Chinese users searching the Internet for legitimate software such as Notepad++ and VNote may be fooled by malicious ads and fake links that distribute infected versions of the software and deploy Geacon (a Golang-based implementation of Cobalt Strike) on their systems.

"The malicious website found in the search notepad++," said Kaspersky researcher Sergey Puzan.
See also: Google ads: Malicious ads promote fake chat apps
“Opening it, an attentive user will immediately notice a significant inconsistency : the website address contains the line vnote, the title refers to downloading Notepad (an analogue of Notepad++, also distributed as open source software), and the image shows Notepad++. In fact, the packages downloaded from here contain Notepad++.“.
The fake website, named vnote.fuwenkeji[.]cn, contains download links for Windows, Linux , and macOS of the software. The link for the Windows version leads to the official Gitee repository that contains the Notepad– installer (“Notepad- -v2.10.0-plugin-Installer.exe”).
The Linux and macOS versions lead to malicious installation packages hosted at vnote-1321786806.cos.ap-hongkong.myqcloud[.]com.
Similarly, fake websites resembling VNote (“vnote[.]info” and “vnotepad[.]com”) lead to the same set of links myqcloud[.]com, which also lead to a Windows hosted on the domain. The links to the potentially malicious versions of VNote are no longer active.
See also: Fake Google Ads mimic Kinsta pages
An analysis of the infected Notepad–installers reveals that they are designed to retrieve a next-stage payload from a remote server. This is a backdoor, which bears similarities to Geacon.
It has various capabilities, such as creating SSH connections, performing file operations, enumerating processes, accessing clipboard content, executing files, sending and receiving files, taking screenshots, and even entering sleep mode.

Protection
One of the most effective ways to protect users is through internet safety education. Users should be aware of the risks involved in downloading software from untrusted sources and clicking on ads that look suspicious.
Additionally, using a reputable antivirus can provide significant protection. These programs can detect and remove suspicious programs before they can cause damage to the user's computer.
See also: Meta fined for tracking users for the purpose of "behavioral advertising"
Using software that provides protection against malicious ads (adware) is also a good option. These programs can prevent malicious ads from appearing and protect users from installing trojanized software.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, users should keep their operating system and all applications up to date. These updates often include security that can protect users from the latest threats.
Source: thehackernews.com
