Technology Today

Researchers at Kaspersky have discovered a new malicious campaign which uses a fake version of a popular VPN service's website to spread the Trojan stealer AZORult by tricking users into thinking they are downloading a Windows installer.AZORult is one of the most common stealers on Russian hacking forums because of its wide range of capabilities.
This Trojan poses a serious threat to infected computers as it allows an attacker to collect a wealth of data including browser history, login credentials, cookies, files and folders, cryptowallet files and it can even be used as a loader to download other malware.As more users have turned to VPNs to protect their privacy online, cybercriminals have begun to abuse the growing popularity of VPNs by impersonating them, as is the case in this AZORult campaign.In the campaign discovered by Kaspersky researchers, the attackers created a copy of ProtonVPN's website which looks identical to the service's actual site except for the fact that it has a different domain name.Links to the fake VPN website are spread through advertisements via different banner networks which is a practice that is also referred to as malvertising.When a victim visits the phishing website, they are prompted to download a free VPN installer.
However, once a victim downloads the fake VPN installer for Windows, it drops a copy of the AZORult botnet implant.
Once the implant is activated, it collects the infected device's environment information and reports it back to a server controlled by the attackers.The attackers then steal any cryptocurrency stored locally on the device from cryptowallets as well as FTP logins, passwords from FileZilla, email credentials, information from browsers including cookies and credentials from WinSCPm, Pidgin messenger and others software.After discovering the campaign, Kaspersky immediately informed ProtonVPN and blocked the fake website in its security software.Founder and CEO of ProtonVPN, Andy Yen told TheIndianSubcontinent Pro how the company is working to limit the impact of the campaign in a statement, saying:This underlines the importance of never downloading an app from an unofficial source.
Before downloading an app, users should always double check the website address, the app name and the app developer to make sure its genuine.
In this case it appears the fake app was designed to steal users information, specifically data regarding crypto currencies.
Kaspersky blocked the fake website and informed us of the issue as soon as they discovered the malware.
We immediately requested a takedown of the domain to limit the impact of the campaign.
We have also published a guide on what to do if you accidentally download a fake version of our apps.Also check out our complete list of the best VPN services





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Top Tech: Best Apple offers as new iPhone, iPad and MacBook Air pre-orders go live


Apple's most recent AirPods 4 see rare cost cut on Amazon - but you'll require to be fast


All Android users placed on 'vital' alert and told to examine their phones now


iPhone upgrade we've been waiting for may arrive soon - just don't look at the price


Lakeland cuts cost of TurboClean flooring mop less expensive than Shark for spring cleansing


Substantial MacBook Air update validated by Apple and there's a huge surprise about its cost


UK's worst broadband confirmed and it's bad news if your postcode is on this list


'My Sony earphones that produce quality noise for a budget friendly cost are now on sale'


Samsung releases 'critical' Galaxy update - check your phone settings now


Smeg retro kettle that 'boils quickly' now cheapest rate at obscure seller


Sky brings back 'lowest ever price' as £120 is cut from TV, Netflix and broadband bills


Apple verifies three brand-new iPads will release next week and the price will shock you


Amazon lowers 'game-changing' Samsung SmartTag tracker that's crucial for summertime travel


Nothing takes aim at Samsung and Apple with a surprisingly cheap new phone


Top Tech: Best vacuum deals from Amazon, Shark, Hoover and more for spring cleaning


Remarkable Android upgrade might quickly repair the most significant issue with your broadband


Therabody launch 'lightest-ever' massage gun with personalised healing routine


UK iPhone owners placed on red alert as severe 'danger' confirmed - don't overlook it


Samsung cuts ₤ 165 of this Galaxy Watch for buyers who stack these two offers


Samsung issues 24-hour alert to claim a free iPad rival - how to get yours today


Gmail and Yahoo red alert - check your inbox now and delete unsafe brand-new email


Virgin Media issues a two-day alert to get a free TV - act now or lose out


Forget the Galaxy S25 - Samsung is back with surprisingly cheap new Android phones


Samsung hands out totally free A9 tablets to consumers who utilize this code at the checkout


Inside the AI music controversy clouding The Beatles' historic BRIT nomination


'I sold my face to AI for £1.5k and now I'll never do one thing in my life ever again'


Leading Tech: Apple iPhone 16e has hit UK stores and we found the best cost


I've attempted Apple's brand-new iPhone - you can get it now for a remarkably low-cost price