logo

Fake Proton VPN Sites and Gaming Mods Spread NWHStealer in New Windows Malware Campaign

ID: 6f247ca9-f811-5147-9272-6beef2268ee6

STIX ID: report--6f247ca9-f811-5147-9272-6beef2268ee6

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Malwarebytes researchers identified NWHStealer, an information-stealing Windows malware campaign that spreads through fake VPN websites, code-hosting and file-sharing mirrors, gaming mods, YouTube links, and compromised web hosting. The campaign uses layered loaders (MSI/Node.js wrappers), DLL hijacking and process hollowing to inject payloads into legitimate processes (e.g., RegAsm.exe), employs UAC bypass (CMSTP) and Defender exclusions for persistence, and exfiltrates browser credentials and cryptocurrency wallet data to C2 servers with a Telegram-based dead-drop fallback.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.