Beware: Google Ads Promote Malicious CPU-Z App on Fake Windows News Site

A threat actor has been using Google Ads to distribute a trojanized version of the CPU-Z tool, which delivers the Redline info-stealing malware. The malicious advertisement is hosted on a cloned copy of the legitimate Windows news site WindowsReport. Clicking on the ad redirects users to a fake Windows news site, where they are prompted to download a digitally-signed CPU-Z installer containing a malicious PowerShell script. The script downloads the Redline Stealer payload, which can collect sensitive data from web browsers and cryptocurrency wallets. Users are advised to be cautious when clicking on promoted results in Google Search and to verify the legitimacy of the loaded site and domain.
- Google ads push malicious CPU-Z app from fake Windows news site BleepingComputer
- New Malvertising Campaign Uses Fake Windows News Portal to Distribute Malicious Installers The Hacker News
- Hackers have found an insidious way to attack you with malware — don't fall for this Tom's Guide
- Trojanized CPU-Z app on fake Windows news site pushed by Google BleepingComputer
- View Full Coverage on Google News
Reading Insights
0
1
1 min
vs 2 min read
71%
373 → 109 words
Want the full story? Read the original article
Read on BleepingComputer