A study revealed that Batloader, a malicious software downloader, exploits Google ads to distribute secondary payloads such as Vidar Stealer and Ursnif.
See also: Medusa ransomware targets companies around the world

According to cybersecurity firm eSentire, malicious ads are being used to mislead a wide range of legitimate apps and services such as Adobe, ChatGPT , Spotify, Tableau, and Zoom.
The name BATLOADER is apt - it does exactly what its name suggests - it distributes malicious payloads, such as information stealers, financial account malware , Cobalt Strike, and ransomware.
A characteristic feature of BATLOADER operations is the use of software masquerading techniques to spread malicious software.
See also: Dark Pink: Attacks government/military organizations with KamiKakaBot malware
This is achieved by creating similar websites that host Windows installation files disguised as legitimate applications to trigger the infection sequence when a user searching for the software clicks on a rogue ad on the Google search results page.

These MSI installer files, when executed, run Python scripts that contain the BATLOADER payload to retrieve the next-stage malicious software from a remote server.
This attack methodology is a slight departure from those observed in December 2022, when MSI installation packages were used to execute PowerShell scripts and ultimately download data-stealing malware .
Through eSentire's analyses, other BATLOADER samples exhibited further functionality that allows the malware to gain persistent access to enterprise networks.
In the wake of Microsoft's decision to block macros in Office by default from files downloaded from the internet, malicious ads on search engines have skyrocketed – a dramatic event that now takes its place in this newer development.
See also: Clop ransomware: Hacked companies via GoAnywhere MFT zero-day
“Threat actors are abusing Google’s ad network by purchasing advertising space for popular keywords and their related typos,” cybersecurity firm Malwarebytes in July 2022.
“BATLOADER continues to evolve and improve since it first appeared in 2022”, reported eSentire.
“BATLOADER intentionally targets and misrepresents popular enterprise applications to exploit them as a means of profit through fraud or intrusion. As these familiar applications are often found on commercial networks, they provide an opportunity for attackers to gain access more easily than ever before.”
Information source: thehackernews.com
