Beware: These Fake Antivirus Sites Spreading Android and Windows Malware
ID: f5f486bd-86f8-5ee2-a1cd-b64d34d4fb5e
STIX ID: report--f5f486bd-86f8-5ee2-a1cd-b64d34d4fb5e
Feed Name: The Hacker News
Trellix researchers uncovered fake antivirus websites (e.g., avast-securedownload.com, bitdefender-app.com, malwarebytes.pro) used to deliver Android and Windows information stealers and trojans—such as SpyNote, Lumma, and StealC—via malicious APKs and archived installers; a rogue Trellix binary (AMCoreDat.exe) was also found dropping stealers. The report highlights malvertising and SEO-poisoning as likely distribution methods and situates the campaign among a broader ecosystem of evolving stealer and Android banking malware threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
