Ransomware Gangs Use SEO Poisoning to Infect Visitors

Share post:

SEO poisoning is on the rise and is currently being used by two well-known ransomware gangs Gootloader and SolarMarket to serve payloads on targets.

The practice is an attack method based on the optimization of websites using ‘black hat’ SEO techniques to place higher in Google search results <span class=”s1″></span>

According to security researchers in Menlo, the optimized pages appear in search results as PDFs that are clicked by users to download a document after clicking the prompt.

Clicking on the download button redirects users through a number of websites that ultimately drop a malicious payload.

Researchers also found that instead of having a malicious site instead, they hacked legitimate WordPress sites that has a good Google search ranking, and they do this by exploiting an undisclosed flaw in the “Formidable Forms” WordPress plugin.

Those using the above plugin are asked to upgrade to version 5.0.10 or higher.

For more information, read the original story in Bleeping Computer.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

UK legislation bans weak passwords

Starting Monday, the UK will enforce new laws banning the sale of devices with weak default passwords such...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways