home.social

#trojanized — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #trojanized, aggregated by home.social.

fetched live
  1. Oldies are still goodies: It didn't take me long to find a #trojanized pirated TV show #Torrent on a public torrent search engine.

    Tell your friends: This is why it's sometimes dangerous to pirate stuff.

    The torrent delivers a rar that contains a #Rhadamanthys #infostealer #malware DLL. The package also contains a benign executable that uses the familiar VLC Player traffic-cone icon. It looks like a TV show file, but it's way too small at only 970kb. Double-clicking the benign executable loads the malware DLL.

    Rhadamanthys is the same malware family that Europol put out a press release about last month. Maybe it was down for a while, but it seems it's not out --yet.

    The bogus torrent leverages strong interest in the streaming TV show Pluribus as its lure.

    europol.europa.eu/media-press/

    virustotal.com/gui/file/a11f4f

  2. Oldies are still goodies: It didn't take me long to find a #trojanized pirated TV show #Torrent on a public torrent search engine.

    Tell your friends: This is why it's sometimes dangerous to pirate stuff.

    The torrent delivers a rar that contains a #Rhadamanthys #infostealer #malware DLL. The package also contains a benign executable that uses the familiar VLC Player traffic-cone icon. It looks like a TV show file, but it's way too small at only 970kb. Double-clicking the benign executable loads the malware DLL.

    Rhadamanthys is the same malware family that Europol put out a press release about last month. Maybe it was down for a while, but it seems it's not out --yet.

    The bogus torrent leverages strong interest in the streaming TV show Pluribus as its lure.

    europol.europa.eu/media-press/

    virustotal.com/gui/file/a11f4f

  3. Self-Replicating Worm Affected Several Hundred #NPM Packages, Including CrowdStrike's -Slashdot

    The Shai-Hulud #malware campaign impacted across multiple maintainers, reports #KoiSecurity , including popular libraries like @ctrl/tinycolor & some packages maintained by #CrowdStrike.

    Malicious versions embed a #trojanized script (bundle.js) designed to steal developer #credentials, exfiltrate secrets, and persist in repositories and endpoints through automated workflows

    it.slashdot.org/story/25/09/20

  4. Self-Replicating Worm Affected Several Hundred #NPM Packages, Including CrowdStrike's -Slashdot

    The Shai-Hulud #malware campaign impacted across multiple maintainers, reports #KoiSecurity , including popular libraries like @ctrl/tinycolor & some packages maintained by #CrowdStrike.

    Malicious versions embed a #trojanized script (bundle.js) designed to steal developer #credentials, exfiltrate secrets, and persist in repositories and endpoints through automated workflows

    it.slashdot.org/story/25/09/20

  5. Facebook accounts hijacked by new malicious ChatGPT Chrome extension

    A #trojanized version of the legitimate #ChatGPT #extension for #Chrome is gaining popularity on the Chrome Web Store, accumulating over 9,000 downloads while stealing Facebook accounts.

    The extension is a copy of the legitimate popular add-on for Chrome named "#ChatGPT for #Google" that offers ChatGPT integration on search results.

    However, this malicious version includes additional code that attempts to #steal #Facebook #session #cookies.

    bleepingcomputer.com/news/secu

  6. Facebook accounts hijacked by new malicious ChatGPT Chrome extension

    A #trojanized version of the legitimate #ChatGPT #extension for #Chrome is gaining popularity on the Chrome Web Store, accumulating over 9,000 downloads while stealing Facebook accounts.

    The extension is a copy of the legitimate popular add-on for Chrome named "#ChatGPT for #Google" that offers ChatGPT integration on search results.

    However, this malicious version includes additional code that attempts to #steal #Facebook #session #cookies.

    bleepingcomputer.com/news/secu