<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.tomsguide.com/feeds/tag/malware-adware" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from Tom's Guide in Malware-adware ]]></title>
                <link>https://www.tomsguide.com/computing/internet/online-security/malware-adware</link>
        <description><![CDATA[ All the latest malware-adware content from the Tom's Guide team ]]></description>
                                    <lastBuildDate>Wed, 15 Jul 2026 19:35:38 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Dangerous new CrashStealer Mac impersonates Apple's own tools — and bypasses Gatekeeper — to steal your passwords and more ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-new-crashstealer-mac-malware-bypasses-apples-gatekeeper-to-steal-your-passwords-and-more</link>
                                                                            <description>
                            <![CDATA[ A new Mac malware strain impersonates Apple’s own crash reports to trick unsuspecting users into handing over their credentials. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ncr9JcdVzBTEMaNasmtJKB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Jul 2026 19:35:38 +0000</pubDate>                                                                                                                                <updated>Wed, 15 Jul 2026 19:40:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing Peripherals]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:description>                                                            <media:text><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:text>
                                <media:title type="plain"><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Even with one of the <a href="https://www.tomsguide.com/best-picks/best-macbook">best MacBooks</a>, you can never be too careful when downloading new apps. Case in point: a new <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-apps-to-distribute-this-dangerous-mac-malware-dont-fall-for-this">malicious Mac app</a> is posing as a legitimate Apple tool to steal passwords, keychain data and more from vulnerable systems.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/new-crashstealer-malware-poses-as-apple-crash-reporting-tool/" target="_blank">BleepingComputer</a>, the app in question serves as a means to infect vulnerable Apple computers with a new <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-from-info-stealing-malware-dont-fall-for-this-microsoft-teams-scam">Mac info-stealer</a>. While security researchers at Jamf first observed it back in May when it was still in development, this malware is now being actively used by cybercriminals in their attacks.</p><p>Dubbed CrashStealer, what makes this Mac malware strain so dangerous is the way in which it perfectly mimics Apple’s own macOS crash reports. Although something might seem off to more discerning users, others could easily fall for this attack given how much care and attention has gone into impersonating this legitimate tool.</p><p>Here’s everything you need to know about this new Mac malware and how you can keep your own MacBook and all the sensitive data it contains safe from hackers.</p><h2 id="impersonating-a-legitimate-apple-utility">Impersonating a legitimate Apple utility</h2><p>In their <a href="https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/" target="_blank">report</a>, Jamf’s security researchers explain how the malware hides in plain sight by posing as a meeting platform called Werkbit. While they don’t go into details about the malware’s initial distribution method, a malicious app like this could be distributed via <a href="https://www.tomsguide.com/news/hackers-using-google-ads-to-steal-your-info-and-drain-your-accounts-what-you-need-to-know">fake ads</a> or on a developer-focused site like GitHub.</p><p>After downloading the app, it’s mounted on your desktop just like with any new software you download for your Mac. Surprisingly, though, the hackers behind this campaign are using a signed and Apple-notarized installer to distribute their fake app. Not only does this add a sense of legitimacy to the app but it also allows it to bypass Apple’s built-in <a href="https://www.tomsguide.com/news/this-severe-macos-flaw-could-let-malware-run-on-your-mac-update-right-now">Gatekeeper</a> security feature without any warnings whatsoever.</p><p>When launched for the first time, the app displays a fake macOS password prompt that looks strikingly similar to what you’d see when downloading new software manually as opposed to through the Mac App Store. Once a victim puts in the password for their Mac, the hackers then have everything they need to unlock their <a href="https://www.tomsguide.com/news/new-macstealer-malware-steals-icloud-keychain-data-and-passwords-how-to-stay-safe">Apple Keychain </a>which acts as macOS’ encrypted password vault and contains all sorts of sensitive info like saved credentials in Safari, app passwords, Wi-Fi passwords and more.