HomeSecurityNotepad++: Malicious Google Ads Avoid Detection

Notepad++: Malicious Google ads evade detection

A new malicious advertising campaign on Google Search targets users looking to download the popular text editor Notepad++, using advanced techniques to evade detection and analysis.

See also: Notepad++ 8.5.7 fixes serious vulnerabilities

Notepad++

Malicious actors have increased their abuse of Google Ads in malicious advertising campaigns to promote websites that distribute malware.

According to Malwarebytes, which detected the Notepad++ malicious advertising campaign, it has been running for several months, but has managed to go unnoticed all this time.

The final payload delivered to victims is unknown, but Malwarebytes says it is likely Cobalt Strike, which typically precedes ransomwarethat result in significant losses.

The Notepad++ malicious advertising campaign promotes URLs that are apparently unrelated to the software, but uses misleading titles that appear in Google search results ads. This SEO strategy was greatly abused in this case, and because the titles are much larger and more visible than the URLs, many people are likely to fall for the trap.

After victims click on any of the ads, a redirection step checks their IP to filter out users who are likely to be crackers, VPNs, bots , etc., directing them to a fake website that does not have any malicious content.

Instead, victims are redirected to “notepadxtreme[.]com“, which mimics the real Notepad++ website, providing download links for various versions of the text editor. When visitors click on these links, a second system check is performed with a JavaScript to confirm that there are no anomalies or indications that the visitor is using a sandbox.

See also: Notepad gets tabs in Windows 11

Google ads

Victims selected as suitable targets then receive an HTA script, which has a unique ID, presumably to allow attackers to track their infections. This payload is only served once per victim, so a second visit results in a 404 error.

examination of the HTA script yielded no useful information. However, analysts spotted the same file in a VirusTotal upload from July. The file attempted to connect to a remote domain on a custom port, which researchers believe likely belonged to a Cobalt Strike deployment.

To avoid downloading malware when searching for specific software tools, try to avoid promoted results in Google search and double-check that it is the official domain. If you are not sure about the true website of the project, check the “About” page, documentation, Wikipedia page, and official social media.

The impacts and damage these harmful Google ads can cause are wide-ranging and devastating. They range from data loss to undermining trust in digital security. 

See also: Privacy Sandbox: Uses Chrome browsing history for ads

Loss of Personal and Professional Data

Often, the malware promoted through these ads is designed to steal sensitive and personal data from unsuspecting users. This information can include names, social security numbers, bank accounts, and credit cards. 

Undermining Trust in Digital Security

When users find themselves the victims of an attack through malicious online advertising, they question the security and protection of their data. This can delay the acceptance and implementation of technologies and digital solutions in general, especially in cases where they play a central role in the survival and development of businesses and organizational structures. 

Economic Damage

In addition to the loss of personal data and the resulting breach of security practices, another important element of malicious advertising is financial damage. This often occurs through stolen credit cards and the loss of large sums of money.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS