216.73.216.226

Thunderstruck! Malicious ads for RVTools lead to ThunderShell payload

· Published 03/04/2025 17:18 · Modified 03/04/2025 19:04

Export JSON

Essential information

Published
03/04/2025 17:18
Modified
03/04/2025 19:04
Tags
2025-04-03 c2 google ads icedid malvertising powershell remote access tool rvtools thundershell trojanized software
Related entities
10 techniques (mitre), 2 malware, 1 others

Description

A security incident involving malicious sponsored ads distributing backdoored administrative tools was detected. Users searching for were served a tampered version containing , a -based . The malicious ads, appearing in Google search results, led to a site mimicking the legitimate download page. The trojanized file, when executed, installs but also deploys , allowing attackers to execute commands on compromised machines. Multiple ads from different verified advertisers were used to evade security controls. The campaign highlights the persistent threat of and the need for stronger ad screening processes and user awareness.

External references