Threats Tagged 'fake websites'
View all threats tagged with 'fake websites'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'fake websites'
Click on any threat for detailed analysis and mitigation recommendations
A campaign uses fake websites impersonating CNN, Stremio, and Avast to distribute legitimate remote administration software O&O Syspectr pre-linked to attacker accounts. The lookalike sites closely mimic authentic homepages and trick Windows users into downloading installers that appear legitimate but grant attackers remote access to victim computers. Additional fake sites use cryptocurrency mining game lures to distribute the same tool. All installers are digitally signed legitimate software, making antivirus detection difficult. The campaign uses multiple Syspectr account IDs embedded in filenames, with CNN, Avast, and Stremio lures sharing one account while crypto-mining lures use another. O&O Software responded by disabling Remote Desktop and Remote Console access for free accounts and suspending the abusive accounts. Join the discussion | AlienVault OTX General | 08/12/2026, 08:00:39 UTC Added: 08/12/2026, 15:41:30 UTC |
NWHStealer is a Windows infostealer malware actively distributed through multiple platforms including fake Proton VPN websites, code and file hosting services, and YouTube links. It steals browser data, saved passwords, and information from over 25 cryptocurrency wallets. The malware uses two main infection methods: malicious ZIP files with self-injection loaders hosted on free web hosting providers, and fake websites employing DLL hijacking to inject code into the RegAsm process. It exfiltrates stolen data encrypted with AES-CBC to attacker-controlled servers and maintains persistence via scheduled tasks and UAC bypass techniques. There is no known official patch or vendor advisory for this threat. Indicators include specific malicious domains and file hashes. Join the discussion | AlienVault OTX General | 04/15/2026, 16:13:12 UTC Added: 04/15/2026, 17:32:23 UTC |
A recent scam involves fake Tesla websites advertised through Google paid ads, targeting potential customers interested in preordering the Optimus robot. These fraudulent sites mimic Tesla's official website design and offer non-existent preorders for various Tesla products, including the Optimus robot. The scam aims to collect $250 non-refundable deposits and potentially steal credit card information. Multiple fake domains have been identified, with some already taken offline. The fraudulent sites lack login functionality and may redirect users to fake authentication pages. Tesla is likely monitoring and requesting takedowns of these sites. The scam exploits the anticipation surrounding Tesla's future products and may go unnoticed until expected delivery dates. Join the discussion | AlienVault OTX General | 08/10/2025, 20:55:34 UTC Added: 08/11/2025, 13:47:42 UTC |
Showing 1 to 3 of 3 results