Fake Malwarebytes Campaign Exploits DLL Sideloading to Drop Infostealers
ID: 48bcff99-e10e-551d-ab31-df61f371f35d
STIX ID: report--48bcff99-e10e-551d-ab31-df61f371f35d
Feed Name: securityonline.info
A recent campaign (observed Jan 11–15, 2026) distributes fake installers named like malwarebytes-windows-github-io-X.X.X.zip that use DLL sideloading—dropping a malicious CoreMessaging.dll alongside legitimate signed EXEs—to run secondary-stage info-stealers. Analysts linked samples by a common behash (4acaac53c8340a8c236c91e68244e6cb) and discovered distinctive metadata and pivot files tying the operation to other fake installers; the malware targets cryptocurrency assets and MFA credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
