logo

‘Vibe-Coded’ Malware Campaign Uses Fake Tools, CDNs and File Hosts to Infect Users

ID: b099193c-fb4e-554b-9e8d-59e826f14e7a

STIX ID: report--b099193c-fb4e-554b-9e8d-59e826f14e7a

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

In January 2026 researchers uncovered a widespread malware campaign distributing hundreds of trojanized ZIP files (443+ samples) across platforms like Discord, SourceForge, MediaFire and others; each package dropped a malicious DLL called WinUpdateHelper.dll that performs DLL sideloading, registers persistence as a Windows service, uses in-memory PowerShell and dynamically generated C2 domains, and deploys coin miners and infostealers/RATs while leveraging social-engineered lures and legitimate third-party installers as distractions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.