Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

£20m science and technology boost supports regional innovation

The man who bet everything on AI and Bill Belichick

Making earth observation data useful to people

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Cybercriminal clone Clone antivirus sites to spread poisonous mice and steal crypto wallets
Identity

Cybercriminal clone Clone antivirus sites to spread poisonous mice and steal crypto wallets

userBy userMay 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 27, 2025Ravi LakshmananMalware/Cybersecurity

Cybercriminals clone antivirus

Cybersecurity researchers have disclosed a new malicious campaign that uses fake websites promoting Antivirus software to download a victim of Dupe, a remote access trojan called Venom Rat, from BitDefender.

The campaign “indicatively shows that it is intended to target individuals for financial interests by breaching their eligibility, crypto wallets and potentially selling access to the system,” the Domaintools Intelligence (DTI) team said in a new report shared with Hacker News.

The website in question is “BitDefender-DownLoad”[.]com, “Advertise visitors and download the Windows version of your antivirus software. Click on the famous “Download Windows for Windows” and it will start downloading files from the Bitbucket repository that will be redirected to your Amazon S3 bucket.

ZIP Archive (“Bitdefender.zip”) contains an executable called “storeinstaller.exe” that contains the malware configuration associated with the venom rat.

Cybersecurity

Venom Rat is a derivative of the Quasar rat with the ability to harvest data and provide permanent remote access to attackers.

Domaintools said the Decoy website where BitDefender shares temporary and infrastructure, overlaps with other malicious domains and popular IT services that are used as part of phishing activities to harvest login qualifications related to Canada’s Royal Bank and Microsoft.

“These tools work in concerts. Venomurat sneaks up, Stormkitty grabs passwords and digital wallet information, and Silent Trinity allows attackers to hide and maintain control,” the company said.

“This campaign highlights a constant trend. Attackers use sophisticated modular malware built from open source components. This ‘build malware’ approach makes these attacks more efficient, stealthy and adaptable. ”

This disclosure occurs when Sucuri uses Bogus Google Meet Pages to deceive users to install Noanti-Vm.bat Rat and warn them to install a very esoteric Windows batch script that allows remote control to the victim’s computer.

“This fake Google Meet page does not present a login form to directly steal your credentials,” said security researcher Puja Srivastava. “It instead employs social engineering tactics, presenting a fake “microphone permission denied” error, prompting the user to copy and paste certain PowerShell commands as “fixes.” ”

It also follows a surge in phishing attacks featuring highly sophisticated campaigns that are spoofing meta, leveraging Google’s Appsheet No-Code Development Platform.

“By leveraging cutting-edge tactics such as polymorphism identification factors, advanced intermediate proxy mechanisms and multi-factor authentication bypass technology, attackers aim to harvest credentials and two-factor authentication (2FA) code, Knowbe4 Threat Lab said in the report.

Cybersecurity

This campaign will deliver phishing emails at large to involve the use of Appsheet, allowing you to bypass email security defenses such as SPF, DKIM, DMARC, etc. due to the fact that the threat actors originated from a valid domain (“noreply@appsheet)[.]com “).

Additionally, the email comes from Facebook Support and claims it is using account deletion warnings to trick users into clicking on fake links under the pretext of sending appeals within 24 hours. The Booby trapped link is designed to guide victims to hostile (AITM) phishing pages and harvest credentials and two-factor authentication (2FA) codes.

“To further avoid detection and complicate remediation, attackers are leveraging Appsheets’ capabilities to generate unique IDs that are presented as case IDs in the body of the email,” the company said.

“The presence of a unique polymorphism identifier in each phishing email ensures that all messages are slightly different and can help bypass traditional detection systems that rely on static indicators such as hashes and known malicious URLs.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCharles III gives “speech from the throne” in Canada: What do you know | News
Next Article At least five people reportedly killed in a major explosion at China Chemical Plant | Environmental News
user
  • Website

Related Posts

MSS claims NSA used 42 cyber tools in multi-stage attack on Beijing Time System

October 20, 2025

Europol dismantles SIM farm network running 49 million fake accounts worldwide

October 19, 2025

New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs

October 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

£20m science and technology boost supports regional innovation

The man who bet everything on AI and Bill Belichick

Making earth observation data useful to people

MSS claims NSA used 42 cyber tools in multi-stage attack on Beijing Time System

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.