Automatically translated.View original post

Black Cat hackers drugged SEO release malware

Black Cat group hackers drugging SEO deceiving people searching for fake web ringing apps to release malware

SEO or Search Engine Optimization is a website management strategy used by marketers to make the website top when searching with a defined set of words, but it's another way that hackers like to use to spread malware.

According to a report by the website, The Hacker News mentioned the detection of a malware distribution campaign by SEO (or ThreatBook) by a group of hackers from China called Black Cat, a cybersecurity organization from China, the National Computer Network Emergency Response Technical Team / Coordination Center of China (CNCERT / CC) and Beijing Weibu Online (or ThreatBook), came forward to reveal the campaign. The hackers will use SEO methods to push websites that claim to be a source of downloading famous applications such as Google Chrome, Notepad + +, QQ International and iTools to high levels. On a popular Search Engine like Bing to trick victims into entering websites in such groups with the aim of downloading fake applications and installing malware.

After the victim has successfully entered the site in such a group, the site will use various techniques to retrieve the victim to the fake application download page. If the victim downloads the application, when the installation is complete, it will lead to the installation of a malware type that opens the back door of the system or the backdoor (the source does not name the malware) without the victim's knowledge, ultimately leading to the loss of important information.

Black Cat hackers have not started this year, but since 2022, using the same technique to spread malware of the remote access trojan, and in 2023, the group released a malware application disguised as a Krypto Curren C application called AICoin that could steal more than US $160,000 (4,963,200).

And in this latest campaign, it is deceiving victims to download fake Notepad + + text management applications through a website that is so disguised as the original website with the domain name "cn-notepadplusplus [.] com." In addition to the aforementioned domain, hackers have also written down other domains, such as "cn-obsidian [.] com," "cn-winscp [.] com," and "notepadplusplus [.] cn" on the domain, it is a clear intention that they intend to head a group of Chinese users or Chinese users in particular by the Download button on these sites. If the victim presses the website, it is Redirect the victim will change the target of the victim to another fake website disguised as a repo or repository. Github, whose domain name is "github.zh-cns." The file downloaded by the victim is a compressed file in the .Zip genus with a fake installation file. After installation, a shortcut will be created on the desktop screen. This file will download the malware file in the DLL file format.

The malware, after embedding itself on the machine, contacts a C2 or Command and Control server with the domain name "sbido [.] com: 2869." The domain is embedded as a constant in the malware code. The malware has the ability to steal data, including data on Clipboard, web browsers, keyboard printing, and important data on the machine. After stealing the data, the malware sends the data to this server.

According to a cybersecurity assessment, there have already been more than 277,800 victims of such hackers in China just in a few days between December 7 and 20, 2025. The number of victims per day has peaked at 62,167 within a single day. Therefore, users need to be very careful to find the software they need and regularly observe the name of the website not to enter the wrong website to ensure safety.

