logo

Software Productivity Tools Hijacked to Deliver Infostealers

ID: be13df27-8db3-5551-b7e8-ae48b61fce3f

STIX ID: report--be13df27-8db3-5551-b7e8-ae48b61fce3f

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-07-04

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Conceptworld Corporation inadvertently distributed trojanized installers for Notezilla, RecentX, and Copywhiz in June; security researchers from Rapid7 found that the installers contained a low-sophistication infostealer dubbed "dllFake" that captures browser data, cryptocurrency wallet information, keystrokes, and clipboard contents and can fetch additional payloads. Rapid7 notified the vendor on June 24 and the company removed the malicious installers and replaced them with legitimate, signed copies within 12 hours; the intrusion appears to have been achieved by swapping files on the vendor's download server (potential web-server vulnerability), and users are advised to validate file signatures and hashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.