Technology Today

Researchers at Kaspersky have discovered a new malicious campaign which uses a fake version of a popular VPN service's website to spread the Trojan stealer AZORult by tricking users into thinking they are downloading a Windows installer.AZORult is one of the most common stealers on Russian hacking forums because of its wide range of capabilities.
This Trojan poses a serious threat to infected computers as it allows an attacker to collect a wealth of data including browser history, login credentials, cookies, files and folders, cryptowallet files and it can even be used as a loader to download other malware.As more users have turned to VPNs to protect their privacy online, cybercriminals have begun to abuse the growing popularity of VPNs by impersonating them, as is the case in this AZORult campaign.In the campaign discovered by Kaspersky researchers, the attackers created a copy of ProtonVPN's website which looks identical to the service's actual site except for the fact that it has a different domain name.Links to the fake VPN website are spread through advertisements via different banner networks which is a practice that is also referred to as malvertising.When a victim visits the phishing website, they are prompted to download a free VPN installer.
However, once a victim downloads the fake VPN installer for Windows, it drops a copy of the AZORult botnet implant.
Once the implant is activated, it collects the infected device's environment information and reports it back to a server controlled by the attackers.The attackers then steal any cryptocurrency stored locally on the device from cryptowallets as well as FTP logins, passwords from FileZilla, email credentials, information from browsers including cookies and credentials from WinSCPm, Pidgin messenger and others software.After discovering the campaign, Kaspersky immediately informed ProtonVPN and blocked the fake website in its security software.Founder and CEO of ProtonVPN, Andy Yen told TheIndianSubcontinent Pro how the company is working to limit the impact of the campaign in a statement, saying:This underlines the importance of never downloading an app from an unofficial source.
Before downloading an app, users should always double check the website address, the app name and the app developer to make sure its genuine.
In this case it appears the fake app was designed to steal users information, specifically data regarding crypto currencies.
Kaspersky blocked the fake website and informed us of the issue as soon as they discovered the malware.
We immediately requested a takedown of the domain to limit the impact of the campaign.
We have also published a guide on what to do if you accidentally download a fake version of our apps.Also check out our complete list of the best VPN services





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Top Tech: Giffgaff is dishing out £100 to try its new broadband to rival Sky and Virgin


What your emoji use says about you as study exposes mental characteristics


Everyone with a Gmail account is 'at risk' - billions told to follow 4 important rules


Your LG television finally gets game-changing upgrade that Samsung users have enjoyed for several years


O2 and Xbox join to provide clients Game Pass Ultimate with a huge saving


Your Gmail account gets upgraded this week as four major changes confirmed


Hoover beats Shark and Amazon with £& pound; 140 off 'effective' cordless vacuum in 56% cost drop


Time to ditch your Fire TV Stick 'Powerful' new rival is coming to the UK soon


'I tried Amazon's gold smartwatch and it's ideal if you want bling on a budget'


Top Tech: Sky's best broadband deals as price drops to cheapest ever in flash sale


Countless UK homes told to examine their landline - ignoring caution could be pricey


New Bowers Wilkins Px7 cordless headphones confirmed and they sound outstanding


Amazon and Argos drop Hisense 4K TV to least expensive ever cost and it's 'unbelievable worth'


Sky customers can get the Apple iPhone 16 Pro for £28 a month


Important Virgin Media Wi-Fi update for UK homes - switch off your router now


WhatsApp validates important upgrade for 'everyone' - here's how to switch it on


Facebook ordered to eliminate posts which 'prompted violence' before Southport riots


Sky's Samsung Galaxy Tab S10 FE offer includes free earbuds and keyboard


WhatsApp will stop working on some iPhones next month - full list confirmed


Android users should examine one phone setting now - neglecting new alert may be pricey


Ditch your Fire TV Stick today and you'll get something way better for less


ChatGPT's palm reading 'conserves lady's life' after spotting possible skin cancer


Argos beats Amazon as Garmin smartwatch without any negative reviews minimized in Easter sale


Watch out Sky - new UK rival finally lets you watch more TV channels for free


Sky revives 'least expensive ever rate' television and broadband handle surprise Easter sale


Amazon shoppers call Galaxy Watch 7 deal 'no-brainer' thanks to £75 voucher


Samsung Smart 4K TV drops to 'lowest ever price' at Argos beating Amazon


Argos shoppers race to get £89 Samsung Galaxy phones using this very simple code