‘Vibe-Coded’ Malware Campaign Uses Fake Tools, CDNs and File Hosts to Infect Users
ID: b099193c-fb4e-554b-9e8d-59e826f14e7a
STIX ID: report--b099193c-fb4e-554b-9e8d-59e826f14e7a
Feed Name: cybersecurityNews.com
In January 2026 researchers uncovered a widespread malware campaign distributing hundreds of trojanized ZIP files (443+ samples) across platforms like Discord, SourceForge, MediaFire and others; each package dropped a malicious DLL called WinUpdateHelper.dll that performs DLL sideloading, registers persistence as a Windows service, uses in-memory PowerShell and dynamically generated C2 domains, and deploys coin miners and infostealers/RATs while leveraging social-engineered lures and legitimate third-party installers as distractions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
