Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

New Social Media Reviews will be added to our Foreign Student Studies Scrutiny

“Heinous Crime”: Israel kills 10 hopeless aid seekers in Gaza in 48 hours | Israeli-Palestinian conflict news

Philadelphia honors Quinta Brunson, an alma mater mural inspired by “Abbott Elementary School.”

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Cybercriminal clone Clone antivirus sites to spread poisonous mice and steal crypto wallets
Identity

Cybercriminal clone Clone antivirus sites to spread poisonous mice and steal crypto wallets

userBy userMay 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 27, 2025Ravi LakshmananMalware/Cybersecurity

Cybercriminals clone antivirus

Cybersecurity researchers have disclosed a new malicious campaign that uses fake websites promoting Antivirus software to download a victim of Dupe, a remote access trojan called Venom Rat, from BitDefender.

The campaign “indicatively shows that it is intended to target individuals for financial interests by breaching their eligibility, crypto wallets and potentially selling access to the system,” the Domaintools Intelligence (DTI) team said in a new report shared with Hacker News.

The website in question is “BitDefender-DownLoad”[.]com, “Advertise visitors and download the Windows version of your antivirus software. Click on the famous “Download Windows for Windows” and it will start downloading files from the Bitbucket repository that will be redirected to your Amazon S3 bucket.

ZIP Archive (“Bitdefender.zip”) contains an executable called “storeinstaller.exe” that contains the malware configuration associated with the venom rat.

Cybersecurity

Venom Rat is a derivative of the Quasar rat with the ability to harvest data and provide permanent remote access to attackers.

Domaintools said the Decoy website where BitDefender shares temporary and infrastructure, overlaps with other malicious domains and popular IT services that are used as part of phishing activities to harvest login qualifications related to Canada’s Royal Bank and Microsoft.

“These tools work in concerts. Venomurat sneaks up, Stormkitty grabs passwords and digital wallet information, and Silent Trinity allows attackers to hide and maintain control,” the company said.

“This campaign highlights a constant trend. Attackers use sophisticated modular malware built from open source components. This ‘build malware’ approach makes these attacks more efficient, stealthy and adaptable. ”

This disclosure occurs when Sucuri uses Bogus Google Meet Pages to deceive users to install Noanti-Vm.bat Rat and warn them to install a very esoteric Windows batch script that allows remote control to the victim’s computer.

“This fake Google Meet page does not present a login form to directly steal your credentials,” said security researcher Puja Srivastava. “It instead employs social engineering tactics, presenting a fake “microphone permission denied” error, prompting the user to copy and paste certain PowerShell commands as “fixes.” ”

It also follows a surge in phishing attacks featuring highly sophisticated campaigns that are spoofing meta, leveraging Google’s Appsheet No-Code Development Platform.

“By leveraging cutting-edge tactics such as polymorphism identification factors, advanced intermediate proxy mechanisms and multi-factor authentication bypass technology, attackers aim to harvest credentials and two-factor authentication (2FA) code, Knowbe4 Threat Lab said in the report.

Cybersecurity

This campaign will deliver phishing emails at large to involve the use of Appsheet, allowing you to bypass email security defenses such as SPF, DKIM, DMARC, etc. due to the fact that the threat actors originated from a valid domain (“noreply@appsheet)[.]com “).

Additionally, the email comes from Facebook Support and claims it is using account deletion warnings to trick users into clicking on fake links under the pretext of sending appeals within 24 hours. The Booby trapped link is designed to guide victims to hostile (AITM) phishing pages and harvest credentials and two-factor authentication (2FA) codes.

“To further avoid detection and complicate remediation, attackers are leveraging Appsheets’ capabilities to generate unique IDs that are presented as case IDs in the body of the email,” the company said.

“The presence of a unique polymorphism identifier in each phishing email ensures that all messages are slightly different and can help bypass traditional detection systems that rely on static indicators such as hashes and known malicious URLs.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCharles III gives “speech from the throne” in Canada: What do you know | News
Next Article At least five people reportedly killed in a major explosion at China Chemical Plant | Environmental News
user
  • Website

Related Posts

Iranian hacker pleads guilty to a $19 million Robin Hood ransomware attack against Baltimore

May 28, 2025

Czech Republic blames APT31 hackers linked to China for cyberattacks in 2022

May 28, 2025

The defect in Microsoft Onedrive file picker gives you full cloud access even if you upload only one file

May 28, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

New Social Media Reviews will be added to our Foreign Student Studies Scrutiny

“Heinous Crime”: Israel kills 10 hopeless aid seekers in Gaza in 48 hours | Israeli-Palestinian conflict news

Philadelphia honors Quinta Brunson, an alma mater mural inspired by “Abbott Elementary School.”

Trump puts aside Elon Musk’s criticism of his signature budget bill | Donald Trump News

Trending Posts

“Heinous Crime”: Israel kills 10 hopeless aid seekers in Gaza in 48 hours | Israeli-Palestinian conflict news

May 28, 2025

Trump puts aside Elon Musk’s criticism of his signature budget bill | Donald Trump News

May 28, 2025

Sudan’s aid workers fear crackdown under strict new military rules | Sudan War News

May 28, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

AI’s Next Horizon: Gemini 2.5 and Google Beam Take Center Stage at Google I/O 2025

Context raises $11 million to launch the first AI-Native Office Suite worth $70 million

Elon Musk’s Xai is partnering with Telegram in a $300 million deal to bring Grok Chatbot to over 1 billion users

Oncade raises a $4 million seed round from the A16Z CSX, helping game studios skip app stores and share revenue with players

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.