Article Details
Scrape Timestamp (UTC): 2023-11-09 16:15:14.417
Original Article Text
Click to Toggle View
Google ads push malicious CPU-Z app from fake Windows news site. A threat actor has been abusing Google Ads to distribute a trojanized version of the CPU-Z tool to deliver the Redline info-stealing malware. The new campaign was spotted by Malwarebytes analysts who, based on the backing infrastructure, asses that it is part of the same operation that used Notepad++ malvertising to deliver malicious payloads. Campaign details The malicious Google advertisement for the trojanized CPU-Z, a tool that profiles computer hardware on Windows, is hosted on a cloned copy of the legitimate Windows news site WindowsReport. CPU-Z is a popular free utility that can help users monitor different hardware components, from fan speeds, to CPU clock rates, voltage, and cache details. Clicking the ad takes the victim through a redirect step that tricks Google’s anti-abuse crawlers by sending invalid visitors to an innocuous site. Those deemed valid to receive the payload are redirected to a Windows news site lookalike hosted on one of the following domains: The reason behind using a clone of a legitimate site is to add another layer of trust to the infection process, as users are familiar with tech news sites hosting download links for useful utilities. Clicking on the ‘Download now’ button results in receiving a digitally-signed CPU-Z installer (MSI file) containing a malicious PowerShell script identified as the ‘FakeBat’ malware loader. Signing the file with a valid certificate makes it unlikely that Windows security tools or third-party antivirus products running on the device will serve a warning for the user. The loader fetches a Redline Stealer payload from a remote URL and launches it on the victim’s computer. Redline is a powerful stealer able to collect passwords, cookies, and browsing data from a range of web browsers and applications, as well as sensitive data from cryptocurrency wallets. To minimize the chances of malware infections when looking for specific software tools, users should pay attention when clicking on promoted results in Google Search and check the if the loaded site and the domain match, or use an ad-blocker that hides them automatically.
Daily Brief Summary
Google Ads has been misused to distribute a trojanized version of the CPU-Z tool, which delivers the Redline info-stealing malware.
Malwarebytes analysts identified the campaign and linked it to previous malvertising operations that targeted users with malicious Notepad++ downloads.
Victims are lured to a cloned Windows news site where a seemingly trustworthy 'Download now' button delivers a signed installer containing a malicious script.
The FakeBat malware loader in the MSI file silently fetches and activates the Redline Stealer payload on the victim's system without triggering security warnings.
Redline malware is capable of harvesting a wide array of personal data, including passwords, cookies, browser data, and cryptocurrency wallet information.
Users are advised to exercise caution when clicking on Google Search ads and ensure the authenticity of the domain or employ ad-blockers to evade such threats.