The digital landscape has become increasingly perilous as cybercriminals develop sophisticated methods to manipulate search engine results, directing unsuspecting users to malicious websites. ESET researchers identified a sophisticated example of this threat in 2021, uncovering a previously undocumented server-side trojan that manipulated search engine results by hijacking the reputation of compromised websites. The attack chain typically begins when a user enters a query into a search engine, receiving results that include either manipulated organic listings or malicious advertisements. When users click on compromised search results, they’re directed to websites that meticulously mimic legitimate services, complete with official-looking logos, layouts, and verification badges. The former involves manipulating search engine algorithms to artificially boost a site’s ranking, while the latter places dangerous content at the top of search results through paid advertising platforms. Both methods capitalize on users’ tendency to trust prominent search results, creating a perfect storm of vulnerability in our everyday online activities. Financial services represent particularly high-value targets, with ESET researchers in Latin America documenting scams impersonating Mastercard through ads that appeared prominently in search results. This dangerous trend exploits our habitual trust in search engines, where users often click on top results without scrutinizing their legitimacy. These attacks primarily operate through two vectors: SEO poisoning (also known as black hat SEO) and malicious search advertisements. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The infrastructure often involves multiple redirect chains, with initial landing pages appearing benign before funneling users to endpoints where credentials or financial information are harvested.
This Cyber News was published on cybersecuritynews.com. Publication date: Sun, 13 Apr 2025 14:30:09 +0000