Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

A ConnectWise hit by CyberAttack. National state actor suspected of target violation

Take: Who will become Poland’s next president? |Election News

Meta destroys the influence of the OPS targeting Romania, Azerbaijan and Taiwan.

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Cybercriminal clone Clone antivirus sites to spread poisonous mice and steal crypto wallets
Identity

Cybercriminal clone Clone antivirus sites to spread poisonous mice and steal crypto wallets

userBy userMay 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 27, 2025Ravi LakshmananMalware/Cybersecurity

Cybercriminals clone antivirus

Cybersecurity researchers have disclosed a new malicious campaign that uses fake websites promoting Antivirus software to download a victim of Dupe, a remote access trojan called Venom Rat, from BitDefender.

The campaign “indicatively shows that it is intended to target individuals for financial interests by breaching their eligibility, crypto wallets and potentially selling access to the system,” the Domaintools Intelligence (DTI) team said in a new report shared with Hacker News.

The website in question is “BitDefender-DownLoad”[.]com, “Advertise visitors and download the Windows version of your antivirus software. Click on the famous “Download Windows for Windows” and it will start downloading files from the Bitbucket repository that will be redirected to your Amazon S3 bucket.

ZIP Archive (“Bitdefender.zip”) contains an executable called “storeinstaller.exe” that contains the malware configuration associated with the venom rat.

Cybersecurity

Venom Rat is a derivative of the Quasar rat with the ability to harvest data and provide permanent remote access to attackers.

Domaintools said the Decoy website where BitDefender shares temporary and infrastructure, overlaps with other malicious domains and popular IT services that are used as part of phishing activities to harvest login qualifications related to Canada’s Royal Bank and Microsoft.

“These tools work in concerts. Venomurat sneaks up, Stormkitty grabs passwords and digital wallet information, and Silent Trinity allows attackers to hide and maintain control,” the company said.

“This campaign highlights a constant trend. Attackers use sophisticated modular malware built from open source components. This ‘build malware’ approach makes these attacks more efficient, stealthy and adaptable. ”

This disclosure occurs when Sucuri uses Bogus Google Meet Pages to deceive users to install Noanti-Vm.bat Rat and warn them to install a very esoteric Windows batch script that allows remote control to the victim’s computer.

“This fake Google Meet page does not present a login form to directly steal your credentials,” said security researcher Puja Srivastava. “It instead employs social engineering tactics, presenting a fake “microphone permission denied” error, prompting the user to copy and paste certain PowerShell commands as “fixes.” ”

It also follows a surge in phishing attacks featuring highly sophisticated campaigns that are spoofing meta, leveraging Google’s Appsheet No-Code Development Platform.

“By leveraging cutting-edge tactics such as polymorphism identification factors, advanced intermediate proxy mechanisms and multi-factor authentication bypass technology, attackers aim to harvest credentials and two-factor authentication (2FA) code, Knowbe4 Threat Lab said in the report.

Cybersecurity

This campaign will deliver phishing emails at large to involve the use of Appsheet, allowing you to bypass email security defenses such as SPF, DKIM, DMARC, etc. due to the fact that the threat actors originated from a valid domain (“noreply@appsheet)[.]com “).

Additionally, the email comes from Facebook Support and claims it is using account deletion warnings to trick users into clicking on fake links under the pretext of sending appeals within 24 hours. The Booby trapped link is designed to guide victims to hostile (AITM) phishing pages and harvest credentials and two-factor authentication (2FA) codes.

“To further avoid detection and complicate remediation, attackers are leveraging Appsheets’ capabilities to generate unique IDs that are presented as case IDs in the body of the email,” the company said.

“The presence of a unique polymorphism identifier in each phishing email ensures that all messages are slightly different and can help bypass traditional detection systems that rely on static indicators such as hashes and known malicious URLs.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCharles III gives “speech from the throne” in Canada: What do you know | News
Next Article At least five people reportedly killed in a major explosion at China Chemical Plant | Environmental News
user
  • Website

Related Posts

A ConnectWise hit by CyberAttack. National state actor suspected of target violation

May 30, 2025

Meta destroys the influence of the OPS targeting Romania, Azerbaijan and Taiwan.

May 30, 2025

Cybercriminals target AI users using malware load installers that pretend to be popular tools

May 29, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

A ConnectWise hit by CyberAttack. National state actor suspected of target violation

Take: Who will become Poland’s next president? |Election News

Meta destroys the influence of the OPS targeting Romania, Azerbaijan and Taiwan.

Climate activist Greta Samberg joins aid ship efforts to break the siege of Gaza | Israeli-Palestinian conflict news

Trending Posts

Take: Who will become Poland’s next president? |Election News

May 30, 2025

Climate activist Greta Samberg joins aid ship efforts to break the siege of Gaza | Israeli-Palestinian conflict news

May 30, 2025

Musk says he will send Mars a 50-50 chance to Mars by the second half of 2026 | Space News

May 30, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Top Startup and Tech Funding News – May 28, 2025

Grammarly raises $1 billion from popular catalysts, expands its AI platform and accelerates growth towards IPOs

The exchange raises $2.1 million to accelerate clean energy projects with AI-powered site intelligence

Donut Lab raises $7 million pre-seed round to launch its first “agent” crypto browser

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.