216.73.216.6

Bengal cat lovers in Australia get psspsspss’d in Google-driven Gootloader campaign

· Published 06/11/2024 14:29 · Modified 06/11/2024 17:34

Export JSON

Essential information

Published
06/11/2024 14:29
Modified
06/11/2024 17:34
Tags
2024-11-06 gootkit gootloader initial access javascript powershell scheduled task seo poisoning
Related entities
14 observables, 1 intrusion sets (apt), 2 malware, 1 others

Description

A new variant has been discovered using search engine optimization (SEO) poisoning to target Australian Bengal cat enthusiasts. The campaign uses Google search results for 'Are Bengal Cats legal in Australia?' to deliver malicious payloads. When users click on compromised links, a zip file containing obfuscated is downloaded. This initial payload drops a larger file, which creates a for persistence. The second stage uses WScript and CScript to execute additional commands. While the full deployment of was not observed in this case, the malware typically leads to information stealing and potential ransomware attacks. The campaign demonstrates the ongoing evolution of 's tactics and the continued threat of for malware delivery.

External references