A new malicious advertising campaign on Google Search targets users looking to download the popular text editor Notepad++, using advanced techniques to evade detection and analysis.
See also: Notepad++ 8.5.7 fixes serious vulnerabilities

Malicious actors have increased their abuse of Google Ads in malicious advertising campaigns to promote websites that distribute malware.
According to Malwarebytes, which detected the Notepad++ malicious advertising campaign, it has been running for several months, but has managed to go unnoticed all this time.
The final payload delivered to victims is unknown, but Malwarebytes says it is likely Cobalt Strike, which typically precedes ransomwarethat result in significant losses.
The Notepad++ malicious advertising campaign promotes URLs that are apparently unrelated to the software, but uses misleading titles that appear in Google search results ads. This SEO strategy was greatly abused in this case, and because the titles are much larger and more visible than the URLs, many people are likely to fall for the trap.
After victims click on any of the ads, a redirection step checks their IP to filter out users who are likely to be crackers, VPNs, bots , etc., directing them to a fake website that does not have any malicious content.
Instead, victims are redirected to “notepadxtreme[.]com“, which mimics the real Notepad++ website, providing download links for various versions of the text editor. When visitors click on these links, a second system check is performed with a JavaScript to confirm that there are no anomalies or indications that the visitor is using a sandbox.
See also: Notepad gets tabs in Windows 11

Victims selected as suitable targets then receive an HTA script, which has a unique ID, presumably to allow attackers to track their infections. This payload is only served once per victim, so a second visit results in a 404 error.
examination of the HTA script yielded no useful information. However, analysts spotted the same file in a VirusTotal upload from July. The file attempted to connect to a remote domain on a custom port, which researchers believe likely belonged to a Cobalt Strike deployment.
To avoid downloading malware when searching for specific software tools, try to avoid promoted results in Google search and double-check that it is the official domain. If you are not sure about the true website of the project, check the “About” page, documentation, Wikipedia page, and official social media.
The impacts and damage these harmful Google ads can cause are wide-ranging and devastating. They range from data loss to undermining trust in digital security.
See also: Privacy Sandbox: Uses Chrome browsing history for ads
Loss of Personal and Professional Data
Often, the malware promoted through these ads is designed to steal sensitive and personal data from unsuspecting users. This information can include names, social security numbers, bank accounts, and credit cards.
Undermining Trust in Digital Security
When users find themselves the victims of an attack through malicious online advertising, they question the security and protection of their data. This can delay the acceptance and implementation of technologies and digital solutions in general, especially in cases where they play a central role in the survival and development of businesses and organizational structures.
Economic Damage
In addition to the loss of personal data and the resulting breach of security practices, another important element of malicious advertising is financial damage. This often occurs through stolen credit cards and the loss of large sums of money.
Source: bleepingcomputer
