infostealer – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 31 Aug 2025 04:47:57 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 infostealer – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 TamperedChef infostealer delivered through fraudulent PDF Editor https://earlybirdsinvest.com/tamperedchef-infostealer-delivered-through-fraudulent-pdf-editor/ https://earlybirdsinvest.com/tamperedchef-infostealer-delivered-through-fraudulent-pdf-editor/#respond Sun, 31 Aug 2025 04:47:57 +0000 https://earlybirdsinvest.com/tamperedchef-infostealer-delivered-through-fraudulent-pdf-editor/

TamperedChef infostealer delivered through fraudulent PDF Editor

Threat actors have been using multiple websites promoted through Google ads to distribute a convincing PDF editing app that delivers an info-stealing malware called TamperedChef.

The campaign is part of a larger operation with multiple apps that can download each other, some of them tricking users into enrolling their system into residential proxies.

More than 50 domains have been identified to host deceiving apps signed with fraudulent certificates issued by at least four different companies.

The campaign appears to be widespread and well-orchestrated as the operators waited for the ads to run their course before activating the malicious components in the applications, researchers say.

Full update delivers infostealer

A technical analysis from cybersecurity services company Truesec describes the process of TamperedChef infostealer being delivered to a user’s system.

The researchers discovered that the malware was delivered through multiple websites that promoted a free tool called AppSuite PDF Editor.

Based on internet records, the investigators determined that the campaign started on June 26, when many of the websites involved were either registered or started to advertise AppSuite PDF Editor.

However, the researchers found that the malicious app had been verified through the VirusTotal malware scanning services on May 15th.

It appears that the program behaved normally until August 21st, when it received an update that activated malicious capabilities built to collect sensitive data like credentials and web cookies.

According to Truesec, TamperedChef infostealer is delivered with the “-fullupdate” argument for the PDF editor’s executable.

The malware checks for various security agents on the host. It also queries the databases of installed web browsers using the DPAPI (Data Protection Application Programming Interface) –  a component in Windows that encrypts sensitive data.

TamperedChef infostealer checking for installed security agents
TamperedChef infostealer checking for installed security agents
source: Truesec

Digging deeper for the distribution method, Truesec researchers found evidence suggesting that the threat actor spreading TamperedChef within AppSuites PDF Editor relied on Google advertising to promote the malicious program.

“Truesec has observed at least 5 different google campaign IDs which suggests a widespread campaign” – Truesec

The threat actor likely had a strategy to maximize the number of downloads before activating the malicious component in AppSuites PDF Editor, as they delivered the infostealer just four days before the typical expiration period of 60 days for a Google ad campaign.

Looking further into AppSuites PDF Editor, the researchers found that different versions of the program were signed by certificates “from at least four companies,” among them ECHO Infini SDN BHD, GLINT By J SDN. BHD, and SUMMIT NEXUS Holdings LLC, BHD.

Joining a residential proxy

Truesec found that the operator of this campaign has been active since at least August 2024 and promoted other tools, including OneStart and Epibrowser browsers.

It is worth noting that OneStart is usually flagged as a potentially unwanted program (PUP), which is typically the term for adware.

However, researchers at managed detection and response company Expel also investigated incidents involving AppSuites PDF Editor, ManualFinder, and OneStart, all “dropping highly suspicious files, executing unexpected commands, and turning hosts into residential proxies,” which is closer to malware-like behavior.

They found that OneStart can download AppSuite-PDF (signed by an ECHO INFINI SDN. BHD certificate), which can fetch  PDF Editor.

“The initial downloads for OneStart, AppSuite-PDF, and PDF Editor are being distributed by a large ad campaign advertising PDFs and PDF editors. These ads direct users to one of many websites offering downloads of AppSuite-PDF, PDF Editor, and OneStart,” Expel.

The code-signing certificates used in this campaign have already been revoked, but the risk is still present for current installations.

In some instances of PDF Editor, the app would show users a message asking for permission to use their device as a residential proxy in return for using the tool for free.

The researchers note that the proxy network provider may be a legitimate entity not involved in the campaign and that the operator of PDF Editor is capitalizing as affiliates.

It appears that whoever is behind PDF Editor is trying to maximize their profit at the expense of users worldwide.

Even if the programs in this campaign are considered PUPs, their capabilities are typical of malware and should be treated as such.

The researchers warn that the operation they uncovered involves more apps, some of them not yet weaponized, capable of distributing malware or suspicious files, or executing commands surreptitiously on the system.

Both reports from Truesec and Expel [1, 2] include a large set of indicators of compromise (IoCs) that could help defenders protect users and assets from getting infected.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/tamperedchef-infostealer-delivered-through-fraudulent-pdf-editor/feed/ 0 55991
Lumma infostealer malware returns after law enforcement disruption https://earlybirdsinvest.com/lumma-infostealer-malware-returns-after-law-enforcement-disruption/ https://earlybirdsinvest.com/lumma-infostealer-malware-returns-after-law-enforcement-disruption/#respond Wed, 23 Jul 2025 06:58:25 +0000 https://earlybirdsinvest.com/lumma-infostealer-malware-returns-after-law-enforcement-disruption/

Hacker

The Lumma infostealer malware operation is gradually resuming activities following a massive law enforcement operation in May, which resulted in the seizure of 2,300 domains and parts of its infrastructure.

Although the Lumma malware-as-a-service (MaaS) platform suffered significant disruption from the law enforcement action, as confirmed by early June reports on infostealer activity, it didn’t shut down.

The operators immediately acknowledged the situation on XSS forums, but claimed that their central server had not been seized (although it had been remotely wiped), and restoration efforts were already underway.

