Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Microsoft Warns of Malvertising Campaign Infecting Over 1 Million Devices Worldwide

The Hacker News by The Hacker News
March 7, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Mar 07, 2025Ravie LakshmananMalvertising / Open Source

Microsoft has disclosed details of a large-scale malvertising campaign that’s estimated to have impacted over one million devices globally as part of what it said is an opportunistic attack designed to steal sensitive information.

The tech giant, which detected the activity in early December 2024, is tracking it under the broader umbrella Storm-0408, a moniker used for a set of threat actors that are known to distribute remote access or information-stealing malware via phishing, search engine optimization (SEO), or malvertising.

“The attack originated from illegal streaming websites embedded with malvertising redirectors, leading to an intermediary website where the user was then redirected to GitHub and two other platforms,” the Microsoft Threat Intelligence team said.

Cybersecurity

“The campaign impacted a wide range of organizations and industries, including both consumer and enterprise devices, highlighting the indiscriminate nature of the attack.”

The most significant aspect of the campaign is the use of GitHub as a platform for delivering initial access payloads. In at least two other isolated instances, the payloads have been found hosted on Discord and Dropbox. The GitHub repositories have since been taken down. The company did not reveal how many such repositories were removed.

The Microsoft-owned code hosting service acts as a staging ground for dropper malware that’s responsible for deploying a series of additional programs like Lumma Stealer and Doenerium, which, in turn, are capable of collecting system information.

The attack also employs a sophisticated redirection chain comprising four to five layers, with the initial redirector embedded within an iframe element on illegal streaming websites serving pirated content.

The overall infection sequence is a multi-stage process that involves system discovery, information gathering, and the use of follow-on payloads such as NetSupport RAT and AutoIT scripts to facilitate more data theft. The remote access trojan also serves as a conduit for stealer malware.

  • First-stage – Establish a foothold on target devices
  • Second-stage – System reconnaissance, collection, and exfiltration, and payload delivery
  • Third-stage – Command execution, payload delivery, defensive evasion, persistence, command-and-control communications, and data exfiltration
  • Fourth-stage – PowerShell script to configure Microsoft Defender exclusions and run commands to download data from a remote server
Malvertising Campaign

Another characteristic of the attacks concerns the use of various PowerShell scripts to download NetSupport RAT, identify installed applications and security software, specifically scanning for the presence of cryptocurrency wallets, indicating potential financial data theft.

“Besides the information stealers, PowerShell, JavaScript, VBScript, and AutoIT scripts were run on the host,” Microsoft said. “The threat actors incorporated use of living-off-the-land binaries and scripts (LOLBAS) like PowerShell.exe, MSBuild.exe, and RegAsm.exe for C2 and data exfiltration of user data and browser credentials.”

Cybersecurity

The disclosure comes as Kaspersky revealed that bogus websites masquerading as the DeepSeek and Grok artificial intelligence (AI) chatbots are being used to trick users into installing a previously undocumented Python information stealer.

DeekSeek-themed decoy sites advertised by verified accounts on X (e.g., @ColeAddisonTech, @gaurdevang2, and @saduq5) have also been employed to execute a PowerShell script that uses SSH to grant attackers remote access to the computer.

“Cybercriminals use various schemes to lure victims to malicious resources,’ the Russian cybersecurity company said. “Typically, links to such sites are distributed through messengers and social networks. Attackers may also use typosquatting or purchase ad traffic to malicious sites through numerous affiliate programs.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
Huawei stellt seine vollständig aktualisierte Xinghe Intelligent Campus Solution vor, um KI-gestützte, erlebnisorientierte Campus-Netzwerke in die KI-Ära zu führen

Huawei stellt seine vollständig aktualisierte Xinghe Intelligent Campus Solution vor, um KI-gestützte, erlebnisorientierte Campus-Netzwerke in die KI-Ära zu führen

Recommended.

Google’s B Wiz Deal Suggests ‘Flurry’ Of Cloud Security M&A Ahead: Analysts

Google’s $32B Wiz Deal Suggests ‘Flurry’ Of Cloud Security M&A Ahead: Analysts

March 18, 2025
TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations

TAG-150 Develops CastleRAT in Python and C, Expanding CastleLoader Malware Operations

September 5, 2025

Trending.

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

July 18, 2025
Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

September 4, 2025
Wesco Declares Quarterly Dividend on Common Stock

Wesco Declares Quarterly Dividend on Common Stock

December 1, 2025
HeyGears Launches Reflex 2 Series 3D Printers – Enabling Users to Go Beyond Prototypes and Start Production

HeyGears Launches Reflex 2 Series 3D Printers – Enabling Users to Go Beyond Prototypes and Start Production

October 24, 2025
⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

March 10, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio