Threat Actors Impersonate as MalwareBytes to Attack Users and Steal Logins
ID: 7187e796-4e9b-583a-82e0-89e015816d3e
STIX ID: report--7187e796-4e9b-583a-82e0-89e015816d3e
Feed Name: cybersecurityNews.com
Threat Score
Security researchers observed an active campaign (Jan 11–15, 2026) distributing ZIP files named to resemble Malwarebytes installers; the archives contain a malicious CoreMessaging.dll used to perform DLL sideloading and drop infostealers that harvest browser-stored credentials and cryptocurrency wallet data. VirusTotal analysts identified a consistent behash value (4acaac53c8340a8c236c91e68244e6cb) and distinctive DLL metadata/exported strings that serve as tracking IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
