drainers on 2,000 Wordpress websites 🚨

As originally reported last month by security firm Sucuri, a large amount of Wordpress websites was originally hacked in order to promote crypto drainers through malvertising and YouTube videos.

However, now the…

🚨Hackers deploy crypto drainers on 2,000 Wordpress websites 🚨

As originally reported last month by security firm Sucuri, a large amount of Wordpress websites was originally hacked in order to promote crypto drainers through malvertising and YouTube videos. 

However, now the…
account_circle
SquareX(@getsquarex) 's Twitter Profile Photo

Malware analysts can leverage 's Disposable Browser to analyze malvertising campaigns with safety.

Investigate suspicious ads on risky websites without risking your own system so you can strengthen defences against malvertising: sqrx.io/651eg

Malware analysts can leverage #SquareX's Disposable Browser to analyze malvertising campaigns with safety. 

Investigate suspicious ads on risky websites without risking your own system so you can strengthen #cybersecurity defences against malvertising: sqrx.io/651eg
account_circle
Brian in Pittsburgh(@arekfurt) 's Twitter Profile Photo

I'm gonna be pessimistic but honest with you: I don't see any particular reason to believe that SEO hijacking and malvertising aren't just going to continue to get more and more popular in terms of the ways that malware gets on Windows machines in the months and years ahead.

account_circle
Florian Hansemann(@CyberWarship) 's Twitter Profile Photo

'New Malvertising Campaign Uses Fake Windows News Portal to Distribute Malicious Installers'


thehackernews.com/2023/11/new-ma…

'New Malvertising Campaign Uses Fake Windows News Portal to Distribute Malicious Installers'

#infosec #pentest #redteam 
thehackernews.com/2023/11/new-ma…
account_circle
Matt Zorich(@reprise_99) 's Twitter Profile Photo

Some names in cyber security are frankly awful, but round of applause for whoever came up with malvertising

account_circle