logo

Fake Bitdefender website used to spread infostealer malware

ID: 722e86f6-d0bc-5d56-81ac-1ad612731386

STIX ID: report--722e86f6-d0bc-5d56-81ac-1ad612731386

Feed Name: The Record from Recorded Future News

Threat Score
65/100

Date Published: 2025-05-29

Date Updated: 2026-05-01

...
...

Cybercriminals deployed a typosquatted Bitdefender download page to distribute VenomRAT; the payload also includes StormKitty for stealing passwords and crypto wallet credentials and SilentTrinity for stealthy persistence. Bitdefender detected and flagged the malicious site and payload and is working with partners to remove the site, but attribution remains difficult since VenomRAT is widely traded on criminal forums.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.