# Trending # lemon 8 diary # seo # freedomhack # hackers

1/30 Edited to

... Read moreการระบาดของมัลแวร์โดยกลุ่มแฮกเกอร์ Black Cat ผ่านการวางยา SEO หรือที่เรียกว่า SEO Poisoning เป็นตัวอย่างที่ชัดเจนของภัยไซเบอร์ยุคใหม่ที่อาศัยกลยุทธ์ทางการตลาดออนไลน์มาสร้างความเสียหาย แทนที่จะแค่เน้นให้เว็บที่ปลอมแปลงขึ้นมาติดอันดับบนหน้าแรกของ Search Engine เหมือนกับ SEO ปกติ กลับใช้วิธีจูงใจผู้ใช้ให้ดาวน์โหลดไฟล์แอปพลิเคชันปลอมที่แฝงมัลแวร์ซึ่งอาจทำให้เครื่องคอมพิวเตอร์ติดไวรัสโดยไม่รู้ตัว จากประสบการณ์การใช้งานอินเทอร์เน็ตในชีวิตประจำวัน ผมพบว่า SEO เป็นหนึ่งในเครื่องมือที่นิยมกันอย่างมากในการค้นหาข้อมูลหรือดาวน์โหลดโปรแกรม แต่ภัยจาก SEO Poisoning ก็เป็นเรื่องที่เราไม่สามารถมองข้ามได้ เพราะเว็บปลอมมีการออกแบบหน้าเว็บไซต์และโดเมนให้เหมือนของจริงมาก เช่น กรณีของ Notepad++ ซึ่งโดยปกติเป็นโปรแกรมแก้ไขข้อความที่ได้รับความนิยมอย่างสูง มีฟีเจอร์รองรับหลายภาษาและดีไซน์ที่ใช้งานง่าย แต่หากดาวน์โหลดจากเว็บปลอม เช่น cn-notepadplusplus.com หรือโดเมนอื่น ๆ ที่แฮกเกอร์จดทะเบียนไว้ อาจทำให้เราติดตั้งมัลแวร์โดยไม่รู้ตัว สิ่งที่ผมแนะนำสำหรับผู้ใช้งานทั่วไปคือการตรวจสอบโดเมนเว็บไซต์อย่างละเอียดก่อนดาวน์โหลด โดยเฉพาะอย่างยิ่งโปรแกรมที่สำคัญและที่ใช้งานบ่อย นอกจากนี้ การอัปเดตโปรแกรมระบบปฏิบัติการและซอฟต์แวร์แอนตี้ไวรัสอย่างสม่ำเสมอจะช่วยเพิ่มเกราะป้องกันจากการโจมตีของมัลแวร์ที่มีความซับซ้อนมากขึ้นเรื่อย ๆ ส่วนมัลแวร์ที่ปล่อยโดย Black Cat นั้น มีคุณสมบัติที่น่ากังวลมาก เพราะมันไม่ได้แค่ทำหน้าที่ขโมยข้อมูลบน clipboard หรือข้อมูลเบราว์เซอร์เท่านั้น แต่ยังสามารถบันทึกการพิมพ์ของเรา (keylogging) รวมถึงส่งข้อมูลกลับไปยังเซิร์ฟเวอร์ Command and Control (C2) ของแฮกเกอร์ ซึ่งส่งผลให้ข้อมูลส่วนตัว ข้อมูลสำคัญทางธุรกิจ หรือแม้กระทั่งรหัสผ่านทางการเงินอาจถูกขโมยไปได้อย่างง่ายดาย ในทางเทคนิค วิธีการวางยา SEO เช่นนี้สะท้อนให้เห็นว่าการรักษาความปลอดภัยด้านข้อมูลไม่ใช่เรื่องของผู้เชี่ยวชาญเพียงอย่างเดียวเท่านั้น ผู้ใช้งานเองก็มีบทบาทสำคัญที่ต้องตระหนักและระมัดระวังมากขึ้น เช่น การไม่ดาวน์โหลดไฟล์จากเว็บไซต์ที่ไม่น่าเชื่อถือ หรือไม่กดปุ่มดาวน์โหลดที่น่าสงสัย รวมทั้งการใช้เครื่องมือช่วยตรวจสอบและรับรองความปลอดภัยของเว็บไซต์ก่อนทุกครั้ง ท้ายที่สุด เรื่องนี้ย้ำเตือนให้เราเห็นว่าแม้แต่กลยุทธ์ที่ดีอย่าง SEO ก็สามารถถูกดัดแปลงใช้ในทางที่ผิดและอันตรายได้ ดังนั้นไม่ว่าใครจะเป็นผู้ใช้อินเทอร์เน็ต การมีความรู้และความระมัดระวังด้านความปลอดภัยไซเบอร์เป็นสิ่งจำเป็นมากในยุคดิจิทัลนี้

Related posts

SIEGEX is all CHEATERS & HACKERS😭
Why is this game full of cheaters and hackers and bugs🤷‍♀️ #siege #rainbowsixsiege #gaming #streamer #foryou
Phasma

Phasma

35 likes

A young woman with long dark hair, wearing a pink satin shirt, smiles at the camera while sitting at a table. Overlay text reads: 'Tools and sites I use as a cybersecurity student to progress my skills and keep me interested in studying'.
A screenshot of 'The Hacker News' website, displaying various cybersecurity news articles from January 2025, including topics like vulnerabilities, malware, cyber espionage, and AI jailbreak methods. An ad for Zscaler and a banner for CIS Hardened Images are also visible.
A screenshot of the O'Reilly learning platform, showing various books and expert playlists related to AI, engineering, and data. Overlay text highlights the subscription cost ($50/month or $499/year) and its value for accessing books and live events.
Tools and sites I use as a cybersecurity student 🌸
#cybersecuritystudent #cybersecurity #techgirlie
LexiStudies

