{"id":45272,"date":"2021-09-08T12:36:09","date_gmt":"2021-09-08T04:36:09","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=45272"},"modified":"2021-09-08T12:36:11","modified_gmt":"2021-09-08T04:36:11","slug":"sophos-uncovers-gootloaders-seo-manipulation-hacked-website-campaign-that-targets-business-users","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2021\/09\/08\/sophos-uncovers-gootloaders-seo-manipulation-hacked-website-campaign-that-targets-business-users\/","title":{"rendered":"Sophos uncovers Gootloader\u2019s SEO manipulation, hacked website campaign that targets business users"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Sophos, a global leader in next-generation cybersecurity, published <a href=\"https:\/\/news.sophos.com\/en-us\/2021\/03\/01\/gootloader-expands-its-payload-delivery-options\">research<\/a> earlier this year on how the operators behind the \u201cGootloader\u201d malware delivery platform were poisoning websites with malicious content and manipulating search engine optimization (SEO) to ensure that these hacked websites appeared among the top search results.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Recently, Sophos researchers have now published an <a href=\"https:\/\/news.sophos.com\/en-us\/2021\/08\/12\/gootloaders-mothership-controls-malicious-content\/\">update<\/a> to the Gootloader research that reveals the following:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The operators behind Gootloader ensure that a web search will find and accept the compromised sites as one of the most suitable targets.<\/li><li>This is no rudimentary process, as the search results that deliver Gootloader pages are often the top result for the specific query that leads victims to them.<\/li><li>The malicious code that runs on the compromised websites<\/li><li>The \u201cmothership\u201d server that controls the infection process and provides the content that is delivered by the compromised sites<\/li><li>The most frequently poisoned search terms that reveal Gootloader is targeting corporate internet users rather than consumers<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Gabor Szappanos, threat research director at Sophos, said: \u201cGootloader uses SEO optimization and social engineering, a combination that is not commonly seen in malware delivery. The usually recommended safety instructions to overcome common threats are not sufficient here. Organizations need to understand how this type of attack works, as outlined in the Sophos research, to be able to recognize it and be ready and able to defend against it.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos recommends that individual internet users also look out for the following warning signs:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Search results that point to websites for businesses that have no logical connection to the advice they appear to offer<\/li><li>Advice that precisely matches the search terms used in the initial question<\/li><li>A \u2018message board\u2019-style page that features text and a download link that also precisely matches the search terms used in the initial Google search<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Sophos <a href=\"https:\/\/www.sophos.com\/en-us\/products\/endpoint-antivirus.aspx?&amp;cmp=17464&amp;utm_campaign=GPD-2019-UKI-Google-PaidSearch-InterceptX-Brand-DG-17464&amp;utm_medium=cpc&amp;utm_content=B_InterceptX&amp;utm_term=intercept+x&amp;utm_source=google-search&amp;gclid=Cj0KCQiA962BBhCzARIsAIpWEL2jnCZxJ0JRb4Pvsp6laibzYad9KsKK1LgrPAdkJaxu1b_RZUXivYsaAiqtEALw_wcB\">Intercept X<\/a> protects users by detecting the actions and behaviors of malware like Gootloader, such as the delivery of Cobalt Strike or the use of its process hollowing techniques to inject malware onto a running system.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gootloader uses SEO optimization and social engineering, a combination that is not commonly seen in malware delivery. The usually recommended safety instructions to overcome common threats are not sufficient here. Organizations need to understand how this type of attack works, as outlined in the Sophos research, to be able to recognize it and be ready and able to defend against it.<\/p>\n","protected":false},"author":6,"featured_media":45273,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[54,2103,206],"class_list":["post-45272","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-security","tag-security-breach","tag-sophos"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/45272","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=45272"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/45272\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/45273"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=45272"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=45272"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=45272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}