Compromised Websites Deliver “BadSpace” Backdoor via Fake Browser Updates: A Cybersecurity Nightmare
Compromised websites are being exploited to deliver a Windows backdoor called BadSpace disguised as fake browser updates. This multi-stage attack uses infected websites and fake pop-ups to deploy the malware, which can take screenshots, execute commands, and more. Beware of unexpected browser update prompts—they might just be a one-way ticket to BadSpace!

Hot Take:
Why settle for just a bad day on the internet when you can also get a malware infection disguised as a browser update? Introducing BadSpace: the gift that keeps on giving (and taking screenshots).
Key Points:
- Compromised websites delivering BadSpace malware via fake browser updates.
- Multi-stage attack chain involving infected websites, C2 servers, and JScript downloaders.
- Attack begins with compromised WordPress sites that collect user data on first visit.
- Malware capable of taking screenshots, executing commands, and stealing data.
- Connections to known SocGholish (FakeUpdates) malware identified.
Already a member? Log in here