Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Fake Laravel packages on Packagist deploy RAT on Windows, macOS, and Linux

Artemis II mission sets stage for lunar return and beyond

APT41-linked Silver Dragon uses Cobalt Strike and Google Drive C2 to target governments

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Black Cat behind SEO-tainting malware campaign targeting popular software search
Identity

Black Cat behind SEO-tainting malware campaign targeting popular software search

userBy userJanuary 7, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 7, 2026Ravi LakshmananCybercrime/Software Security

A cybercriminal organization known as Black Cat is believed to be involved in search engine optimization (SEO) poisoning campaigns that use fraudulent sites promoting popular software to trick users into downloading backdoors that can steal sensitive data.

According to a report published by the China National Computer Network Emergency Response Technology Team/Coordination Center (CNCERT/CC) and Beijing Weiwu Online (also known as ThreatBook), the operation is strategically designed to push fake sites to the top of search results on search engines such as Microsoft Bing, specifically targeting users looking for programs such as Google Chrome, Notepad++, QQ International, and iTools.

cyber security

“Users who visit these top phishing pages are directed to carefully constructed download pages where they attempt to download software installation packages bundled with malicious programs,” CNCERT/CC and ThreatBook said. “Once installed, the program embeds a backdoor Trojan horse without the user’s knowledge, allowing the attacker to steal sensitive data from the host computer.”

Black Cat has been active since at least 2022 and is credited with orchestrating a series of attacks aimed at data theft and remote control using malware distributed through SEO poisoning campaigns. In 2023, the group allegedly impersonated AICoin, a popular cryptocurrency trading platform, and stole at least $160,000 worth of cryptocurrencies.

In the latest round of attacks, users searching for Notepad++ are provided with a link to a convincing phishing site purporting to be related to a software program (‘cn-notepadplusplus’).[.]com”). Other domains registered by Black Cat include ‘cn-obsidian’.[.]com,””cn-winscp[.]com” and “notepadplusplus[.]yeah. ”

The presence of “cn” in the domain name indicates that the attackers are specifically targeting Chinese users who may be looking for such tools via search engines.

If an unsuspecting user clicks on the “download” button on the fake website, they will be redirected to another URL that mimics GitHub (“github.zh-cns”).[.]You can download a ZIP archive from “top”). Inside the ZIP file is an installer that creates a shortcut on the user’s desktop. This shortcut acts as an entry point to sideload a malicious DLL and launch a backdoor.

cyber security

The malware establishes a connection with a hard-coded remote server (‘sbido’).[.]com:2869″) to steal web browser data, log keystrokes, extract clipboard contents, and other valuable information from a compromised host.

CNCERT/CC and ThreatBook noted that the Black Cat cybercrime syndicate compromised approximately 277,800 hosts across China between July 7 and 20, 2025, bringing the highest daily number of compromised machines in the country to 62,167.

To reduce risk, users are advised not to click on links from unknown sources and to download software from trusted sources.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCES 2026: Follow live news from Caterpillar and Nvidia, and enjoy surprises from robotaxis, robots, and the show floor.
Next Article NASA telescope combines 100 maps of the universe into one: ‘Every astronomer will find something of value here’
user
  • Website

Related Posts

Fake Laravel packages on Packagist deploy RAT on Windows, macOS, and Linux

March 4, 2026

APT41-linked Silver Dragon uses Cobalt Strike and Google Drive C2 to target governments

March 4, 2026

CISA adds actively exploited VMware Aria operational flaw CVE-2026-22719 to KEV catalog

March 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Fake Laravel packages on Packagist deploy RAT on Windows, macOS, and Linux

Artemis II mission sets stage for lunar return and beyond

APT41-linked Silver Dragon uses Cobalt Strike and Google Drive C2 to target governments

UK allocates £30m to strengthen satellite communications sector

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.