malvertising

Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
Researchers have uncovered a sophisticated campaign distributing the Vidar stealer and XMRig cryptocurrency miner, primarily targeting users seeking cracked software. Attackers use malvertising to lure victims into downloading password-protected archives containing malicious loaders. These loaders are signed with a fake certificate and employ techniques like file-size inflation and AMSI bypass to evade detection before dropping the final payloads.

Lost in relocation: analysis of a new loader distributing CASTLESTEALER
A new Windows loader, named OXLOADER, has been identified distributing the CASTLESTEALER information-stealing malware. This loader employs sophisticated obfuscation techniques and exploits the Windows .reloc section for shellcode staging. It is being spread through malicious Google Ads that impersonate Node.js, leading victims to fake landing pages. The campaign appears to be financially motivated, with targeting exclusions suggesting a Russian-speaking threat actor.

Malvertising Scams Proliferate Across APAC Via Social Media Ads
Bitdefender Labs has identified a significant malvertising operation targeting the Asia-Pacific region. The campaign utilizes paid advertisements on Meta platforms to distribute scams, with over 12,000 campaigns observed across 13 countries. Health and finance-related scams are the most prevalent, contributing significantly to the overall campaign volume.

Football Fever Fuels Scam Campaigns Across Email and Social Media
Cybercriminals are leveraging the excitement surrounding football, particularly the FIFA World Cup 2026, to launch various scam campaigns. These attacks target fans through emails and social media using tactics like fake online stores, fraudulent apps, and deceptive giveaways, exploiting their passion for clubs and national teams.