logo

Threat Actors Impersonate as MalwareBytes to Attack Users and Steal Logins

ID: 7187e796-4e9b-583a-82e0-89e015816d3e

STIX ID: report--7187e796-4e9b-583a-82e0-89e015816d3e

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Security researchers observed an active campaign (Jan 11–15, 2026) distributing ZIP files named to resemble Malwarebytes installers; the archives contain a malicious CoreMessaging.dll used to perform DLL sideloading and drop infostealers that harvest browser-stored credentials and cryptocurrency wallet data. VirusTotal analysts identified a consistent behash value (4acaac53c8340a8c236c91e68244e6cb) and distinctive DLL metadata/exported strings that serve as tracking IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.