LexiStudies

107 likes

Do you like hackers?
#hacker #hackers #tricked #fyp
Lil Conscious

Lil Conscious

38 likes

WARNING TO 2.5B GMAIL USERS. Hackers are continuing to target you. Here’s what to do Follow @cybersecuritygirl for more tips #google #gmail #tips #news #techtips
Cybersecurity Girl

Cybersecurity Girl

507 likes

⚠️ The Hidden Dangers of Public Wi-Fi Free Wi-Fi feels convenient, but it can be a trap. Hackers can create what’s called an “evil twin” network—a fake hotspot that looks legitimate. The moment you connect, they can access your data, passwords, banking info, and private messages. Listen
Dannah Eve

Dannah Eve

82 likes

#yungblud
watch4hackers

watch4hackers

6 likes

Taco Tuesday 🤯 Admin Abuse ⁉️ #stealabrainrot #robloxstealabrainrot #roblox #neoskittles
NeoSkittles

NeoSkittles

6 likes

scammers and hackers beware
Hudson
cercofhell

cercofhell

28 likes

WARZONE HACKERS
Warzone is full hackers and call of duty does not care #warzone #hacker #memesdaily #memes🤣 #gaming
DUSTINMYRQ ™

DUSTINMYRQ ™

4 likes

4 In demand Certificates You Need in 2025
Hey Career Girl, I know you want to start off the New Year on the right foot and a certificate is just the thing. Certificates can open the doors to new pathways in the career world that wouldn't have been opened before! Love this type of content? Follow and share! Need Interview P
Lauren|Career Girl

Lauren|Career Girl

164 likes

You shouldn’t be worried about the hackers, you should be worried about your settings. Check out ThreatLocker DAC today #ad #cybersecurity
Cybersecurity Girl

Cybersecurity Girl

28 likes

A message to Minecraft hackers…
You should join the server #minecraft #gaming #fyp
BendersMC

BendersMC

13 likes

A laptop with a cloudy sky wallpaper and a white cup with a red logo. Text overlay reads: 'Free Websites That Saved My GPA AND MY SANITY Sharing So You Don't Struggle Too'.
A laptop screen displays Yahoo search results for 'Quizlet'. An overlay describes Quizlet as a free flashcard tool for memorizing terms, definitions, and formulas, making studying feel like a game.
A laptop screen displays Yahoo search results for 'Unriddle.ai'. An overlay describes Unriddle.ai as a free tool that breaks down notes, articles, or assignments to aid understanding of long readings.
Websites You NEED to Pass Your College Courses
Y’all college is hard enough without trying to figure everything out on your own 😩 So here’s my list of websites that actually helped me pass my classes like, these were in my survival kit. I’m not gatekeeping 🫶🏽 Quizlet When I needed to memorize terms FAST. I used it for flashcards, and the matc
Beauty

Beauty

280 likes

BIG Holiday Costco Shop & Haul | Anchorage, Alaska
vanditsv

vanditsv

2 likes

PSA PSA PSA ‼️ #fyp #hackers #facebook #scammers #viral
Kay’s House ✨

Kay’s House ✨

2 likes

Hackers are using tricks & steal financial info.🌸🍋
SECURITY TIPS: Be careful from hackers they use multiple different types of software and tricks to steal data from computers, cell phones or other devices to steal your data, financial information and personal details. When they hack via computer systems Showing they are from Microsoft Security Ale
Mujahid Bakht

Mujahid Bakht

6 likes

Hackers Be Like:
#fypage
AidenIsMyself

AidenIsMyself

0 likes

Hackers
How call of duty has me #call of duty #hacker #warzone
Stevie_Wonders

Stevie_Wonders

1 like

warzone hackers be mad little babies
#cod #ps5 #gamergirl #warzone #fuckhackers
Twilightvile

Twilightvile

2 likes

I wanted a real project I could actually show, not just talk about. So I used Atoms ⚛️ Check it out here: https://tinyurl.com/3xzc8xbe It feels like having a whole AI team helping me: 🔍 they do the deep research first 🏁 then Race Mode builds different versions so I can compare 👥 I just pick
emilie.studygram

emilie.studygram

19 likes

Have Gamer Kids Who Love Ramen? 👀 Take Them Here!
Have gamer children who love to eat ramen noodles like mine? 👀 Gone and take them to The Forks USA in Suwanee and let them have a ball ! 📍The Forks USA Self Ramen & PC Cafe 💰: $8.99 for ramen plus add on items (chicken, rice cakes, crab, etc.) & $6.99 per hour for each person who plans
Call Me Pooh ✨

