Cyber Security News

Hackers Manipulate Search Results to Target IT Pros with Trojanized PuTTY and WinSCP

Arctic Wolf has uncovered a cunning cybersecurity threat that exploits search engine optimization (SEO) poisoning and malvertising tactics to distribute Trojanized versions of widely used IT tools such as PuTTY and WinSCP.

This campaign cunningly targets IT professionals and system administrators, individuals who frequently rely on these tools for secure file transfers and remote system management.

Malvertising Campaign Unveiled

By manipulating search engine results and placing malicious sponsored ads on platforms like Bing, threat actors have created a deceptive web of fake websites that mimic legitimate sources.

Example of Malicious Sponsored PuTTY Ad on Bing.

Unsuspecting users who download from these fraudulent sites inadvertently install malware, posing a significant risk to both individual systems and organizational security.

The mechanics of this attack are both sophisticated and stealthy. The malicious websites host Trojanized installers of PuTTY and WinSCP, which, upon execution, deploy a backdoor identified as Oyster or Broomstick.

These backdoor grants attackers unauthorized access to the compromised system, potentially leading to data theft, lateral movement within networks, or further malware deployment.

Technical Breakdown of the Persistence Mechanism

To ensure persistence, the malware creates a scheduled task that executes every three minutes, leveraging a malicious DLL file named twain_96.dll.

This DLL is executed via rundll32.exe using the DllRegisterServer export, a technique that abuses the DLL registration process to maintain a foothold on the infected system.

While only PuTTY and WinSCP have been confirmed as targets in this campaign, Arctic Wolf warns that other IT tools could also be weaponized in similar attacks, urging heightened vigilance across the board.

The implications of this campaign are far-reaching, especially for IT environments where trust in tools like PuTTY and WinSCP is paramount.

A single infected system could serve as an entry point for broader network compromise, making it imperative for organizations to act swiftly.

Arctic Wolf strongly recommends that IT teams and users avoid relying on search engines to download administrative tools. Instead, software should be sourced exclusively from vetted internal repositories or directly from official vendor websites.

This practice significantly reduces the risk of falling victim to SEO poisoning and malicious ads that lead to Trojanized downloads.

Furthermore, organizations are advised to educate their staff, particularly IT personnel, about the dangers of unverified download sources and to implement strict policies governing software acquisition.

As a proactive defense measure, Arctic Wolf has identified several domains linked to this malicious activity that should be blocked immediately to prevent access to harmful download sources.

By integrating these indicators of compromise (IOCs) into security controls such as firewalls and endpoint protection systems, organizations can minimize their exposure to this ongoing threat.

This campaign serves as a stark reminder of the evolving tactics employed by cybercriminals and the critical need for robust cybersecurity hygiene in today’s digital landscape.

Indicators of Compromise (IOCs)

TypeIndicator
Domainupdaterputty[.]com
Domainzephyrhype[.]com
Domainputty[.]run
Domainputty[.]bet
Domainputtyy[.]org

Stay Updated on Daily Cybersecurity News. Follow us on Google NewsLinkedIn, and X.

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…

6 hours ago

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…

6 hours ago

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…

6 hours ago

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…

7 hours ago

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…

7 hours ago

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…

8 hours ago