216.73.217.22

Threat actor impersonates Google via fake ad for Authenticator

· Published 31/07/2024 10:38 · Modified 31/07/2024 10:59

Export JSON

Essential information

Published
31/07/2024 10:38
Modified
31/07/2024 10:59
Tags
2024-07-31 advertising authentication deerstealer phishing stealer
Related entities
5 observables, 9 techniques (mitre), 1 malware

Description

An unknown threat actor created a deceptive advertisement that appeared as if it was from a reputable company, enticing users to click on it and visit a malicious website. The site hosted a digitally signed malicious file disguised as a popular multi-factor application. Upon execution, the malware would exfiltrate personal data from the victim's device to an attacker-controlled server. This attack highlights the ongoing abuse of online platforms for distributing malware and demonstrates the need for users to exercise caution when downloading software, even from seemingly trustworthy sources.

External references