Call Me Pooh ✨

84 likes

Prayers for Jamaica 🇯🇲 — opening Hacker’s Slumber,
Cousin B

Cousin B

0 likes

HACKERS IN THE BETA
Blackops 7 has hackers already…. #hacker #blackops7 #bo7
Goofstha

Goofstha

1 like

If you have the Samsung, you need to watch this and update your phone immediately 
Cybersecurity Girl

Cybersecurity Girl

48 likes

Kalebdavis19

Kalebdavis19

1 like

Ban Hackers
Vinicius Jr 🇧🇷 #fcmobile #eafcmobile #fifamobile #fcmobile25 #eafc
manuelofficial_13

manuelofficial_13

1 like

Bigfoot Super Hackers.
#manthoughts #hackers #laughoutloud #bigfootvlog #lifetips
Alien Hayes

Alien Hayes

11 likes

A hand holds a pink iPhone with text 'Tech 101 For Beginners' and 'Tips to help Non-Tech Savvy Users,' accompanied by laptop and phone app icons, against a brick background.
A pink iPhone in its box, illustrating the tip to 'Keep Your Devices Updated' with text explaining why updates help and advising to enable automatic updates.
An iPhone screen displaying app icons and display settings, accompanying the tip to 'Use Strong, Unique Passwords' with reasons why and advice on using combinations and password managers.
Tech Hacks For Beginners 📲💻😬
I have some great tips for non-tech savvy tech users. I know these tips will help you learn your tech more quickly and effectively. 1. Keep Your Devices Updated Why It Helps: Updates often contain security patches and improvements that help your device run smoothly. Tip: Enable automatic updat
Joy 📚

Joy 📚

282 likes

Replying to @Red what parts or the dark web live in your brain rent free? #scarystories #horror #eductional #darkweb
Liz Cooper🦋

Liz Cooper🦋

42 likes

Nice one boys
#cod #callofdutyp #codapartments #pvp #ashika #finalexfil #ashikapowerplant #almazrah #talkingshit #squad #dmz #gamer #sniper #headshot #longrange #headbussa #letthebodieshitthefloor #proxie #closecombat #closecombatfight #talkingshit #kamikazi #nomercy #nolovelost #groundhack #rocke
TheAuditor

TheAuditor

1 like

Look world I just made this new Facebook account a minute ago Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg just locked and suspended it cause I'm sharing my legal paperwork and federal complaints I'm filling
glentrump359

glentrump359

0 likes

Don’t fall for these scams in London 🇬🇧❌
3 scams to avoid when visiting London 🇬🇧❌ 📍Fake Wifi hotspots Something else I do when traveling to avoid hackers from public Wifi networks is use a VPN that can protect your personal information and online identity. I’d still avoid connecting to any public Wifi when you don’t need to, thou
Iisa Hero

Iisa Hero

34 likes

The image shows a keyboard with a fingerprint icon, overlaid with "OUTSMART HACKERS" and "Secrets they don't want you to know," serving as the title for a guide on cybersecurity.
This image explains hackers use software to guess passwords and advises creating long passwords with a random mix of letters, numbers, and symbols to defend against such attacks.
The image warns that hackers try common passwords and advises users to defend themselves by avoiding easy words/phrases and not reusing passwords across different sites.
SECRETS Hackers DON’T Want You to Know!
After hackers got into my Facebook account and completely erased it, I dusted myself off and started a deep dive to understand why and how hackers work. The best way to protect yourself is to outsmart them. Here are 5 secrets Hackers DON'T want you to know! Share this with everyone! #lemon8pa
techgirljen

techgirljen

425 likes

Don’t Use Airport USB Chargers!
TSA is now advising NOT to use Airport USB Chargers. Bring your own USB charging bricks. "Hackers can install malware at USB ports (we’ve been told that’s called 'juice/port jacking'). So, when you’re at an airport do not plug your phone directly into a USB port. Bring your TSA-compl
Destination & Travel Junkies

Destination & Travel Junkies

151 likes

🚨 16 Billion passwords leaked - the largest breach ever 🚨 Here is how it happened and what you can do to be safe. #news #databreach #cybersecuritytips #onlinesafety
Cybersecurity Girl

