Threats Tagged 'seo'
View all threats tagged with 'seo'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'seo'
Click on any threat for detailed analysis and mitigation recommendations
CNCERT and Microstep Online jointly detected a cyberattack campaign launched by the "Black Cat" criminal gang. This gang uses search engine SEO (Search Engine Optimization) techniques to push meticulously crafted phishing websites to the top of search engine keyword results. After visiting these high-ranking phishing pages, users are lured by carefully designed download pages, attempting to download software installation packages bundled with malicious programs. Once installed, the program implants a backdoor Trojan without the user's knowledge, leading to the theft of sensitive data from their host computer by attackers. Join the discussion | AlienVault OTX General | 01/09/2026, 10:24:39 UTC Added: 01/09/2026, 10:28:21 UTC |
TamperedChef is a sophisticated global malvertising and SEO-driven campaign that delivers malicious payloads via seemingly legitimate, digitally signed installers. It leverages social engineering, malvertising, and abused code-signing certificates obtained through U. S. -registered shell companies to evade detection and increase user trust. The campaign primarily targets healthcare, construction, and manufacturing sectors, establishing persistence and deploying obfuscated JavaScript for remote access and control. Attackers may use this access for credential theft, ransomware preparation, or espionage. Although currently concentrated in the Americas, European organizations in similar sectors are at risk due to the campaign's stealth and persistence techniques. Mitigation requires enhanced scrutiny of signed applications, network monitoring for unusual JavaScript execution, and strict controls on software installation sources. Countries with significant healthcare and manufacturing industries, such as Germany, France, and the UK, are most likely to be affected. Given the medium severity rating and the complexity of exploitation, the threat is assessed as high severity for European contexts due to potential impact and stealth. Join the discussion | AlienVault OTX General | 11/20/2025, 08:15:41 UTC Added: 11/20/2025, 09:46:48 UTC |
A sophisticated malware campaign is increasingly targeting WordPress websites to inject online casino spam content. This malware uses multiple redundancy and reinfection techniques, storing payloads in databases and non-standard file extensions to evade detection and maintain persistence. The campaign exploits the popularity of online gambling and leverages the decline of other spam sources, such as essay writing services, to focus on lucrative casino spam. Although primarily noted in Indonesia due to strict gambling laws, the campaign has international reach. The malware's complexity and persistence mechanisms pose risks to website integrity, SEO rankings, and user trust. European organizations running WordPress sites could be targeted, especially those with lax security or outdated plugins. Mitigation requires advanced detection, continuous monitoring, and tailored cleanup strategies. The threat is assessed as medium severity due to its impact on website integrity and SEO rather than direct data breach or system compromise. Join the discussion | AlienVault OTX General | 11/07/2025, 23:18:21 UTC Added: 11/10/2025, 11:35:31 UTC |
The 'HijackServer' malicious IIS module is actively compromising IIS servers by exploiting exposed ASP . NET machine keys, enabling unauthenticated remote command execution. This threat, attributed to the RudePanda group, uses a customized rootkit and off-the-shelf tools to maintain persistent access. While primarily used to manipulate search engine results for cryptocurrency scams, the module's capabilities allow attackers or third parties to conduct espionage or build malicious infrastructure. Hundreds of servers worldwide have been affected, indicating a broad impact. The exploitation does not require authentication, and the attack leverages a critical misconfiguration or exposure of sensitive cryptographic keys. European organizations running IIS with exposed ASP . NET machine keys are at risk, especially those in countries with high IIS usage and strategic value. Mitigation requires immediate review and protection of ASP . NET machine keys, deployment of advanced monitoring for rootkit activity, and hardening of IIS configurations. Join the discussion | AlienVault OTX General | 10/22/2025, 19:02:28 UTC Added: 10/22/2025, 19:52:59 UTC |
A malicious WordPress plugin named 'wordpress-player.php' has been discovered, affecting at least 26 websites. The plugin injects a hidden HTML5 video player and establishes a WebSocket connection to a command and control server. It redirects visitors to suspicious websites after 4-5 seconds, avoiding execution for logged-in users. The malware uses a fake 'WordPress Core' author name to evade detection. It impacts website integrity through unauthorized redirects, SEO degradation, and potential security risks to visitors. Mitigation steps include thorough scanning, malware removal, credential resets, software updates, and implementing a Web Application Firewall. Join the discussion | AlienVault OTX General | 06/19/2025, 01:56:31 UTC Added: 06/19/2025, 19:16:39 UTC |
Showing 1 to 5 of 5 results