{"id":4027,"date":"2022-02-04T17:23:07","date_gmt":"2022-02-04T22:23:07","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4027"},"modified":"2022-02-04T17:23:08","modified_gmt":"2022-02-04T22:23:08","slug":"new-malicious-installation-campaign-of-productivity-tools","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/","title":{"rendered":"New Malicious installation campaign of productivity tools"},"content":{"rendered":"\n<p>Cybercriminals have a new malicious SEO management campaign underway. The goal of the campaign is to distribute the Batloader and Atera Agent malware on the systems of targeted professionals looking for downloads of productivity tools, such as Zoom, TeamViewer, and Visual Studio.<\/p>\n\n\n\n<p>These campaigns are based on compromising legitimate websites to plant malicious files or URLs. The URLs redirect users to sites that host malware disguised as popular apps.<\/p>\n\n\n\n<p>As part of this campaign, cybercriminals perform search engine optimization (SEO) techniques. This is to legitimize the compromised sites in the search results of popular apps.<\/p>\n\n\n\n<p>It should be noted that if a user clicks on the search engine link, they are taken to the compromised site that includes a Traffic Direction System (TDS). Traffic steering systems are scripts that check various characteristics of a visitor. The TDS uses that information to decide whether to show them the legitimate web page or redirect them to another malicious site under the attacker&#8217;s control.<\/p>\n\n\n\n<p>If a visitor is redirected, the malicious site displays a fake forum discussion. In the discussion one user asks how to get a particular app and another fake user provides a download link.<\/p>\n\n\n\n<p>Of course, this is a hoax and if you click it, the site creates a bundled malware installer with the name of the desired application. As malware bundles include legitimate software, many users do not realize that they have also been inflicted with malware, which is why it is never recommended to access, let alone download, suspicious links.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malicious campaigns are always on the prowl, and today we&#8217;re seeing a new one that surfaced via productivity tool installers&#8230;&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4028,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4027","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New Malicious installation campaign of productivity tools - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Malicious campaigns are always on the prowl, and today we&#039;re seeing a new one that surfaced via productivity tool installers......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Malicious installation campaign of productivity tools - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Malicious campaigns are always on the prowl, and today we&#039;re seeing a new one that surfaced via productivity tool installers......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-04T22:23:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-02-04T22:23:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/campana.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"New Malicious installation campaign of productivity tools\",\"datePublished\":\"2022-02-04T22:23:07+00:00\",\"dateModified\":\"2022-02-04T22:23:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/\"},\"wordCount\":260,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/campana.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/\",\"name\":\"New Malicious installation campaign of productivity tools - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/campana.jpg\",\"datePublished\":\"2022-02-04T22:23:07+00:00\",\"dateModified\":\"2022-02-04T22:23:08+00:00\",\"description\":\"Malicious campaigns are always on the prowl, and today we're seeing a new one that surfaced via productivity tool installers......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/campana.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/campana.jpg\",\"width\":1000,\"height\":600},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/new-malicious-installation-campaign-of-productivity-tools\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New Malicious installation campaign of productivity tools\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New Malicious installation campaign of productivity tools - Truxgo Server Blog","description":"Malicious campaigns are always on the prowl, and today we're seeing a new one that surfaced via productivity tool installers......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/","og_locale":"es_MX","og_type":"article","og_title":"New Malicious installation campaign of productivity tools - Truxgo Server Blog","og_description":"Malicious campaigns are always on the prowl, and today we're seeing a new one that surfaced via productivity tool installers......","og_url":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-02-04T22:23:07+00:00","article_modified_time":"2022-02-04T22:23:08+00:00","og_image":[{"width":1000,"height":600,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/campana.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"New Malicious installation campaign of productivity tools","datePublished":"2022-02-04T22:23:07+00:00","dateModified":"2022-02-04T22:23:08+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/"},"wordCount":260,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/campana.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/","url":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/","name":"New Malicious installation campaign of productivity tools - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/campana.jpg","datePublished":"2022-02-04T22:23:07+00:00","dateModified":"2022-02-04T22:23:08+00:00","description":"Malicious campaigns are always on the prowl, and today we're seeing a new one that surfaced via productivity tool installers......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/campana.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/campana.jpg","width":1000,"height":600},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/new-malicious-installation-campaign-of-productivity-tools\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"New Malicious installation campaign of productivity tools"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4027","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4027"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4027\/revisions"}],"predecessor-version":[{"id":4031,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4027\/revisions\/4031"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4028"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}