Cybersecurity Girl

125 likes

This is the newest way people are getting hacked and if you use AI to answer your questions and give you advice, you need to watch this.Thanks to Huntress for reporting this Follow for more
Cybersecurity Girl

Cybersecurity Girl

15 likes

A list titled 'Top Cybersecurity GitHub Projects' created by Dan Nanni, updated 2026/1. It displays 25 GitHub projects with their star counts, repository names, and brief descriptions, covering tools for hacking, pentesting, reverse engineering, proxies, and security scanning.
Top cybersecurity-related GitHub projects
My top GitHub list for cybersecurity projects is updated for this month 😎👆 Explore top-ranked FOSS projects spanning both the defensive and offensive sides of cybersecurity. Find a high-res pdf book with all my cybersecurity related infographics from https://study-notes.org #cybersecurity
Dan Nanni

Dan Nanni

34 likes

Attention Instagram users! A data leak exposed 17.5 million users' info. Find out what happened and learn how to keep your account secure. #news #technews #instagramdataleak
Cybersecurity Girl

Cybersecurity Girl

14 likes

10 things I NO LONGER do as a CYBERSECURITY EXPERT 1. Hand out my real birthday, name, phone number etc online 2. Create online accounts I don’t need 3. Post vacation pics while I’m still away 4. Believe free Wi-Fi or apps is actually free 5. Save my logins in Notes or browsers 6. Use my mom’
Cybersecurity Girl

Cybersecurity Girl

6 likes

A smartphone displays a message asking God to unblock it due to hackers. A patterned pad and colorful items are in the hazy background. The image includes Lemon8 branding and a username.
God, please unblock this android, hackers have in
Olga Ledbetter

Olga Ledbetter

37 likes

A stylized AI-generated portrait of a person with vibrant red hair, striking blue eyes, and long eyelashes. The image includes text overlays 'AI-generated content, for entertainment only' and 'Lemon8 @cynthgir'.
I think I may have been hacked🥺😕🫣
I keep getting notifications on comments I have made on posts? I can't see the comments and access the mean/hateful comments that are in question. Please excuse me as I figure this out 🥺😕🙏 I don't rage-bait or click bait on social media. I apologize for any NASTY/Mean things that hackers ha
Cynthgirrl777

Cynthgirrl777

7 likes

Just An FYI This Is How So Many People are Getting Hacked!!! Plz Don’t Fall For Message Like These!!! it’s A Fake Account!!! #fakeaccount #hackers
MaryBell

MaryBell

2 likes

me rocking the shades yesterday at my day group ☺️
Øg Hackers Dèmøn

Øg Hackers Dèmøn

1 like

King Trump
GrouchyGrandpaChannel

GrouchyGrandpaChannel

4 likes

Look world on my new Snapchat right now want let anyone see my stories rejecting all of them Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers everyday all day and night and morning harassing me on all my social media ap
glentrump359

glentrump359

0 likes

These Hackers on Marvel Rivals getting crazy!
#marvelrivals #twitchtv #followme #Hackers #marvelfunny
MisFit Miracles

MisFit Miracles

1 like

Most small businesses believe they’re too small to be hacked… but that’s not how cyber risk works. In today’s connected world, your business doesn’t stand alone. You rely on vendors, payroll systems, cloud platforms, CRMs, IT providers, to run your operations. But here’s the truth many people ov
Abby❤️💎

Abby❤️💎

0 likes

A monitor displays the Martin AI assistant dashboard with sections for to-dos, reminders, calendar, and chat, set on a desk with a keyboard and plant, illustrating the phrase "Say what you need, it gets it done."
The Martin AI assistant dashboard is shown, featuring to-dos, reminders, calendar, inbox, and a chat interface for sending schedules, emphasizing its ability to use voice commands for tasks like texting and setting reminders.
The Martin AI assistant dashboard displays to-dos, reminders, calendar, and an inbox with emails, highlighting its function to remember and track information across various platforms without repetition.
Your to-do list just got a personal manager
You know when you have too many tabs open in your brain? This app is like closing all of them... at once. Martin is your Al assistant that actually works like a real one. Need to text someone, forward notes, set reminders, or manage your day? Just tell Martin. It connects with your inbox,
Reverelia

Reverelia

363 likes

See more