Drooid Logo
Back to story perspectives

Full Breakdown

Black Cat Cybercrime Syndicate's SEO Poisoning Campaign Targets Chinese Users

1/8/2026, 10:49:51 PM

Overview of the Cybercrime Operation

The Black Cat cybercrime gang has been linked to a significant search engine optimization (SEO) poisoning campaign that exploits users' trust in popular software. This operation, detailed in a report by the National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT/CC) and Beijing Weibu Online (ThreatBook), has compromised approximately 277,800 hosts across China between December 7 and 20, 2025. The campaign primarily targets users searching for widely used software such as Notepad++, Google Chrome, QQ International, and iTools.

Mechanism of Attack

The Black Cat operation employs fraudulent websites that mimic legitimate software distribution portals. By manipulating search engine results, these bogus sites rise to the top of search results on platforms like Microsoft Bing. Users searching for software are redirected to phishing domains, such as "cn-notepadplusplus[.]com," which closely resemble official download pages. The attackers utilize a strategy that relies on convincing users to download ZIP files containing installers that create desktop shortcuts. These shortcuts serve as entry points for side-loading a malicious Dynamic Link Library (DLL) that deploys a backdoor Trojan.

Once installed, the backdoor Trojan connects to a hard-coded remote server ("sbido[.]com:2869") and begins to harvest sensitive information, including web browser data, keystrokes, and clipboard contents, without the user's knowledge. The malware's design emphasizes stealth, allowing it to operate quietly and maintain remote control over compromised systems.

Scale and Impact

The scale of the Black Cat campaign is notable, with a peak of 62,167 compromised machines reported in a single day. This widespread infection indicates a well-coordinated and automated distribution model rather than isolated incidents. The group has been active since at least 2022, consistently employing SEO poisoning as a method for data theft and remote access. In a previous operation in 2023, Black Cat was implicated in the theft of at least $160,000 worth of cryptocurrency by impersonating AICoin, a virtual currency trading platform.

Criticism and Concerns

Experts have raised concerns about the increasing sophistication of cybercrime tactics, particularly the use of SEO poisoning to manipulate search behaviors. The reliance on social engineering rather than technical exploits makes these attacks challenging to detect and mitigate. The careful construction of download pages that resemble legitimate software distribution sites further complicates user awareness and response.

Official Statements

CNCERT/CC and ThreatBook have emphasized the need for heightened vigilance among users, particularly those searching for software tools online. They have urged users to verify the authenticity of download links and to be cautious of unsolicited prompts to download software.

Verbatim Quotes

  • “The operation relied less on technical exploits than on careful mimicry: convincing websites, familiar download buttons, and search results engineered to appear legitimate.” — CNCERT/CC and ThreatBook
  • “Once the program was installed, the backdoor operated without the user’s knowledge, quietly siphoning data from the host computer.” — CNCERT/CC and ThreatBook

This campaign by Black Cat underscores the evolving landscape of cyber threats, where traditional security measures may fall short against increasingly deceptive tactics.