This simple Google Search could infect your computer with dangerous malware

  • Hackers are now using a bizarre search term—'Are Bengal Cats legal in Australia?'—to trap unsuspecting internet users with data-stealing malware! A cybersecurity company warns that a single click could unleash a powerful malware capable of spying on victims, deploying ransomware, and more.

Ravi Hari
Published10 Nov 2024, 03:00 PM IST

One click on the wrong link, and your data could be at risk. Here’s what you need to know to stay safe. (Representative Image)
One click on the wrong link, and your data could be at risk. Here’s what you need to know to stay safe. (Representative Image)

SOPHOS, a US-based cybersecurity firm, has issued a warning to internet users about a unique cyber threat tied to a seemingly harmless search phrase: "Are Bengal Cats legal in Australia?" Hackers are reportedly exploiting this specific search term to lead users to malicious websites.

SEO poisoning leads to malware infection

By using SEO poisoning, cybercriminals have manipulated Google’s search results to rank these malware-laden sites highly, enticing users with what appear to be legitimate links. Once clicked, users risk infection by GootLoader malware, which can steal data, deploy ransomware, and install other harmful software.

GootLoader: Malware delivery platform

The Sophos report highlights that GootLoader, an evolved malware-delivery platform that has been repurposed by cybercriminals as an "initial access as a service" tool, relies heavily on search engine optimization (SEO) poisoning to trick users into clicking malicious links in their search results. The attackers rank these compromised websites highly on Google by leveraging popular search terms, such as "Are Bengal Cats legal in Australia?" Once a user clicks the link, a seemingly innocent .zip file is downloaded, containing JavaScript-based malware designed to evade detection.

Also Read | RBI to introduce real-time AI-driven systems to check cyber fraud

Upon execution, the initial JavaScript downloads a second-stage payload, identified as GootKit—a remote access trojan (RAT) that establishes a foothold in the victim’s network. This malware is capable of persisting through multiple sessions and can later deploy other malicious software like ransomware.

Also Read | Deepfakes and WhatsApp scam hit elderly as online frauds surge: How to stay safe

 

Advice for safe internet browsing

SOPHOS cautions users to stay vigilant, avoid suspicious links, and be mindful of search phrases that may disguise potential cyber threats. They advise avoiding unusual or overly enticing search terms and being wary of search results on unfamiliar websites, as SEO-poisoned links continue to serve as a significant vector for initial malware compromises.

Also Read | How cyber insurance can provide a safety net in the face of growing cyber threat

Stay updated with the latest Trending, India , World and United States news. Follow all the latest updates on Israel Iran Conflict here on Livemint.

Business NewsNewsThis simple Google Search could infect your computer with dangerous malware
MoreLess