Free Converter Apps that Convert your Clean System to Infected in Seconds
ID: 2699f16f-ef13-57e5-9044-4ef55b800fee
STIX ID: report--2699f16f-ef13-57e5-9044-4ef55b800fee
Feed Name: cybersecurityNews.com
Malicious file-converter apps promoted through deceptive Google ads are delivering trojanized C# converters that install persistent RATs on victim systems. The campaign uses redirects through multiple domains to fake converter sites, abuses code-signing certificates to appear legitimate, drops payloads into %LocalAppData%, creates scheduled tasks (often with a +1 day execution offset), and communicates with attacker-controlled C2 servers to run additional .NET assemblies; the report includes numerous payload delivery domains and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
