Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches

Posted on January 7, 2026January 7, 2026 By CWS

Jan 07, 2026Ravie LakshmananCybercrime / Software program Safety
A cybercrime gang often called Black Cat has been attributed to a SEO (search engine optimization) poisoning marketing campaign that employs fraudulent websites promoting well-liked software program to trick customers into downloading a backdoor able to stealing delicate knowledge.
In accordance with a report printed by the Nationwide Pc Community Emergency Response Technical Staff/Coordination Middle of China (CNCERT/CC) and Beijing Weibu On-line (aka ThreatBook), the exercise is designed to strategically push bogus websites to the highest of search outcomes on search engines like google like Microsoft Bing, particularly focusing on customers searching for applications like Google Chrome, Notepad++, QQ Worldwide, and iTools.

“After visiting these high-ranking phishing pages, customers are lured by fastidiously constructed obtain pages, trying to obtain software program set up packages bundled with malicious applications,” CNCERT/CC and ThreatBook stated. “As soon as put in, this system implants a backdoor Trojan with out the consumer’s data, resulting in the theft of delicate knowledge from the host pc by attackers.”
Black Cat is assessed to be energetic since not less than 2022, orchestrating a collection of assaults designed for knowledge theft and distant management utilizing malware distributed by way of search engine optimization poisoning campaigns. In 2023, the group is claimed to have stolen not less than $160,000 value of cryptocurrency by impersonating AICoin, a preferred digital forex buying and selling platform.

Within the newest set of assaults, customers looking for Notepad++ are served hyperlinks to a convincing phishing web site masquerading as related to the software program program (“cn-notepadplusplus[.]com”). Different domains registered by Black Cat embrace “cn-obsidian[.]com,” “cn-winscp[.]com,” and “notepadplusplus[.]cn.”
The inclusion of “cn” within the domains signifies that the risk actors are particularly going after Chinese language customers who could also be searching for such instruments by way of search engines like google.
Ought to unsuspecting customers find yourself clicking the “obtain” button on the pretend web site, they’re redirected to a different URL that mimics GitHub (“github.zh-cns[.]prime”) from the place a ZIP archive may be downloaded. Current inside the ZIP file is an installer that creates a shortcut on the consumer’s desktop. The shortcut acts because the entry level for side-loading a malicious DLL that, in flip, launches the backdoor.

The malware establishes contact with a hard-coded distant server (“sbido[.]com:2869”), permitting it to steal net browser knowledge, log keystrokes, extract clipboard contents, and different precious data from the compromised host.
CNCERT/CC and ThreatBook famous that the Black Cat cybercrime syndicate has compromised about 277,800 hosts throughout China between 7 and 20, 2025, with the very best day by day variety of compromised machines inside the nation scaling a excessive of 62,167.
To mitigate the chance, customers are suggested to chorus from clicking on hyperlinks from unknown sources and follow trusted sources for downloading software program.

The Hacker News Tags:Black, Campaign, Cat, Malware, Poisoning, Popular, Searches, SEO, Software, Targeting

Post navigation

Previous Post: Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns Delivering Multiple Malware Families
Next Post: Hackers Using Malicious Imageless QR Codes to Render Phishing Attack Via HTML Table

Related Posts

Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain The Hacker News
RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities The Hacker News
Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection The Hacker News
Scattered Spider Arrests, Car Exploits, macOS Malware, Fortinet RCE and More The Hacker News
Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries The Hacker News
Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers
  • MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
  • Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime
  • New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data
  • Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers
  • MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
  • Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime
  • New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data
  • Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark