Google-hosted malvertising leads to fake Keepass site that looks genuine
Google-verified advertiser + legit-looking URL + valid TLS cert = convincing look-alike.
Google-hosted malvertising leads to fake Keepass site that looks genuine
Google-verified advertiser + legit-looking URL + valid TLS cert = convincing look-alike.
@arstechnica Do people still use keepass? I assumed keepassxc was the "new" version and that keepass was abandoned in favor of xc.
@arstechnica Ten years ago, we were hacked. The hacker put in what appeared to be Google Adsense code, which Google itself then marked as malicious and put up big security warnings to anyone trying to access our site on Chrome (as well as people linking to us). Even back then I knew not to trust Google ads!
@arstechnica badvertising
Detailed report from #Malwarebytes LABS
https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website
@arstechnica you also see a lot of this with crypto tools / apps. IE, folks will run ads for fake wallet sites that then drain users.
You can debate the worth of crypto till the cows come home.
But we can’t debate that ad platforms need to take their own duty of care seriously.
076萌SNS is a social network, courtesy of 076. It runs on GNU social, version 2.0.2-beta0, available under the GNU Affero General Public License.
All 076萌SNS content and data are available under the Creative Commons Attribution 3.0 license.