Security News > 2023 > October > Fake KeePass site uses Google Ads and Punycode to push malware

Fake KeePass site uses Google Ads and Punycode to push malware
2023-10-19 18:17

A Google Ads campaign was found pushing a fake KeePass download site that used Punycode to appear as the official domain of the KeePass password manager to distribute malware.

Even worse, Google Ads can be abused to show the legitimate domain for Keepass in the advertisements, making the threat hard to spot even for more diligent and security-conscious users.

While Google has removed the original Punycode advertisement seen by Malwarebytes, BleepingComputer found additional ongoing KeePass ads in the same malware campaign.

Like the Punycode domain, this site pushes the same MSIX file that includes the same FakeBat PowerShell script to download and install malware on the Windows device.

Fake Cisco Webex Google Ads abuse tracking templates to push malware.

Bing Chat responses infiltrated by ads pushing malware.


News URL

https://www.bleepingcomputer.com/news/security/fake-keepass-site-uses-google-ads-and-punycode-to-push-malware/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 994 4850 2758 1634 10236
Keepass 2 0 5 3 0 8