SEO Poisoning Attack Delivers Trojanized IT Tools
Arctic Wolf has reported a new SEO poisoning attack promoting malicious websites that host Trojanized versions of IT tools such as PuTTY and WinSCP.
“These fake sites aim to trick unsuspecting users – often IT professionals – into downloading and executing Trojanized installers. Upon execution, a backdoor known as Oyster/Broomstick is installed,” says Andres Ramos in the company’s security bulletin.
Arctic Wolf recommends blocking the following specific domains to prevent user access and reduce exposure to these Trojanized versions:
- updaterputty[.]com
- zephyrhype[.]com
- putty[.]run
- putty[.]bet
- puttyy[.]org
Learn more at Arctic Wolf.
Subscribe to our ADMIN Newsletters
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Most Popular
Focus On Self-Hosting
• Self-Hosted File Syncing with Seafile
• Wiring the Modern Stack with Node-RED
• Self-Hosted Collaboration with Forgejo
• Self-Hosted PaaS with Coolify
• Build and Host Docker Images
• Self-Hosted Pritunl VPN Server with MFA
Support Our Work
ADMIN content is made possible with support from readers like you. Please consider contributing when you've found an article to be beneficial.
