Fake popular sites offer a free app, instead take over PCs
ID: 1b434177-060b-5a8a-83b4-e388e129eeab
STIX ID: report--1b434177-060b-5a8a-83b4-e388e129eeab
Feed Name: Malwarebytes Blog
Malicious actors set up convincing lookalike download sites (impersonating CNN, Avast, Stremio and also using a fake crypto-mining game) to distribute legitimately signed O&O Syspectr remote-management installers tied to attacker accounts; because the binaries are genuine and signed, antivirus often misses them, and victims who install them grant attackers remote access and administrative control. The report provides filenames, domains, embedded account IDs as IOCs and notes O&O's mitigations (disabling remote features on free accounts and suspending abusive accounts).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
