Threats Tagged 'fake installers'
View all threats tagged with 'fake installers'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'fake installers'
Click on any threat for detailed analysis and mitigation recommendations
An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives. Join the discussion | AlienVault OTX General | 09/03/2026, 07:26:56 UTC Added: 09/03/2026, 07:52:49 UTC |
LevelBlue has identified two distinct ValleyRAT attack vectors: campaigns using fake installers and malicious email-based campaigns. Detection volume increased significantly from May 2025, nearly doubling in 2026. The fake installer attacks primarily target Chinese-speaking users and employ advanced techniques including Pool Party Variant 7 process injection and BYOVD methods. The malicious email campaigns target both Chinese and Japanese-speaking users, delivering ZIP archives containing EXE and DLL files that leverage DLL sideloading. The malware employs multiple evasion techniques including junk code insertion, memory size checks, sleeping duration checks, process count validation, and fileless execution using Donut-generated shellcode. ValleyRAT establishes persistence through registry modification and enables remote access capabilities for threat actors. Join the discussion | AlienVault OTX General | 07/01/2026, 01:24:45 UTC Added: 07/01/2026, 07:21:30 UTC |
Cisco Talos has uncovered new threats disguised as legitimate AI tool installers, including CyberLock ransomware, Lucky_Gh0$t ransomware, and a newly-discovered malware called Numero. These threats exploit the increasing popularity of AI across various industries. CyberLock, developed using PowerShell, encrypts specific files and demands a $50,000 ransom in Monero. Lucky_Gh0$t is a variant of Yashma ransomware, distributed as a fake ChatGPT installer. Numero, masquerading as an AI video creation tool, manipulates the Windows GUI, rendering systems unusable. Threat actors are using SEO poisoning and social media to distribute these fraudulent installers, targeting businesses in B2B sales, technology, and marketing sectors. Organizations must exercise caution and rely on reputable vendors to avoid falling prey to these malicious campaigns. Join the discussion | AlienVault OTX General | 05/29/2025, 15:05:50 UTC Added: 05/29/2025, 15:28:43 UTC |
Showing 1 to 3 of 3 results