SEO Poisoning Attack Delivers Trojanized IT Tools

By

Arctic Wolf has observed the attack since June 2025.

Arctic Wolf has reported a new SEO poisoning attack promoting malicious websites that host Trojanized versions of IT tools such as PuTTY and WinSCP.

“These fake sites aim to trick unsuspecting users – often IT professionals – into downloading and executing Trojanized installers. Upon execution, a backdoor known as Oyster/Broomstick is installed,” says Andres Ramos in the company’s security bulletin.

Arctic Wolf recommends blocking the following specific domains to prevent user access and reduce exposure to these Trojanized versions:

  • updaterputty[.]com
  • zephyrhype[.]com
  • putty[.]run
  • putty[.]bet
  • puttyy[.]org

Learn more at Arctic Wolf.
 
 

 
 
 

07/11/2025

Related content

comments powered by Disqus