Lumma admin's first message after the law enforcement action
Lumma admin’s first message after the law enforcement action
Source: Trend Micro

Gradually, the MaaS built up again and regained trust within the cybercrime community, and is now facilitating infostealing operations on multiple platforms again.

According to Trend Micro analysts, Lumma has almost returned to pre-takedown activity levels, with the cybersecurity firm’s telemetry indicating a rapid rebuilding of infrastructure.

“Following the law enforcement action against Lumma Stealer and its associated infrastructure, our team has observed clear signs of a resurgence in Lumma’s operations,” reads the Trend Micro report.

“Network telemetry indicates that Lumma’s infrastructure began ramping up again within weeks of the takedown.”

New Lumma C2 domains tracked by Trend Micro
New Lumma C2 domains
Source: Trend Micro

Trend Micro reports that Lumma still uses legitimate cloud infrastructure to mask malicious traffic, but has now shifted from Cloudflare to alternative providers, most notably the Russian-based Selectel, to avoid takedowns.

The researchers have highlighted four distribution channels that Lumma currently uses to achieve new infections, indicating a full-on return to multifaceted targeting.

  1. Fake cracks/keygens: Fake software cracks and keygens are promoted via malvertising and manipulated search results. Victims are directed to deceptive websites that fingerprint their system using Traffic Detection Systems (TDS) before serving the Lumma Downloader.
  2. ClickFix: Compromised websites display fake CAPTCHA pages that trick users into running PowerShell commands. These commands load Lumma directly into memory, helping it evade file-based detection mechanisms.
  3. GitHub: Attackers are actively creating GitHub repositories with AI-generated content advertising fake game cheats. These repos host Lumma payloads, like “TempSpoofer.exe,” either as executables or in ZIP files.
  4. YouTube/Facebook: Current Lumma distribution also involves YouTube videos and Facebook posts promoting cracked software. These links lead to external sites hosting Lumma malware, which sometimes abuses trusted services like sites.google.com to appear credible.
Malicious GitHub repository (left) and YouTube video (right) distributing Lumma
Malicious GitHub repository (left) and YouTube video (right) distributing Lumma payloads
Source: Trend Micro

The re-emergence of Lumma as a significant threat demonstrates that law enforcement action, devoid of arrests or at least indictments, is ineffective in stopping these determined threat actors.

MaaS operations, such as Lumma, are incredibly profitable, and the leading operators behind them likely view law enforcement action as routine obstacles they merely have to navigate.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/lumma-infostealer-malware-returns-after-law-enforcement-disruption/feed/ 0 49167
TikTok videos now push infostealer malware in ClickFix attacks https://earlybirdsinvest.com/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/ https://earlybirdsinvest.com/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/#respond Fri, 23 May 2025 14:40:00 +0000 https://earlybirdsinvest.com/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/

TikTok

Cybercriminals are using TikTok videos to trick users into infecting themselves with Vidar and StealC information-stealing malware in ClickFix attacks.

As Trend Micro recently discovered, the threat actors behind this TikTok social engineering campaign are using videos likely generated using AI that ask viewers to run commands claiming to activate Windows and Microsoft Office, as well as premium features in various legitimate software like CapCut and Spotify.

“This attack uses videos (possibly AI-generated) to instruct users to execute PowerShell commands, which are disguised as software activation steps. TikTok’s algorithmic reach increases the likelihood of widespread exposure, with one video reaching more than half a million views,” Trend Micro said.

“The videos are highly similar, with only minor differences in camera angles and the download URLs used by PowerShell to fetch the payload,” it added.

“These suggest that the videos were likely created through automation. The instructional voice also appears AI-generated, reinforcing the likelihood that AI tools are being used to produce these videos.”

One of the videos claiming to provide instructions on how to “boost your Spotify experience instantly,” has reached almost 500,000 views, with over 20,000 likes and more than 100 comments.

TikTok ClickFix video
TikTok ClickFix video (Trend Micro)

​In the video, the attackers prompt viewers to run a PowerShell command that will instead download and execute a remote script from hxxps://allaivo[.]me/spotify that installs Vidar or StealC information-stealing malware, launching it as a hidden process with elevated permissions.

After being deployed, Vidar can take desktop screenshots and steal credentials, credit cards, cookies, cryptocurrency wallets, text files, and Authy 2FA authenticator databases.

Stealc can also harvest a wide range of sensitive information from infected computers as it targets dozens of web browsers and cryptocurrency wallets.

After the device is compromised, the script will download a second PowerShell script payload from hxxps://amssh[.]co/script[.]ps1 that will add a registry key to launch at startup automatically.

Attack flow
Attack flow (Trend Micro)

​What is ClickFix?

ClickFix is a tactic where attackers employ fake errors or verification systems, such as CAPTCHA prompts, to trick potential targets into running malicious scripts to download and install malware on their devices.

While generally targeting Windows users through PowerShell commands, ClickFix has also been adopted in attacks against macOS and Linux users.

State-sponsored threat groups have also hacked their targets in similar attacks, with APT28 and ColdRiver (Russia), Kimsuky (North Korea), and MuddyWater (Iran) having all used these tactics in espionage campaigns in recent months.

This is not the first time TikTok videos were used to push malware, with cybercriminals capitalizing on a trending TikTok challenge named ‘Invisible Challenge’ to infect thousands with a fake app that installed WASP Stealer (Discord Token Grabber) malware.

The malware was pushed through videos that received over a million views shortly after being posted and can steal Discord accounts, passwords, credit cards, and cryptocurrency wallets.

In recent years, scammers have also been flooding TikTok with fake cryptocurrency giveaways, almost all using Elon Musk, Tesla, or SpaceX themes.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/tiktok-videos-now-push-infostealer-malware-in-clickfix-attacks/feed/ 0 37868