Automatically translated.View original post

Black Cat hackers drugged SEO release malware

Black Cat group hackers drugging SEO deceiving people searching for fake web ringing apps to release malware

SEO or Search Engine Optimization is a website management strategy used by marketers to make the website top when searching with a defined set of words, but it's another way that hackers like to use to spread malware.

According to a report by the website, The Hacker News mentioned the detection of a malware distribution campaign by SEO (or ThreatBook) by a group of hackers from China called Black Cat, a cybersecurity organization from China, the National Computer Network Emergency Response Technical Team / Coordination Center of China (CNCERT / CC) and Beijing Weibu Online (or ThreatBook), came forward to reveal the campaign. The hackers will use SEO methods to push websites that claim to be a source of downloading famous applications such as Google Chrome, Notepad + +, QQ International and iTools to high levels. On a popular Search Engine like Bing to trick victims into entering websites in such groups with the aim of downloading fake applications and installing malware.

After the victim has successfully entered the site in such a group, the site will use various techniques to retrieve the victim to the fake application download page. If the victim downloads the application, when the installation is complete, it will lead to the installation of a malware type that opens the back door of the system or the backdoor (the source does not name the malware) without the victim's knowledge, ultimately leading to the loss of important information.

Black Cat hackers have not started this year, but since 2022, using the same technique to spread malware of the remote access trojan, and in 2023, the group released a malware application disguised as a Krypto Curren C application called AICoin that could steal more than US $160,000 (4,963,200).

And in this latest campaign, it is deceiving victims to download fake Notepad + + text management applications through a website that is so disguised as the original website with the domain name "cn-notepadplusplus [.] com." In addition to the aforementioned domain, hackers have also written down other domains, such as "cn-obsidian [.] com," "cn-winscp [.] com," and "notepadplusplus [.] cn" on the domain, it is a clear intention that they intend to head a group of Chinese users or Chinese users in particular by the Download button on these sites. If the victim presses the website, it is Redirect the victim will change the target of the victim to another fake website disguised as a repo or repository. Github, whose domain name is "github.zh-cns." The file downloaded by the victim is a compressed file in the .Zip genus with a fake installation file. After installation, a shortcut will be created on the desktop screen. This file will download the malware file in the DLL file format.

The malware, after embedding itself on the machine, contacts a C2 or Command and Control server with the domain name "sbido [.] com: 2869." The domain is embedded as a constant in the malware code. The malware has the ability to steal data, including data on Clipboard, web browsers, keyboard printing, and important data on the machine. After stealing the data, the malware sends the data to this server.

According to a cybersecurity assessment, there have already been more than 277,800 victims of such hackers in China just in a few days between December 7 and 20, 2025. The number of victims per day has peaked at 62,167 within a single day. Therefore, users need to be very careful to find the software they need and regularly observe the name of the website not to enter the wrong website to ensure safety.

# Trending # lemon 8 diary # seo # freedomhack # hackers

1/30 Edited to

... Read moreการระบาดของมัลแวร์โดยกลุ่มแฮกเกอร์ Black Cat ผ่านการวางยา SEO หรือที่เรียกว่า SEO Poisoning เป็นตัวอย่างที่ชัดเจนของภัยไซเบอร์ยุคใหม่ที่อาศัยกลยุทธ์ทางการตลาดออนไลน์มาสร้างความเสียหาย แทนที่จะแค่เน้นให้เว็บที่ปลอมแปลงขึ้นมาติดอันดับบนหน้าแรกของ Search Engine เหมือนกับ SEO ปกติ กลับใช้วิธีจูงใจผู้ใช้ให้ดาวน์โหลดไฟล์แอปพลิเคชันปลอมที่แฝงมัลแวร์ซึ่งอาจทำให้เครื่องคอมพิวเตอร์ติดไวรัสโดยไม่รู้ตัว จากประสบการณ์การใช้งานอินเทอร์เน็ตในชีวิตประจำวัน ผมพบว่า SEO เป็นหนึ่งในเครื่องมือที่นิยมกันอย่างมากในการค้นหาข้อมูลหรือดาวน์โหลดโปรแกรม แต่ภัยจาก SEO Poisoning ก็เป็นเรื่องที่เราไม่สามารถมองข้ามได้ เพราะเว็บปลอมมีการออกแบบหน้าเว็บไซต์และโดเมนให้เหมือนของจริงมาก เช่น กรณีของ Notepad++ ซึ่งโดยปกติเป็นโปรแกรมแก้ไขข้อความที่ได้รับความนิยมอย่างสูง มีฟีเจอร์รองรับหลายภาษาและดีไซน์ที่ใช้งานง่าย แต่หากดาวน์โหลดจากเว็บปลอม เช่น cn-notepadplusplus.com หรือโดเมนอื่น ๆ ที่แฮกเกอร์จดทะเบียนไว้ อาจทำให้เราติดตั้งมัลแวร์โดยไม่รู้ตัว สิ่งที่ผมแนะนำสำหรับผู้ใช้งานทั่วไปคือการตรวจสอบโดเมนเว็บไซต์อย่างละเอียดก่อนดาวน์โหลด โดยเฉพาะอย่างยิ่งโปรแกรมที่สำคัญและที่ใช้งานบ่อย นอกจากนี้ การอัปเดตโปรแกรมระบบปฏิบัติการและซอฟต์แวร์แอนตี้ไวรัสอย่างสม่ำเสมอจะช่วยเพิ่มเกราะป้องกันจากการโจมตีของมัลแวร์ที่มีความซับซ้อนมากขึ้นเรื่อย ๆ ส่วนมัลแวร์ที่ปล่อยโดย Black Cat นั้น มีคุณสมบัติที่น่ากังวลมาก เพราะมันไม่ได้แค่ทำหน้าที่ขโมยข้อมูลบน clipboard หรือข้อมูลเบราว์เซอร์เท่านั้น แต่ยังสามารถบันทึกการพิมพ์ของเรา (keylogging) รวมถึงส่งข้อมูลกลับไปยังเซิร์ฟเวอร์ Command and Control (C2) ของแฮกเกอร์ ซึ่งส่งผลให้ข้อมูลส่วนตัว ข้อมูลสำคัญทางธุรกิจ หรือแม้กระทั่งรหัสผ่านทางการเงินอาจถูกขโมยไปได้อย่างง่ายดาย ในทางเทคนิค วิธีการวางยา SEO เช่นนี้สะท้อนให้เห็นว่าการรักษาความปลอดภัยด้านข้อมูลไม่ใช่เรื่องของผู้เชี่ยวชาญเพียงอย่างเดียวเท่านั้น ผู้ใช้งานเองก็มีบทบาทสำคัญที่ต้องตระหนักและระมัดระวังมากขึ้น เช่น การไม่ดาวน์โหลดไฟล์จากเว็บไซต์ที่ไม่น่าเชื่อถือ หรือไม่กดปุ่มดาวน์โหลดที่น่าสงสัย รวมทั้งการใช้เครื่องมือช่วยตรวจสอบและรับรองความปลอดภัยของเว็บไซต์ก่อนทุกครั้ง ท้ายที่สุด เรื่องนี้ย้ำเตือนให้เราเห็นว่าแม้แต่กลยุทธ์ที่ดีอย่าง SEO ก็สามารถถูกดัดแปลงใช้ในทางที่ผิดและอันตรายได้ ดังนั้นไม่ว่าใครจะเป็นผู้ใช้อินเทอร์เน็ต การมีความรู้และความระมัดระวังด้านความปลอดภัยไซเบอร์เป็นสิ่งจำเป็นมากในยุคดิจิทัลนี้

Related posts

scammers and hackers beware
Hudson
cercofhell

cercofhell

28 likes

SIEGEX is all CHEATERS & HACKERS😭
Why is this game full of cheaters and hackers and bugs🤷‍♀️ #siege #rainbowsixsiege #gaming #streamer #foryou
Phasma

Phasma

28 likes

BIG Holiday Costco Shop & Haul | Anchorage, Alaska
vanditsv

vanditsv

1 like

Kalebdavis19

Kalebdavis19

0 likes

Hackers hijacked antivirus features to install mal
Hackers hijacked antivirus features to install malware - here's what we know https://www.yahoo.com/tech/cybersecurity/articles/hackers-hijacked-antivirus-features-install-140500891.html #hackers #malware #cybersecurity #antivirus
angela1957

angela1957

1 like

BIG Holiday Costco Shop & Haul | Anchorage, Alaska
vanditsv

vanditsv

2 likes

SECRETS Hackers DON’T Want You to Know!
After hackers got into my Facebook account and completely erased it, I dusted myself off and started a deep dive to understand why and how hackers work. The best way to protect yourself is to outsmart them. Here are 5 secrets Hackers DON'T want you to know! Share this with everyone! #lemon8pa
techgirljen

techgirljen

424 likes

#yungblud
watch4hackers

watch4hackers

5 likes

Don’t Use Airport USB Chargers!
TSA is now advising NOT to use Airport USB Chargers. Bring your own USB charging bricks. "Hackers can install malware at USB ports (we’ve been told that’s called 'juice/port jacking'). So, when you’re at an airport do not plug your phone directly into a USB port. Bring your TSA-compl
Destination & Travel Junkies

Destination & Travel Junkies

151 likes

Ban Hackers
😃 #fcmobile #eafcmobile #fifamobile #fcmobile25 #eafc
manuelofficial_13

manuelofficial_13

4 likes

WARNING TO 2.5B GMAIL USERS. Hackers are continuing to target you. Here’s what to do Follow @cybersecuritygirl for more tips #google #gmail #tips #news #techtips
Cybersecurity Girl

Cybersecurity Girl

496 likes

Bigfoot Super Hackers.
#manthoughts #hackers #laughoutloud #bigfootvlog #lifetips
Alien Hayes

Alien Hayes

11 likes

Do you like hackers?
#hacker #hackers #tricked #fyp
Lil Conscious

Lil Conscious

38 likes

Instagram is sharing your exact location to all your followers Turn this off ASAP. #techtips #instagram #news #technews
Cybersecurity Girl

Cybersecurity Girl

201 likes

Columbus blue jackets hockey
Had a good time watching the bluejackets vs St. Louis blues pre season game! New vlog on the YouTube d channel up now! #columbusbluejackets #hockey #stlouisblues #follow
Kalebdavis19

Kalebdavis19

16 likes

WARZONE HACKERS
Warzone is full hackers and call of duty does not care #warzone #hacker #memesdaily #memes🤣 #gaming
DUSTINMYRQ ™

DUSTINMYRQ ™

3 likes

Websites You NEED to Pass Your College Courses
Y’all college is hard enough without trying to figure everything out on your own 😩 So here’s my list of websites that actually helped me pass my classes like, these were in my survival kit. I’m not gatekeeping 🫶🏽 Quizlet When I needed to memorize terms FAST. I used it for flashcards, and the matc
Beauty

Beauty

273 likes

Hackers
How call of duty has me #call of duty #hacker #warzone
Stevie_Wonders

Stevie_Wonders

1 like

warzone hackers be mad little babies
#cod #ps5 #gamergirl #warzone #fuckhackers
Twilightvile

Twilightvile

2 likes

Hackers suck
Fastcarracer36

Fastcarracer36

7 likes

I wanted a real project I could actually show, not just talk about. So I used Atoms ⚛️ Check it out here: https://tinyurl.com/3xzc8xbe It feels like having a whole AI team helping me: 🔍 they do the deep research first 🏁 then Race Mode builds different versions so I can compare 👥 I just pick
emilie.studygram

emilie.studygram

19 likes

OH HACKERS & SHIPMENT
#codm #fypシ #camogrind #hacker #fyp
GlockitSuckit

GlockitSuckit

2 likes

Poor Belle ! #beauty & the beast salt shackers
Like why did they have to paint her face like that 😂😂🤣🤣 #new #beauty #beautyandthebeast #disney #salt #pepper #homegoods #finds #fyp #fypシ #trending #shop #shopping #shopwithme #fypage #explore #explorepage #reels #eleydencreations #content #contentcreator #creator
EleydenCreation

EleydenCreation

651 likes

Look world on my new Facebook account right now rejecting all my reels now just locked it for no reason These meth heads going crazy Elon Musk and Donald Trump and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers just locked my Facebook accounts right now for no reason
glentrump359

glentrump359

0 likes

Hackers Dream
🕶 Digital Survival Duo "What if the real threat wasn’t in the email… but hidden in the vacation photo you just opened?" Remote Access Terminal (R.A.T.) and Image Hunter are not theory — they’re step-by-step, copy-paste-ready manuals with real, verifiable code. Learn exactly how attackers
Dark Meta

Dark Meta

9 likes

Look world Elon Musk and Donald Trump and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers still harassing me on all my social media apps showing favoritism and discriminate against Glen Nickolas Akins cause I'm listening to music
glentrump359

glentrump359

1 like

I think I may have been hacked🥺😕🫣
I keep getting notifications on comments I have made on posts? I can't see the comments and access the mean/hateful comments that are in question. Please excuse me as I figure this out 🥺😕🙏 I don't rage-bait or click bait on social media. I apologize for any NASTY/Mean things that hackers ha
Cynthgirrl777

Cynthgirrl777

6 likes

You shouldn’t be worried about the hackers, you should be worried about your settings. Check out ThreatLocker DAC today #ad #cybersecurity
Cybersecurity Girl

Cybersecurity Girl

27 likes

No time for hackers
#notimeforhaters #unitedstates #nosugardaddy
Lemon8er

Lemon8er

4 likes

⚠️ The Hidden Dangers of Public Wi-Fi Free Wi-Fi feels convenient, but it can be a trap. Hackers can create what’s called an “evil twin” network—a fake hotspot that looks legitimate. The moment you connect, they can access your data, passwords, banking info, and private messages. Listen
Dannah Eve

Dannah Eve

82 likes

Baymax 3D Print!
Just a little colorful Baymax I printed for my wife. I used Matterhackers silky rose gold PLA for the body. #3dprinting #fyp #foryoupage #disney @
PrintsWithChris

PrintsWithChris

3 likes

Prayers for Jamaica 🇯🇲 — opening Hacker’s Slumber,
Cousin B

Cousin B

0 likes

These meth heads going crazy Elon Musk and Donald Trump and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers just locked my Facebook accounts right now for no reason y'all obsessed with me gay bitches unlocked my damn Facebook account
glentrump359

glentrump359

0 likes

Amen thanks Father God Jesus Christ God morning word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

0 likes

Amen thanks Father God Jesus Christ God morning word and prayer devil's I rebuke you your childrens Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg and Randy Tappin and Christopher Thirdkill and IT and their countr
glentrump359

glentrump359

0 likes

🧠 Would YOU plug in a random USB? Jamie did… and almost let hackers into his system. ⚠️ This comic shows a real cybersecurity trick: USB Baiting — where attackers drop infected drives hoping someone connects them. 👀 Learn what a Trojan is 🔐 Discover how to spot dangerous files 💬 Drop a 🛑
CyberSnack

CyberSnack

1 like

God, please unblock this android, hackers have in
Olga Ledbetter

Olga Ledbetter

37 likes

Just An FYI This Is How So Many People are Getting Hacked!!! Plz Don’t Fall For Message Like These!!! it’s A Fake Account!!! #fakeaccount #hackers
MaryBell

MaryBell

2 likes

This is the newest way people are getting hacked and if you use AI to answer your questions and give you advice, you need to watch this.Thanks to Huntress for reporting this Follow for more
Cybersecurity Girl

Cybersecurity Girl

15 likes

Look world Elon Musk and Donald Trump and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers still harassing me on all my social media apps showing favoritism and discriminate against Glen Nickolas Akins cause I'm listening to music
glentrump359

glentrump359

0 likes

HACKERS IN THE BETA
Blackops 7 has hackers already…. #hacker #blackops7 #bo7
Goofstha

Goofstha

1 like

How to spy on your partner’s phone to catch them
Cheating #howtospyonyourcheatingpartner #2024 #viral #fypシ゚viral New York
Morgancyberhelp

Morgancyberhelp

47 likes

Look world Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers and Elon Musk and Donald Trump and Mark Zuckerberg rejecting all my followers on my Snapchat right now these meth heads going crazy frfr
glentrump359

glentrump359

4 likes

Look world still on my YouTube channel right now removing my YouTube channel right now and on my Facebook account right now pausing my lives since 4:44 am these meth heads going crazy Elon Musk and Donald Trump and Mark Zuckerberg and Morehouse parish sheriff department officers and Mike Stone Tubb
glentrump359

glentrump359

0 likes

These Hackers on Marvel Rivals getting crazy!
#marvelrivals #twitchtv #followme #Hackers #marvelfunny
MisFit Miracles

MisFit Miracles

1 like

Look world these meth heads going crazy miserable and desperate mutherfckers Elon Musk and Donald Trump and Morehouse parish sheriff department officers and Mike Stone Tubbs and hackers harassing me on my bingo live right now since I came on it ended my lives and on my YouTube channel showing favor
glentrump359

glentrump359

0 likes

A rumor has been going around that Iranian hackers threatened to hack the U.S. credit system and boost everyone’s credit score. #fyp
iddy2707

iddy2707

2 likes

Replying to @Red what parts or the dark web live in your brain rent free? #scarystories #horror #eductional #darkweb
Liz Cooper🦋

Liz Cooper🦋

40 likes

Ban Hackers
Vinicius Jr 🇧🇷 #fcmobile #eafcmobile #fifamobile #fcmobile25 #eafc
manuelofficial_13

manuelofficial_13

1 like

See more