#Adspect
Rock, tracked as The Quarry, runs a MaaS/PhaaS toolkit for tax-themed phishing campaigns against U.S. victims using RMM software, cloaking, and Telegram reporting. #Rock #IRS #USA
Dark Web Profile: Rock
Rock, tracked by SOCRadar as The Quarry, is a one-person MaaS/PhaaS operation that sells a full phishing and remote access toolkit to affiliates running tax-themed campaigns against U.S. victims. The ecosystem uses legitimate RMM software, Adspect cloaking, and Telegram-based reporting to support campaigns impersonating the IRS, SSA, Adobe, Dropbox, DocuSign, and Messenger. #TheQuarry #Rock #ScreenConnect #Adspect #Telegram #IRS #SSA #Adobe #Dropbox #DocuSign #Messenger
www.hendryadrian.com
June 13, 2026 at 5:15 AM
🟢 Malicious npm packages abuse Adspect redirects

🗨️ Researchers at Socket have discovered seven malicious packages on npm that use the Adspect cloud service to cloak…

#news
Malicious npm packages abuse Adspect redirects
Read more
hackmag.com
March 27, 2026 at 2:00 AM
A malware campaign since Jan 2026 uses Google Ads with tax search lures to deliver ScreenConnect installers deploying HwAudKiller, a Huawei driver that disables EDRs and enables LSASS credential dumping in the US. #HwAudKiller #ScreenConnect #USA
Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR
A large-scale malvertising campaign since January 2026 has used Google Ads to lure U.S. tax-searching victims into downloading rogue ConnectWise Control installers that deploy a BYOVD EDR killer called HwAudKiller. The attackers employ stacked cloaking services (Adspect and JustCloakIt) and a legitimately signed Huawei driver (HWAuidoOs2Ec.sys) to blind EDRs, enable LSASS...
www.hendryadrian.com
March 25, 2026 at 1:00 PM
Notícia da BleepingComputer

"Malicious NPM packages abuse Adspect redirects to evade security" #bolhasec
Malicious NPM packages abuse Adspect redirects to evade security
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations.
www.bleepingcomputer.com
January 12, 2026 at 9:30 PM
悪意あるNPMパッケージがAdspectリダイレクトを悪用してセキュリティを回避

Node Package Manager(npm)レジストリに公開された7つのパッケージが、Adspectというクラウドベースのサービスを利用して、研究者と潜在的な被害者を振り分け、被害者を悪意ある場所へ誘導している。 アプリケーションセキュリティ企業Socketの研究者による分析によれば、この攻撃の目的は被害者を暗号通貨詐欺サイトへ誘導することだという。…
悪意あるNPMパッケージがAdspectリダイレクトを悪用してセキュリティを回避
Node Package Manager(npm)レジストリに公開された7つのパッケージが、Adspectというクラウドベースのサービスを利用して、研究者と潜在的な被害者を振り分け、被害者を悪意ある場所へ誘導している。 アプリケーションセキュリティ企業Socketの研究者による分析によれば、この攻撃の目的は被害者を暗号通貨詐欺サイトへ誘導することだという。 すべての悪意あるパッケージは、9月から11月の間に開発者名「dino_reborn」(geneboo@proton[.]me)名義で公開された。しかし、そのうち6つには悪意あるコードが含まれており、7つ目は悪意あるウェブページを構築するために使用されている: signals-embed dsidospsodlks applicationooks21 application-phskck integrator-filescrypt2025 integrator-2829 integrator-2830 研究者によれば、signals-embed 自体には本質的な悪意はなく、白いデコイ(おとり)ウェブページを作成するコードのみが含まれているという。他の6つには、トラフィックが研究者からのものか潜在的な被害者からのものかを判別するために、訪問者に関するデータを収集するコードが含まれている。 これは、ブラウザ環境からブラウザ識別子、ページおよびURLデータ、現在のページのホストおよびホスト名などの情報を収集し、それをAdspectのAPIに送信できるよう準備することで実現される。 Adspectによるクローク(秘匿化) Socketの研究者によると、6つの悪意あるパッケージには39kBのコードが含まれており、そこにクローク機構が実装されている。このコードは、即時実行関数(IIFE)でラップされているため、ユーザーの追加操作なしにページ読み込み時に自動的に実行される。 攻撃は、侵害された開発者のウェブアプリケーションがブラウザ内で悪意あるJavaScriptを読み込んだときに実行される。 Socketによれば、注入されたコードには、右クリック、F12、Ctrl+U、Ctrl+Shift+Iのブロックや、DevToolsが検出された場合にページをリロードするなどの解析妨害機能が備わっている。これにより、セキュリティ研究者がウェブページを調査することが難しくなる。 悪意あるコードスニペット出典: Socket スクリプトは、訪問者のユーザーエージェント、ホスト、リファラー、URI、クエリ文字列、プロトコル、言語、エンコーディング、タイムスタンプ、受け入れ可能なコンテンツタイプを収集し、そのフィンガープリントデータを脅威アクターのプロキシに送信する。 実際の被害者のIPアドレスは取得されてAdspect APIに転送され、その後、Adspectがデータを評価して訪問者を分類する。 ターゲットと判定された訪問者は、暗号通貨ブランド(Ethereum、Solana)を装った偽のCAPTCHAページにリダイレクトされる。そこで、ユーザー操作を装いながら、新しいタブでAdspectが定義したURLを開く欺瞞的なシーケンスが開始される。 訪問者が研究者の可能性ありと判定された場合は、疑念を和らげるために、偽だが無害なOfflido社のページが読み込まれる。 偽の企業サイト出典: Socket Adspectは、ウェブページへの不正アクセスをフィルタリングし、ボットや悪意あるアクターをブロックして正当なユーザーのみを許可する、クラウドベースのサービスとして販売されている。 BleepingComputerは、同社がこの悪用を認識しているか、またそれを防ぐためにどのような仕組みを用意しているかを確認するために問い合わせを行ったが、公開時点までに回答は得られていない。 翻訳元:
blackhatnews.tokyo
December 5, 2025 at 1:55 AM
Notícia da BleepingComputer

"Malicious NPM packages abuse Adspect redirects to evade security" #bolhasec
Malicious NPM packages abuse Adspect redirects to evade security
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations.
www.bleepingcomputer.com
November 29, 2025 at 3:30 PM
Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam
Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam
www.darkreading.com
November 28, 2025 at 5:56 AM
ТОП-5 ИБ-событий недели по версии Jet CSIRT Сегодня в ТОП-5 — вредоносные пакеты npm используют Adspect для кражи крип...

#технологии,семья,Блокчейн,криптовалюта,жертва,Ethereum

Origin | Interest | Match
November 27, 2025 at 2:09 PM
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 72

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Contagious Interview Actors Now Utilize JSON Storage Services for Malware Del…
#gpt #hackernews #news
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 72
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Contagious Interview Actors Now Utilize JSON Storage Services for Malware Delivery RONINGLOADER: DragonBreath’s New Path to PPL Abuse   npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects  GPT Trade: Fake Google Play Store […]
securityaffairs.com
November 24, 2025 at 1:41 PM
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages thehackernews.com/2025/11/seve...
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages
Malicious npm packages use Adspect cloaking to filter victims and deliver crypto-themed redirects.
thehackernews.com
November 23, 2025 at 10:42 PM
📢 Campagne npm malveillante: cloaking Adspect et faux CAPTCHAs pour rediriger vers des arnaques crypto
📝 Source: Socket (Socket Threat Resea…
https://cyberveille.ch/posts/2025-11-22-campagne-npm-malveillante-cloaking-adspect-et-faux-captchas-pour-rediriger-vers-des-arnaques-crypto/ #IOC #Cyberveille
November 22, 2025 at 5:00 PM
📌 Malicious NPM Packages Use Adspect for Cloaking in Crypto Scam Campaign https://www.cyberhub.blog/article/15806-malicious-npm-packages-use-adspect-for-cloaking-in-crypto-scam-campaign
Malicious NPM Packages Use Adspect for Cloaking in Crypto Scam Campaign
A recent malware campaign has been identified that leverages fake websites to determine if a visitor is a potential victim or a security researcher, employing a technique known as "cloaking." This method is being used in a cryptocurrency scam, where malicious NPM packages utilize Adspect for cloaking their activities. Cloaking allows the attackers to present different content based on the visitor's profile, making it harder for security researchers to detect and analyze the malicious activity. The use of malicious NPM packages is particularly concerning as these can be inadvertently installed by developers who trust the NPM ecosystem. Once installed, these packages can execute malicious code on the developer's machine or within their applications, potentially leading to data theft, unauthorized access, or other malicious activities. The focus on cryptocurrency suggests that the attackers are targeting individuals with valuable digital assets, which are often less regulated and more difficult to trace than traditional financial assets. The technical implications of this campaign are significant. Cloaking makes it challenging for security professionals to detect and mitigate threats, as the malicious activity is hidden from those who are most likely to investigate it. Additionally, the use of malicious NPM packages represents a supply chain attack, where the attackers target the software development process itself. This can have wide-reaching implications, as compromised packages can affect many downstream applications. For cybersecurity professionals, this campaign highlights the need for robust detection mechanisms to identify cloaked websites and malicious packages. Behavioral analysis, anomaly detection, and regular audits of installed packages are essential components of a comprehensive defense strategy. Furthermore, developers must be educated about the risks of using untrusted packages and the importance of verifying the integrity of packages before installation. In terms of incident response, organizations should have plans in place to quickly identify and mitigate the impact of malicious packages and cloaked websites. This includes monitoring for unusual activity, isolating affected systems, and conducting thorough investigations to understand the scope and impact of any breaches. Overall, this campaign underscores the increasing sophistication of attackers and the need for continuous vigilance and adaptation in cybersecurity practices. By staying informed about emerging threats and implementing robust security measures, organizations can better protect themselves against these evolving risks.
www.cyberhub.blog
November 20, 2025 at 12:40 PM
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages

Cybersecurity researchers have discovered a set of seven npm packages published by a single threat actor that leverages a cloaking service called Adspect to differentiate between real victims and secu…
#hackernews #news
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages
Cybersecurity researchers have discovered a set of seven npm packages published by a single threat actor that leverages a cloaking service called Adspect to differentiate between real victims and security researchers to ultimately redirect them to sketchy crypto-themed sites. The malicious npm packages, published by a threat actor named "dino_reborn" between September and November 2025, are
thehackernews.com
November 19, 2025 at 3:24 PM
Cybersecurity researchers identified seven malicious npm packages published by the threat actor "dino_reborn" between September and November 2025.
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages
thehackernews.com
November 19, 2025 at 12:35 PM
悪意のあるnpmパッケージが暗号詐欺のクローキング機能を悪用

Malicious Npm Packages Abuse Adspect Cloaking in Crypto Scam #DarkReading (Nov 19)

www.darkreading.com/application-...
Malicious Npm Packages Abuse Adspect Cloaking
A malware campaign presents fake websites that can check if a visitor is a victim or a researcher, and then proceed accordingly to defraud or evade
www.darkreading.com
November 19, 2025 at 9:30 AM
npmマルウェアキャンペーン、Adspect Cloakingを介して悪意のあるリダイレクトを配信
#CybersecurityNews
socket.dev/blog/npm-mal...
npm Malware Campaign Uses Adspect Cloaking to Deliver Malici...
Malicious npm packages use Adspect cloaking and fake CAPTCHAs to fingerprint visitors and redirect victims to crypto-themed scam sites.
socket.dev
November 19, 2025 at 7:22 AM
7つのnpmパッケージがアドスペクトクローキングを利用して被害者を暗号詐欺ページに誘導

Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages #HackerNews (Nov 18)

thehackernews.com/2025/11/seve...
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages
Malicious npm packages use Adspect cloaking to filter victims and deliver crypto-themed redirects.
thehackernews.com
November 19, 2025 at 6:00 AM
Seven Malicious NPM Packages Use Adspect to Redirect to Crypto Scams

#Adspect #cryptoscams #JavaScript #maliciouspackages #NPM
Seven Malicious NPM Packages Use Adspect to Redirect to Crypto Scams
Cybersecurity researchers have uncovered seven malicious JavaScript packages on NPM that utilize Adspect, a commercial cloaking service. These packages are
blazetrends.com
November 19, 2025 at 12:11 AM
npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects https://socket.dev/blog/npm-malware-campaign-uses-adspect-cloaking-to-deliver-malicious-redirects
npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects
npm Malware Campaign Uses Adspect Cloaking to Deliver Malicious Redirects
socket.dev
November 19, 2025 at 3:20 AM
Cybersecurity researchers reveal 7 npm packages exposed by a single attacker targeting cryptocurrency users

Cybersecurity researchers have uncovered a set of seven npm packages published by a single attacker. These packages use a cloaking service called Adspect to distinguish between real victims…
Cybersecurity researchers reveal 7 npm packages exposed by a single attacker targeting cryptocurrency users
Cybersecurity researchers have uncovered a set of seven npm packages published by a single attacker. These packages use a cloaking service called Adspect to distinguish between real victims and security researchers, and ultimately redirect to sketchy crypto-themed sites. Malicious npm packages were published by a threat actor named 'dino_reborn' between September and November 2025. Packages include signals-embed (342 downloads), dsidospsodlks (184 downloads), applicationooks21 (340 downloads), application-phskck (199 downloads), integrator-filescrypt2025 (199 downloads), integrator-2829 (276 downloads).
earlybirdsinvest.com
November 19, 2025 at 3:13 AM
恶意npm包滥用Adspect重定向规避安全检测

研究人员发现,恶意分子在npm发布包中借助Adspect重定向服务隐藏攻击路径,成功绕过部分安全检测,给开源供应链安全带来新的挑战。

📰 https://psa.ngo/news/malicious-npm-packages-abuse-adspect-redirects-to-bypass-security/
Malicious NPM packages abuse Adspect redirects to evade security
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations.
www.bleepingcomputer.com
November 19, 2025 at 2:10 AM
Malicious NPM packages abuse Adspect redirects to evade security

Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations. [...]
#hackernews #news
Malicious NPM packages abuse Adspect redirects to evade security
Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations. [...]
www.bleepingcomputer.com
November 19, 2025 at 1:33 AM
Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
November 18, 2025 at 11:12 PM