Hackers Poison Search Results to Lure IT Pros into Downloading Trojanized PuTTY and WinSCP

Security analysts at Arctic Wolf have discovered a sophisticated SEO poisoning and malvertising operation since early June 2025, which is a worrying increase in supply chain dangers.

The campaign leverages manipulated search engine results and sponsored ads to distribute Trojanized versions of popular IT tools, specifically PuTTY and WinSCP.

The primary targets are IT professionals and administrators, individuals who routinely seek such utilities for legitimate business operations.

SEO Poisoning Campaign Targets IT Administrators

Cybercriminals are creating malicious websites that closely mimic the appearance and functionality of official vendor sites.

These fraudulent domains are promoted to the top of search rankings through search engine optimization abuse and paid advertising, increasing the likelihood that unsuspecting users searching for reputable sources will instead land on these attacker-controlled pages.

Once on these sites, victims are prompted to download what appears to be legitimate installers for PuTTY or WinSCP. However, these software packages have been tampered with and contain a stealthy backdoor.

Trojanized PuTTY
Example of Malicious Sponsored PuTTY Ad on Bing.

Upon execution of the compromised installers, a sophisticated backdoor known as Oyster, also referred to in some circles as Broomstick, is dropped onto the target system.

The backdoor achieves persistence by creating a scheduled task that triggers every three minutes.

This task executes a malicious DLL file (twain_96.dll) via the rundll32.exe utility, specifically invoking the DllRegisterServer export function a technique commonly used by attackers to ensure their payload remains active and under the radar.

Oyster/Broomstick Backdoor

The use of DLL registration for persistence is notable, as it blends in with normal administrative and operating system processes, making detection more challenging for both endpoint security tools and incident responders.

While the campaign has thus far been observed distributing only altered installations of PuTTY and WinSCP, experts warn that other widely used IT tools could soon be targeted using similar tactics.

Given the effectiveness of this distribution method, Arctic Wolf urges organizations to revise their software acquisition protocols.

IT personnel should be expressly instructed to avoid downloading administrative tools and utilities through search engine results or advertisements.

Instead, organizations are encouraged to maintain vetted internal software repositories or direct users to navigate only to confirmed official vendor websites.

This approach significantly reduces the risk of exposure to SEO poisoning and malvertising-based attacks.

Additionally, Arctic Wolf has identified several domains associated with the ongoing campaign and recommends they be blocked at the network perimeter to prevent accidental access and download of compromised installers.

These proactive steps are vital for mitigating risk and maintaining the integrity of enterprise environments.

The security community is advised to stay vigilant and monitor for additional malicious domains or variants of this campaign, as attackers continue to exploit trust in well-known IT tools to infiltrate organizational networks.

Indicators of Compromise (IOC)

Malicious DomainDescription
updaterputty[.]comFake PuTTY distribution site
zephyrhype[.]comAssociated malicious domain
putty[.]runSEO-poisoned download portal
putty[.]betFraudulent site mimicking PuTTY branding
puttyy[.]orgLookalike domain for distributing malware

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories