Skip to main content

Threats Tagged 'trojanized software'

View all threats tagged with 'trojanized software'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: trojanized software

Threats Tagged 'trojanized software'

Click on any threat for detailed analysis and mitigation recommendations

Projextor is a malware campaign that leverages Electron-based productivity applications to deliver malicious payloads. The threat disguises itself as legitimate document converters, meal planners, and PDF management tools with working user interfaces. Distribution occurs through impersonating websites that mimic genuine services, using high-ranking search results to lure victims. Applications like Kitchen Canvas, Food Formula, DocConvertWizard, and PDFGrip contain insecure Electron configurations that enable dynamic JavaScript execution and desktop capture capabilities. The infection chain begins with NSIS, Squirrel, or Inno Setup installers that download the main Electron application. Preload scripts abuse privileged Node.js APIs with intentionally disabled security features, allowing arbitrary code execution and screen monitoring. This enables threat actors to capture sensitive information, monitor user activity, and execute remote commands while maintaining the appearance of functional productivity soft...

Join the discussion

Operation DreamJob is a cyberespionage campaign by the North Korea-aligned Lazarus group targeting European defense companies specializing in UAV technology. The attackers use social engineering and trojanized open-source software to deliver a sophisticated malware toolset including ScoringMathTea RAT and BinMergeLoader. The campaign aims to steal intellectual property and manufacturing knowledge to support North Korea's drone program. Attack techniques involve multiple stages with droppers, loaders, and downloaders, exploiting user interaction and system reconnaissance. The threat poses a medium severity risk due to targeted espionage with potential long-term strategic impact on defense capabilities. European UAV manufacturers and defense contractors are primary targets, especially in countries with significant aerospace industries. Mitigation requires enhanced supply chain security, strict validation of open-source software, user training against social engineering, and robust endpoint detection. Countries like Germany, France, Italy, and the UK are most likely affected given their UAV sector prominence and defense industry size. The campaign does not require zero-day exploits but leverages social engineering and trojanized software, increasing the risk of successful infiltration. Defenders should prioritize monitoring for known malware components and suspicious network activity related to this campaign.

Join the discussion

A new botnet called NightshadeC2 has been identified, employing sophisticated techniques to bypass malware analysis sandboxes and exclude itself from Windows Defender. It uses a 'UAC Prompt Bombing' technique and has both C and Python variants. The botnet's capabilities include reverse shell, file execution, self-deletion, remote control, screen capture, hidden web browsers, and keylogging. It's being distributed through ClickFix attacks and trojanized legitimate software. The botnet uses encryption for C2 communication and gathers victim information. It also employs various persistence mechanisms and can bypass certain sandbox environments. The discovery highlights the evolving sophistication of malware and the need for advanced detection and response capabilities.

Join the discussion

A large cybercrime campaign has been observed involving multiple fraudulent websites promoted through Google advertising. The campaign aims to trick users into downloading and installing a trojanized PDF editor containing the TamperedChef information-stealing malware. The malware harvests sensitive data, including credentials and web cookies. The campaign began on June 26, 2025, with the PDF editor initially appearing harmless but later activating malicious capabilities. The threat actor used Google advertising to promote the PDF editor, with at least 5 different campaign IDs observed. The malware's activation occurred 56 days after the campaign's start, coinciding with a typical Google ad campaign duration. The threat actor has a history of distributing malicious code disguised as free utility tools, and this campaign has successfully affected several European organizations.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: trojanized software
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses