Skip to main content

Threats Tagged 'trojanized installer'

View all threats tagged with 'trojanized installer'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: trojanized installer

Threats Tagged 'trojanized installer'

Click on any threat for detailed analysis and mitigation recommendations

Over five months, four distinct malicious chains operated through the same bulletproof hosting provider, AS202412 registered to OMEGATECH LTD in Seychelles. All chains began with fake CAPTCHA pages (ClickFix technique) that instructed victims to paste commands into Windows Run dialogs. The campaigns used disposable domains with similar naming patterns, compromised legitimate websites, and varied infrastructure including cloud storage, blockchain-resolved C2 addresses, and trojanized installers. Despite different payloads and staging methods, every chain initiated contact through AS202412. The provider expanded from initial allocations to announcing twenty-four /24 prefixes during the observation period. Most browser contacts ended at the lure page without execution, but successful compromises deployed stealers and remote access tools with persistence mechanisms surviving system reboots.

Join the discussion

In July 2025, threat actors compromised organizations through SEO poisoning campaigns targeting users searching for legitimate IT management tools. Users downloading trojanized installers for ManageEngine OpManager received Bumblebee malware, granting initial access. The attackers exploited the fact that users executing these IT tools were privileged administrators, enabling rapid lateral movement to domain controllers. They dumped credentials using wbadmin, created backdoor accounts with enterprise admin privileges, and installed RustDesk for persistent access. AdaptixC2 beacons were deployed for command and control. The threat actors conducted extensive reconnaissance, dumped LSASS memory across multiple systems, attempted Veeam credential theft, and exfiltrated data via SFTP using FileZilla. The intrusion culminated in Akira ransomware deployment across both root and child domains within 44 hours, with subsequent re-encryption two days later affecting the child domain.

Join the discussion

A sophisticated supply chain attack compromised the legitimate 3CXDesktopApp softphone application across Windows, macOS, and Linux platforms. The malicious activity involved trojanized signed installers that deployed a compromised ffmpeg.dll binary, establishing HTTPS beacons to attacker-controlled infrastructure and enabling second-stage payload deployment. Analysis revealed the attack utilized specific beacon structures and encryption keys matching infrastructure patterns, with hands-on-keyboard activity observed in targeted cases. The operation affected multiple platforms through signed MSI installers containing malicious components. The attack demonstrated advanced tradecraft through abuse of trusted software distribution channels, requiring immediate removal of affected versions and deployment of behavioral detection capabilities to identify malicious beaconing activity.

Join the discussion

A supply chain compromise involving Daemon Tools installers distributed via the official vendor website has been identified. The attackers used valid code-signing certificates to make the trojanized installers appear legitimate and bypass security controls. These malicious packages deploy a backdoor that performs system reconnaissance, environment verification, and communicates with attacker-controlled command-and-control infrastructure. The compromise leverages trusted software delivery mechanisms to evade detection, establish persistent access, and enable remote command execution. Organizations should block related malicious infrastructure, hunt for suspicious Daemon Tools installations and network activity, verify software integrity, and implement application allowlisting. Monitoring for unusual certificate usage in software deployment is also advised. No patch or official fix information is available, and no known exploits in the wild have been reported.

Join the discussion

Attackers are leveraging the trusted reputation of Foxit PDF Reader, used by over 650 million people, to distribute malicious installers disguised as legitimate software. Rather than exploiting vulnerabilities, threat actors impersonate the vendor through fake installers with document-themed filenames that bypass user suspicion. When executed, these files display decoy passport images while downloading malicious MSI packages that deploy UltraVNC remote access tools disguised as GPU drivers. The attack establishes persistence through registry modifications and firewall exceptions, connecting to attacker-controlled infrastructure for complete remote system control. Telemetry indicates broad distribution across Germany, the United States, the United Kingdom, and Ukraine. This campaign demonstrates how brand impersonation combined with social engineering proves more effective than technical exploits, relying on user trust and behavioral patterns rather than software vulnerabilities.

Join the discussion

A recent malware campaign uses SEO poisoning on Bing to distribute a trojanized Ivanti Pulse Secure VPN client via lookalike domains. Users are tricked into downloading a malicious MSI installer that steals VPN credentials from the connectionstore.dat file. Stolen credentials are exfiltrated to a command and control server hosted on Azure infrastructure. The attack employs signed executables and referrer-based conditional content delivery to evade detection. This credential theft technique has been linked to subsequent Akira ransomware deployments. Organizations are advised to implement multi-factor authentication, conduct user awareness training, and monitor for suspicious network and endpoint activity. No CVE or known exploits in the wild are reported yet. The threat poses a medium severity risk due to credential compromise and potential ransomware follow-on attacks. European organizations using Ivanti Pulse Secure VPN are at risk, especially in countries with high adoption of this VPN solution and critical infrastructure sectors.

Join the discussion

A new campaign is distributing the Oyster (Broomstick) backdoor through trojanized Microsoft Teams installers. Threat actors are using SEO poisoning and malvertising to trick users into downloading fake installers from spoofed websites. The malicious installers deploy a persistent backdoor that enables remote access, gathers system information, and supports additional payload delivery while evading detection. This tactic mirrors earlier fake PuTTY campaigns, showing a trend of abusing trusted software for initial access. The backdoor communicates with attacker-controlled C2 domains and uses DLL sideloading via rundll32.exe for stealthy execution. Organizations are advised to download software only from verified sources and avoid relying on search engine advertisements.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: trojanized installer
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses