Cybercriminals using Google Search as the latest trick to snare unsuspecting victims for malware attacks

EvilEyeFleegle

Dogpatch USA
Gold Supporting Member
Nov 2, 2017
15,737
8,834
1,280
Twin Falls Idaho
One of the reasons I use DuckDuckGo and Firefox for my search engine and browser!


It was only a matter of time before cybercriminals turned their attention to one of the most common activities on the internet— a Google search. The latest trick is using long-tail search terms and legitimate websites to deliver the Gootkit remote access trojan.
This latest iteration of the Gootkit RAT uses "malicious search engine optimization techniques to squirm into Google search results," as Sophos analysts describe it in a blog post. The cybersecurity firm reports that criminals are using this new variation they call Gootloader to deliver malware payloads in North America, South Korea, Germany and France. The Sophos research found that bad actors are not targeting other search engines as frequently or as successfully.
Chris Rodgers, CEO and founder of Colorado SEO Pros, said that this new tactic uses Google as a gateway and SEO knowledge, particularly about long-tail searches.
"They had to go in and find topics that are low competition and low search volume and they have to be doing this at massive volume for it to be lucrative," he said.

Hackers seem to be getting control through content management systems like WordPress and via plugins.
 
One of the reasons I use DuckDuckGo and Firefox for my search engine and browser!


It was only a matter of time before cybercriminals turned their attention to one of the most common activities on the internet— a Google search. The latest trick is using long-tail search terms and legitimate websites to deliver the Gootkit remote access trojan.
This latest iteration of the Gootkit RAT uses "malicious search engine optimization techniques to squirm into Google search results," as Sophos analysts describe it in a blog post. The cybersecurity firm reports that criminals are using this new variation they call Gootloader to deliver malware payloads in North America, South Korea, Germany and France. The Sophos research found that bad actors are not targeting other search engines as frequently or as successfully.
Chris Rodgers, CEO and founder of Colorado SEO Pros, said that this new tactic uses Google as a gateway and SEO knowledge, particularly about long-tail searches.
"They had to go in and find topics that are low competition and low search volume and they have to be doing this at massive volume for it to be lucrative," he said.

Hackers seem to be getting control through content management systems like WordPress and via plugins.
A couple of times in the past few days, when I've done a Google search, it's gone to a big CONGRATULATIONS YOU'RE THE 5 MILLIONTH SEARCH AND YOU CAN WIN....then there's boxes to click to find your prize--lots of electronics, $100 gift cards... BUT YOU ONLY HAVE 15 MINUTES TO CLAIM YOUR PRIZE..... I backed out of it the first time and it popped up again a couple days later.

Don't know if it was legit, but I didn't trust it.
 
One of the reasons I use DuckDuckGo and Firefox for my search engine and browser!


It was only a matter of time before cybercriminals turned their attention to one of the most common activities on the internet— a Google search. The latest trick is using long-tail search terms and legitimate websites to deliver the Gootkit remote access trojan.
This latest iteration of the Gootkit RAT uses "malicious search engine optimization techniques to squirm into Google search results," as Sophos analysts describe it in a blog post. The cybersecurity firm reports that criminals are using this new variation they call Gootloader to deliver malware payloads in North America, South Korea, Germany and France. The Sophos research found that bad actors are not targeting other search engines as frequently or as successfully.
Chris Rodgers, CEO and founder of Colorado SEO Pros, said that this new tactic uses Google as a gateway and SEO knowledge, particularly about long-tail searches.
"They had to go in and find topics that are low competition and low search volume and they have to be doing this at massive volume for it to be lucrative," he said.

Hackers seem to be getting control through content management systems like WordPress and via plugins.
A couple of times in the past few days, when I've done a Google search, it's gone to a big CONGRATULATIONS YOU'RE THE 5 MILLIONTH SEARCH AND YOU CAN WIN....then there's boxes to click to find your prize--lots of electronics, $100 gift cards... BUT YOU ONLY HAVE 15 MINUTES TO CLAIM YOUR PRIZE..... I backed out of it the first time and it popped up again a couple days later.

Don't know if it was legit, but I didn't trust it.
Which is how it's supposed to work: private citizens alone regulating private social media.
 
It is neither the role nor responsible of government to dictate to private media how to edit their content.
Not entirely sure what that has to do with my OP?

But the logical flaw in your argument is that some content..such as Child porn, is illegal..and the govt. has every right to demand oversight.

But a bit off topic?

My intent here was to warn~
 
I've been thinking of making Duck Duck my default browser. Tired of the Google ad pop-ups I get on occasion based on browsing history.
 
I've been thinking of making Duck Duck my default browser. Tired of the Google ad pop-ups I get on occasion based on browsing history.
I recommend it..as they don't track you--used in conjunction with Firefox browser--it has the ability to stop ads in their tracks...block all social media trackers and referrers and warn you about malicious scripts.

This site, for example, is like night and day when viewing it with Google and Explorer--that are designed to let the masters through your defenses.
 
I've been thinking of making Duck Duck my default browser. Tired of the Google ad pop-ups I get on occasion based on browsing history.
I recommend it..as they don't track you--used in conjunction with Firefox browser--it has the ability to stop ads in their tracks...block all social media trackers and referrers and warn you about malicious scripts.

This site, for example, is like night and day when viewing it with Google and Explorer--that are designed to let the masters through your defenses.

I use Safari on my iMac and iPhone but go to Firefox on occasion when a site has some sort of Mac issue. Don't see that very often. Duck Duck is a good idea though. Google is becoming more invasive and less trustworthy.
 
[A couple of times in the past few days, when I've done a Google search, it's gone to a big CONGRATULATIONS YOU'RE THE 5 MILLIONTH SEARCH AND YOU CAN WIN....then there's boxes to click to find your prize--lots of electronics, $100 gift cards... BUT YOU ONLY HAVE 15 MINUTES TO CLAIM YOUR PRIZE..... I backed out of it the first time and it popped up again a couple days later.

Don't know if it was legit, but I didn't trust it.

It's most certainly not legit.

 
[A couple of times in the past few days, when I've done a Google search, it's gone to a big CONGRATULATIONS YOU'RE THE 5 MILLIONTH SEARCH AND YOU CAN WIN....then there's boxes to click to find your prize--lots of electronics, $100 gift cards... BUT YOU ONLY HAVE 15 MINUTES TO CLAIM YOUR PRIZE..... I backed out of it the first time and it popped up again a couple days later.

Don't know if it was legit, but I didn't trust it.

It's most certainly not legit.

Thank you! Glad I smelled it in time! Can't imagine where I picked it up, but I have downloaded a few apps to watch tv shows like the Super Bowl and the President's speeches. Or one of the bazillion ads that run on the side of my screen on this forum.
 

Forum List

Back
Top