Security News > 2021 > March > Cybercriminals using Google Search as the latest trick to snare unsuspecting victims for malware attacks

It was only a matter of time before cybercriminals turned their attention to one of the most common activities on the internet- a Google search.
The latest trick is using long-tail search terms and legitimate websites to deliver the Gootkit remote access trojan.
This latest iteration of the Gootkit RAT uses "Malicious search engine optimization techniques to squirm into Google search results," as Sophos analysts describe it in a blog post.
The Sophos research found that bad actors are not targeting other search engines as frequently or as successfully.
Gaurav Banga, founder and CEO of cybersecurity company Balbix, said that with the recent Gootloader malware, bad actors are "SEO poisoning" by compromising legitimate and highly-trafficked websites by accessing the site back-end, editing content to improve SEO, and adding discreetly named ZIP files containing the malware that website visitors then download. "The easiest way to deploy SEO malware is through an admin user's compromised system," he said.
A reply to the query includes a direct download link to a zip archive file with a filename that matches the search query.
News URL
Related news
- Ivanti zero-day attacks infected devices with custom malware (source)
- WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites (source)
- Fake Homebrew Google ads target Mac users with malware (source)
- IPany VPN breached in supply-chain attack to push custom malware (source)
- MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks (source)
- Google takes action after coder reports 'most sophisticated attack I've ever seen' (source)
- Google says hackers abuse Gemini AI to empower their attacks (source)
- Google fixes Android kernel zero-day exploited in attacks (source)
- Crypto-stealing iOS, Android malware found on App Store, Google Play (source)
- Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking (source)