logo

Fake Malwarebytes Campaign Exploits DLL Sideloading to Drop Infostealers

ID: 48bcff99-e10e-551d-ab31-df61f371f35d

STIX ID: report--48bcff99-e10e-551d-ab31-df61f371f35d

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

A recent campaign (observed Jan 11–15, 2026) distributes fake installers named like malwarebytes-windows-github-io-X.X.X.zip that use DLL sideloading—dropping a malicious CoreMessaging.dll alongside legitimate signed EXEs—to run secondary-stage info-stealers. Analysts linked samples by a common behash (4acaac53c8340a8c236c91e68244e6cb) and discovered distinctive metadata and pivot files tying the operation to other fake installers; the malware targets cryptocurrency assets and MFA credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.