Compromised Websites Deliver “BadSpace” Backdoor via Fake Browser Updates: A Cybersecurity Nightmare

Compromised websites are being exploited to deliver a Windows backdoor called BadSpace disguised as fake browser updates. This multi-stage attack uses infected websites and fake pop-ups to deploy the malware, which can take screenshots, execute commands, and more. Beware of unexpected browser update prompts—they might…

Hot Take:

Why settle for just a bad day on the internet when you can also get a malware infection disguised as a browser update? Introducing BadSpace: the gift that keeps on giving (and taking screenshots).

Key Points:

  • Compromised websites delivering BadSpace malware via fake browser updates.
  • Multi-stage attack chain involving infected websites, C2 servers, and JScript downloaders.
  • Attack begins with compromised WordPress sites that collect user data on first visit.
  • Malware capable of taking screenshots, executing commands, and stealing data.
  • Connections to known SocGholish (FakeUpdates) malware identified.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here