</p><p>The CrashStealer malware isn’t just limited to stealing from your Keychain though. It can also steal browser credentials and cookies from Chrome and other Chromium-based browsers as well as Firefox. Likewise, it can steal data from 80 different crypto wallet extensions and 14 of the <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">best password managers</a> including 1Password, LastPass, Dashlane and more.</p><p>To get all of this stolen data off your Mac, the malware encrypts it before packaging it into hidden ZIP archives and uploading it to a hacker-controlled C&C server.</p><p>By using a signed and notarized dropper and a re-signed payload, CrashStealer is a sophisticated Mac malware that’s especially good at avoiding detection.</p><h2 id="how-to-stay-safe-from-mac-malware">How to stay safe from Mac malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="F9ybS7WNwSK95hqxotZgYM" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/F9ybS7WNwSK95hqxotZgYM.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>If you’re worried about CrashStealer and other Mac malware, the first thing you should do is to avoid sideloading apps, or in this case, installing new apps from anywhere besides the <a href="https://www.tomsguide.com/computing/macos/macos-sequoia-is-streamlining-downloads-from-the-mac-app-store-heres-what-you-need-to-know">Mac App Store</a>.</p><p>Just like on one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android smartphones</a>, when you download new apps from websites instead of an official app store, you’re putting your devices and the data they contain at risk. Apps submitted to the Mac App Store go through rigorous security checks while those you download from a random website don’t.</p><p>Normally when you download an unverified app from the web, macOS’s built-in Gatekeeper security feature will block it or warn you before you install it. In this case, though, that doesn’t happen since the installer used in this campaign is signed and appears to be legitimate. Well, at least in Gatekeeper’s eyes.</p><p>While Gatekeeper can keep you safe from most threats, there are ones like this that manage to bypass its defenses. For this reason, you might want to consider using one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> solutions alongside Apple’s built-in ones. That way, if something slips past Apple, your third-party antivirus software will be able to stop the threat before it can do serious damage.</p><p>Since CrashStealer is still a relatively new Mac malware, this likely won’t be the last time we see it. This is why you always need to be extra careful when downloading and installing new software onto your Apple computer.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom’s Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/new-pamstealer-mac-malware-poses-as-a-clipboard-manager-to-steal-your-login-info-how-to-stay-safe">New PamStealer Mac malware poses as a clipboard manager to steal login info</a></li><li><a href="https://www.tomsguide.com/computing/online-security/apples-hide-my-email-always-seemed-too-good-to-be-true-and-this-new-vulnerability-proves-it-was">Apple’s ‘Hide My Email’ reportedly exposing real email addresses</a></li><li><a href="https://www.tomsguide.com/gaming/gta-6-warning-pre-order-scams-are-stealing-users-info-and-spreading-malware-how-to-stay-safe">GTA 6 warning: Pre-order scams are stealing users' info and spreading malware </a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New PamStealer Mac malware poses as a clipboard manager to steal your login info — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-pamstealer-mac-malware-poses-as-a-clipboard-manager-to-steal-your-login-info-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ The new PamStealer Mac malware appears to be surprisingly clever while it harvests data and login credentials in the background. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Wx9SvCZDucTPh9rnMm85un</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Jul 2026 03:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ scott.younker@futurenet.com (Scott Younker) ]]></author>                    <dc:creator><![CDATA[ Scott Younker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RZsUpqcJ6Uj2q83oCUwNhQ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the latest tech news, including phones, computing and more. He’s been involved in tech since 2011 covering everything from cameras and swimming pool equipment to the latest gaming consoles and smart TVs. He is on a seemingly never ending hunt to build the easiest to use home media system. &lt;/p&gt;&lt;p&gt;Before Tom’s Guide, Scott worked for publications like &lt;em&gt;Digital Trends, Outdoor Photographer, Dead Beats Panel&lt;/em&gt;, and in a brief detour, &lt;em&gt;America’s Funniest Home Videos&lt;/em&gt;. Yes, he has seen more pratfalls, silly pets and ridiculous home movie fails than is reasonably healthy. &lt;/p&gt;&lt;p&gt;When not writing about the latest devices or advances in chipsets, be sure to ask about Scott about disc golf and sustainability, or just if you’re being cheeky, ask about his noodle arm. If you truly want to get nerdy, bring up board games and his ongoing losing streak. &lt;/p&gt;&lt;p&gt;Scott joined Tom&#039;s Guide in 2024 as the West Coast Reporter. He graduated from the School of Journalism at the University of Oregon with a degree in magazine journalism and a minor in communications. While there he blogged or wrote for several magazines including the Fluxx, Ethos and the Oregon Commentator. He briefly wrote and managed a moderately successful blog focused on web comics. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers who focus on Apple devices have discovered a new <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-cracked-versions-of-legitimate-apps-to-spread-dangerous-mac-malware-how-to-stay-safe">macOS malware</a> that appears to be surprisingly clever while it harvests data and login credentials. </p><p>According to the IT firm <a href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/" target="_blank">Jamf </a>(via <a href="https://arstechnica.com/security/2026/07/new-pamstealer-macos-malware-uses-clever-tradecraft-to-remain-stealthy/?comments-page=1#comments" target="_blank">ArsTechnica</a>), the new malware, dubbed PamStealer, can get on your Mac in two stages. First, it disguises itself as Maccy, a clipboard manager. </p><p>Apparently, PamStealer is compiled as AppleScript written in Rust that uses the Pluggable Authentication Modules interface that is built into macOS to target the device's login password, which is then sent to an attacker-controlled server.</p><p>What makes PamStealer unique is that it combines AppleScript and disk images to stealthily enter your computer. When you click the AppleScript, it opens the macOS Script Editor where the malware is buried in the file.</p><p>"Rather than relying on shell commands such as curl or zsh, the AppleScript executes a self-contained JavaScript for Automation (JXA) downloader that retrieves and stages the payload using native Objective-C APIs," the Jamf team wrote. "Combined with a Rust-based second stage and a password capture workflow that validates credentials locally through PAM, the result is a quieter execution chain than we typically observe in commodity macOS stealers."</p><h2 id="how-pamstealer-works">How PamStealer works</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="q5NLfryTKCNZmK5StdViGe" name="shutterstock_1748211680 apple security lock.jpg" alt="opened padlock in front of Apple logo" src="https://cdn.mos.cms.futurecdn.net/q5NLfryTKCNZmK5StdViGe.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>When someone installs the false Maccy and opens the disk image,  they're prompted to enter Command-R immediately. Doing so executes the malicious code inside AppleScript. This allows it to bypass com.apple.quarantine, a normal macOS feature that offers warnings and restrictions when you're opening executable files from the internet.</p><p>The second stage is a Mach-O file specifically written for Macs running Apple M-series CPUs. Rust is apparently an uncommon code for <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-cracked-versions-of-legitimate-apps-to-spread-dangerous-mac-malware-how-to-stay-safe">macOS infostealers</a>. This bundles SQLite and calls it read interface, meaning it opens and reads databases files directly.</p><p>PamStealer will pop up a native password prompt that is meant to resemble a system authorization request. It reads, "“Maccy wants to make changes. Enter your password to allow this.” </p><p>Once a password is entered, it's validated through the PAM API, meaning its harder for malware defenders to detect. Additionally, it can either give a malicious actor full disk access or inject code designed to access Ethereum accounts.</p><p>“Together, these behaviors illustrate how commodity macOS stealers continue to evolve, adopting quieter execution chains and native implementations that reduce traditional detection opportunities while remaining compatible with standard macOS features,” Jamf said.</p><h2 id="how-to-stay-safe-from-pamstealer">How to stay safe from PamStealer</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WNK5Zs69wY5j94beX98P3A" name="MacBook Pro M5--11" alt="MacBook Pro M5" src="https://cdn.mos.cms.futurecdn.net/WNK5Zs69wY5j94beX98P3A.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tom's Guide)</span></figcaption></figure><p>First and foremost, Maccy is a real, legitimate app that is quite popular. If you are interested in checking the app, the only real website is <a href="https://maccy.app/" target="_blank">maccy.app</a>. </p><p>Jamf found the fake Maccy was being hosted at maccyapp.com, a site you should <strong>not</strong> visit.</p><p>Secondly, it's a good reminder to double and triple-check website URLs. Specifically for macOS apps, you can also see if the app in question is available in the Apple App Store. Maccy, for instance, is in the App Store.</p><p>Apple is still a pretty closed garden so if you're looking for something and want to be sure it's real, I would recommend starting there before venturing into the hinterlands of the internet.</p><p>Beyond that, your Mac does come with built-in security software in the form of <a href="https://www.tomsguide.com/computing/online-security/i-tried-apples-new-security-feature-in-macos-that-warns-you-about-potential-clickfix-attacks-and-windows-should-take-note">XProtect</a>. But if you need some extra protection, it might be worth investing in one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> solutions to run alongside it.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/apples-hide-my-email-always-seemed-too-good-to-be-true-and-this-new-vulnerability-proves-it-was">Apple’s ‘Hide My Email’ reportedly exposing real email addresses</a></li><li><a href="https://www.tomsguide.com/computing/online-security/what-is-q-day">What is Q-Day?</a></li><li><a href="https://www.tomsguide.com/computing/online-security/amazon-put-identity-theft-victims-through-a-kafkaesque-ordeal-ftc-issues-usd2-5-million-fine-over-denying-requests">'Amazon put identity theft victims through a Kafkaesque ordeal': FTC issues $2.5 million fine over denying requests</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new Android malware impersonates TikTok and Chrome to steal your banking info from over 200 apps — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-malware-impersonates-tiktok-and-chrome-to-steal-your-banking-info-from-over-200-apps-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ A dangerous new Android banking trojan is posing as popular apps to take over devices and drain bank accounts. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kdVPtFri2ZPK2nhxjADc5T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PoEqQyXuATwMvtLV5s5VYL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Jun 2026 18:33:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing Peripherals]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PoEqQyXuATwMvtLV5s5VYL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shuterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware]]></media:description>                                                            <media:text><![CDATA[Android malware]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PoEqQyXuATwMvtLV5s5VYL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Even though you should always download new apps from official sources like the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a>, some Android users still end up getting tricked into downloading them from websites which can be extremely dangerous. Case in point, a new <a href="https://www.tomsguide.com/computing/malware-adware/this-android-banking-trojan-steals-passwords-to-take-over-your-accounts-and-all-it-takes-is-a-single-text-message">Android banking trojan</a> is currently making the rounds online that’s distributed via fake apps from malicious websites.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/new-rokarolla-android-malware-targets-217-banking-crypto-apps/" target="_blank">BleepingComputer</a>, once installed on vulnerable Android phones, the banking trojan in question is capable of targeting over 200 banking and financial apps to drain accounts and steal crypto. Unsurprisingly, it does so by impersonating Google Chrome and TikTok as both apps are extremely popular.</p><p>The trojan installs the new Rokarolla malware which also steals lock screen credentials, your contacts, SMS data and even uses keyloggers to record everything you type into your phone.</p><p>Here’s everything you need to know about this new Android banking trojan and how you can keep your bank account safe from the cybercriminals using it in their attacks.</p><h2 id="masquerading-as-google-play-protect">Masquerading as Google Play Protect</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aMwXYxuTeVu62PiTqBzShb" name="Google Play Protect Real Time Scanning.jpg" alt="An example showing how real-time scanning works in Google Play Protect" src="https://cdn.mos.cms.futurecdn.net/aMwXYxuTeVu62PiTqBzShb.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Although you should never <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps">sideload Android apps</a> unless you absolutely have to, many people still do despite the risk. The hackers behind this campaign use fake websites to trick unsuspecting users into installing Chrome or TikTok unofficially instead of downloading these apps directly from the Google Play Store like they should.</p><p>According to a <a href="https://zimperium.com/blog/rokarolla-android-banker-with-complete-device-takeover-capabilities" target="_blank">new report</a> from the cybersecurity firm Zimperium, after downloading either app though, the hackers use an interesting trick to give potential victims the illusion of safety. For those unfamiliar, Google’s built-in security app <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> checks any new software you download for viruses. However, in this case, a fake Play Protect pop-up appears before the Rockarolla malware is actually downloaded. Given the fact that the pop-up perfectly impersonates a Play Protect warning, most users wouldn’t think twice before proceeding with this secondary download.</p><p>At this point, the damage is done and the Rockarolla malware gets to work. In total, it’s able to spoof 217 different banking and financial apps to steal your credentials. It does so by using overlays that mimic each individual app. While to the end user it appears as if they’re just logging into their online bank account, they’re actually handing over their username and password to hackers.</p><p>Another interesting trick up Rockarolla’s sleeve is that it can steal SMS notifications from your online bank as well as intercept any calls trying to warn you that something is amiss. This way, you won’t get a fraud alert and the hackers can proceed to empty your accounts one by one.</p><p>While Google continues to improve Android’s security, if you don’t download apps the right way, you too could easily end up falling victim to this and other malware.</p><div style="min-height: 250px;">                                <div class="kwizly-quiz kwizly-X8ogVO"></div>                            </div>                            <script src="https://kwizly.com/embed/X8ogVO.js" async></script><h2 id="how-to-stay-safe-from-android-banking-trojans">How to stay safe from Android banking trojans</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>I can’t stress this enough, unless you <em>really</em> know what you’re doing, you should avoid sideloading apps. Sure, <a href="https://www.tomsguide.com/computing/malware-adware/more-than-250-malicious-apps-are-spreading-info-stealing-malware-on-android-and-ios-delete-these-right-now">malicious apps</a> do manage to sneak past Google’s defenses from time to time but for the most part, if you download new apps from the Play Store, you should be safe. The same goes for other official Android app stores like the Samsung Galaxy Store too.</p><p>From there, you want to make sure that Google Play Protect is installed and enabled on your smartphone. It’s enabled by default on all of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> but it’s always a good idea to check to make sure. For extra protection though, you can also use one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it. You have to pay for many of them but they typically add other useful features like a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a> to help keep you safe online.</p><p>Despite constant warnings, people keep installing apps from websites instead of official stores. As long as this keeps happening, hackers are going to use it to their advantage. However, if you install new apps the way you’re supposed to, you can avoid falling victim to Rockrolla and other banking trojans like it.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/popular-steam-wallpaper-app-hijacked-to-spread-dangerous-malware-how-to-stay-safe">Popular Steam wallpaper app hijacked to spread dangerous malware — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/gpus/update-your-nvidia-gpu-drivers-now-to-protect-your-pc-from-9-high-severity-vulnerabilities-heres-whats-at-risk">Update your Nvidia GPU drivers now to protect your PC from 9 "high-severity" vulnerabilities — here's what's at risk</a></li><li><a href="https://www.tomsguide.com/wellness/smart-rings/ultrahuman-data-breach-i-was-affected-and-here-is-exactly-what-hackers-stole-from-my-account">I just got hit by the Ultrahuman data breach — here's what hackers stole from my account</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Update your Nvidia GPU drivers now to protect your PC from 9 "high-severity" vulnerabilities — here's what's at risk ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/gpus/update-your-nvidia-gpu-drivers-now-to-protect-your-pc-from-9-high-severity-vulnerabilities-heres-whats-at-risk</link>
                                                                            <description>
                            <![CDATA[ Nvidia is urging users to upgrade their GPU drivers immediately to avoid several "high-severity" vulnerabilities. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6AWoqcqcqFWizMA89Txo2N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/V3cKNwFUP2UYBUKCHXZVuT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 May 2026 20:57:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[GPUs]]></category>
                                                    <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Hardware]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ scott.younker@futurenet.com (Scott Younker) ]]></author>                    <dc:creator><![CDATA[ Scott Younker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RZsUpqcJ6Uj2q83oCUwNhQ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the latest tech news, including phones, computing and more. He’s been involved in tech since 2011 covering everything from cameras and swimming pool equipment to the latest gaming consoles and smart TVs. He is on a seemingly never ending hunt to build the easiest to use home media system. &lt;/p&gt;&lt;p&gt;Before Tom’s Guide, Scott worked for publications like &lt;em&gt;Digital Trends, Outdoor Photographer, Dead Beats Panel&lt;/em&gt;, and in a brief detour, &lt;em&gt;America’s Funniest Home Videos&lt;/em&gt;. Yes, he has seen more pratfalls, silly pets and ridiculous home movie fails than is reasonably healthy. &lt;/p&gt;&lt;p&gt;When not writing about the latest devices or advances in chipsets, be sure to ask about Scott about disc golf and sustainability, or just if you’re being cheeky, ask about his noodle arm. If you truly want to get nerdy, bring up board games and his ongoing losing streak. &lt;/p&gt;&lt;p&gt;Scott joined Tom&#039;s Guide in 2024 as the West Coast Reporter. He graduated from the School of Journalism at the University of Oregon with a degree in magazine journalism and a minor in communications. While there he blogged or wrote for several magazines including the Fluxx, Ethos and the Oregon Commentator. He briefly wrote and managed a moderately successful blog focused on web comics. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/V3cKNwFUP2UYBUKCHXZVuT-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nvidia RTX 5060]]></media:description>                                                            <media:text><![CDATA[Nvidia RTX 5060]]></media:text>
                                <media:title type="plain"><![CDATA[Nvidia RTX 5060]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/V3cKNwFUP2UYBUKCHXZVuT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If your Windows or Linux computer uses one of <a href="https://www.tomsguide.com/computing/gpus/best-graphics-cards">best graphics cards</a> made by Nvidia, you're going to want to make sure you're using the latest drivers. This week, the company <a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5821" target="_blank">issued a security alert</a> and driver updates to combat a variety of vulnerabilities. </p><p>The alert highlights 15 issues, nine of which Nvidia has marked as "high-vulnerability." The high-risk flaws run the gamut of what bad actors can do to your PC. That includes letting hackers get access to your PC kernel, inject malicious code, steal crucial data, or gain administrative access. All the stuff you don't want happening. </p><p>For both Windows and Linux, you can download the driver update <a href="https://www.nvidia.com/en-us/drivers/" target="_blank">directly from Nvidia</a>. On Windows, you'll want to make sure you upgrade to driver version 569.49. </p><p>On Linux, you want to make sure you update to version 590.48.01. The new versions were released about a week ago, so most people who have automatic updates turned on should have the update. But check your driver version just in case.</p><p>According to the alert, all Nvidia drivers before version 596.36 — version 482.53 for GTX 10-series and below — are potentially at risk from these vulnerabilities.</p><h2 id="keep-your-pc-safe-from-malware">Keep your PC safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1280px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="tp6SQJXH7qNPosVnCnjnGh" name="TG Screenshot Template_2024 Mo ratio" alt="Futuristic looking data with padlock and shield" src="https://cdn.mos.cms.futurecdn.net/tp6SQJXH7qNPosVnCnjnGh.jpg" mos="" align="middle" fullscreen="" width="1280" height="720" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>This is a general reminder to ensure all your drivers are up to date. Most driver releases patch security flaws like the ones outlined by Nvidia.</p><p>To be fair, some driver updates can cause issues, but later this year, <a href="https://www.tomsguide.com/computing/windows-operating-systems/microsoft-will-soon-automatically-uninstall-bad-windows-drivers-and-this-new-tool-could-be-a-game-changer-for-your-pc">Microsoft will automatically roll back bad Windows drivers</a> to the most recent stable version. Still, keeping your drivers up to date is good practice.</p><p>If you're on PC, Microsoft releases new security updates every second Tuesday of each month. </p><p>Additionally, you'll want to ensure that Windows Defender is enabled. It largely does a great job of catching threats before they do damage. </p><p>For extra protection, you should consider the <a href="https://www.tomsguide.com/computing/antivirus/best-antivirus-software">best antivirus software</a>. Paid antivirus solutions usually update regularly, plus you often get access to VPNs, a <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a> and other security goodies. </p><p>New vulnerabilities crop up all the time, but if you practice good cyber hygiene you devices and data should stay safe.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/ai/nvidia-wants-to-turn-your-home-into-a-mini-ai-data-center-and-its-already-being-tested">Nvidia is teaming up with Span to install mini AI data centers right on the side of your house, turning residential neighborhoods into a distributed supercomputing network that actually pays homeowners for their unused electricity</a></li><li><a href="https://www.tomsguide.com/best-picks/best-gaming-laptops">I test gaming laptops all year — here are the only 8 I recommend in 2026</a></li><li><a href="https://www.tomsguide.com/computing/gaming-laptops/nvidia-rtx-5070-laptop-gpu-officially-has-12gb-of-vram-and-its-about-time">Nvidia RTX 5070 laptop GPU gets 12GB VRAM — here’s why it's a game-changer</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 100 million Mac users at risk: Hackers are hijacking ‘verified’ apps to sneak past your Mac’s security ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/100-million-mac-users-at-risk-hackers-are-hijacking-verified-apps-to-sneak-past-your-macs-security</link>
                                                                            <description>
                            <![CDATA[ A new wave of malware is stealing developer keys to impersonate trusted apps, leaving your MacBook wide open to data theft. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mADEmWGdYnFjhUyi657Nt5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iuibyMGxncrhX6RweFUqcb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Apr 2026 10:28:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing Peripherals]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jason England ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/v4fSq5U4uZUEtGY2BwNuJ6.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jason brings a decade of tech and gaming journalism experience to his role as a Managing Editor of Computing at Tom&#039;s Guide. He has previously written for Laptop Mag, Tom&#039;s Hardware, Kotaku, Stuff and BBC Science Focus. In his spare time, you&#039;ll find Jason looking for good dogs to pet or thinking about eating pizza if he isn&#039;t already.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iuibyMGxncrhX6RweFUqcb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop with warning messages displayed on screen]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop with warning messages displayed on screen]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop with warning messages displayed on screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iuibyMGxncrhX6RweFUqcb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Mac users have felt safe behind Gatekeeper — the macOS digital security guard that only lets verified, trusted apps onto your machine. But now, that gate has just developed a massive crack, as hackers have found a way to get around it undetected.</p><p>On April 22, the research team at <a href="https://mosyle.com/" target="_blank">Mosyle Security</a> discovered two forms of malware named “Phoenix Worm” and “ShadeStager.” With them, hackers are now successfully stealing developer keys, which act like a digital passport, and by hijacking them, cybercriminals can disguise malware as Apple-approved apps.</p><p>To your MacBook, these viruses don’t look like a threat; they look like trusted guests. And with over 100 million Mac users worldwide, this blind spot means that even the most cautious users could be downloading a disaster in disguise.</p><h2 id="how-it-works">How it works</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3840px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="trJ7rzQsBZMrscyUd39qp" name="MacBook Neo, MacBook Air M5 and MacBook Pro M5 Pro" alt="MacBook Neo, MacBook Air M5 and MacBook Pro M5 Pro" src="https://cdn.mos.cms.futurecdn.net/trJ7rzQsBZMrscyUd39qp.jpg" mos="" align="middle" fullscreen="" width="3840" height="2160" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>The attack doesn’t start with you, but with the people who make your favorite apps. Hackers target the developers with a tag-team effort between these two new threats. First, the Phoenix Worm is snuck onto a developers system through a range of social engineering attacks — think recruiters with fake job offers or urgent coding tasks from clients.</p><p>Once it's there, Phoenix Worm is the inside man, which gives your Mac a secret ID number, waits for instructions, and even keeps watch for security software to hide further away from it.</p><p>When the coast is clear, the Phoenix Worm calls in the heavy hitter: ShadeStager. This specialist comes in and takes over developer keys, cloud credentials and secret dev tools. And while this digital heist happens behind the scenes, the fallout lands squarely on your desktop. </p><p>With these master keys, hackers can forge Apple’s verified seal of approval on any malicious file they want. By compromising the tools used to build apps, hackers are essentially poisoning the well in the Mac’s walled garden — turning a trusted developer’s reputation into a backdoor onto your private machine.</p><h2 id="how-to-avoid-this-attack">How to avoid this attack</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3360px;"><p class="vanilla-image-block" style="padding-top:62.50%;"><img id="rWiAHAkhbjDc827VWMif4A" name="unnamed (2).png" alt="The Mac App Store includes many AI apps" src="https://cdn.mos.cms.futurecdn.net/rWiAHAkhbjDc827VWMif4A.png" mos="" align="middle" fullscreen="" width="3360" height="2100" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Apple)</span></figcaption></figure><p>First off, given Apple’s real focus on security, I would not be surprised if a hotfix update is deployed in the next few days to strengthen its verification process. But ultimately, while these two exploits in tandem are sophisticated, they’re not magic — they still need people to let them in.</p><p>So from a developer perspective, it’s going to be all about being extra careful of the emails being received. In fact, Apple added a warning into macOS 26.4 when you’re about to paste potentially malicious code into the Terminal app. Stop immediately if you see it.</p><p>As for most of you reading this, if you’re downloading apps outside the Mac App store, it’s about exercising some extra caution and asking yourself a couple of questions:</p><ul><li>Do I <em>really </em>know this company?</li><li>If it’s something I’ve never heard of before, is it worth the risk?</li></ul><p>And of course, while the Terminal warning above is more to developers, it’s good general advice for you too. If ever you see a website asking you to open the Terminal at all, that’s an automatic “close tab” moment.</p><p>Like any computer, your Mac is only as safe as the things you allow it to do, and by staying vigilant and skeptical, you can keep yourself invisible to even the most sophisticated attacks like this one.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/over-1-billion-windows-users-at-risk-after-disgruntled-security-researcher-leaks-defender-zero-days">Over 1 billion Windows users at risk after disgruntled security researcher leaks Defender zero-days</a></li><li><a href="https://www.tomsguide.com/computing/online-security/scammers-are-weaponizing-apples-own-notifications-in-a-dangerous-new-phishing-attack-dont-fall-for-this">Scammers are abusing Apple account change notifications in new phishing attack — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/108-malicious-chrome-extensions-found-stealing-data-and-injecting-ads-into-every-page-you-visit-delete-them-right-now">108 malicious Chrome extensions found stealing data and injecting ads into every page you visit — delete them right now</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new NoVoice Android malware could be undeletable on older phones — check your settings right now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/50-malicious-apps-with-2-3-million-downloads-infecting-android-phones-with-undeletable-malware-what-to-do-now</link>
                                                                            <description>
                            <![CDATA[ New NoVoice Android malware hides in innocent-looking apps to bypass your phone’s defenses and secretly monitor every single app you open. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GNAtPyVAap6knEC4CeKFAj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 02 Apr 2026 12:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 06 Apr 2026 15:06:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:description>                                                            <media:text><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>We’ve always been told that as long as we stick to the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a> and avoid sideloading, our Android phones are safe. However, a sophisticated new malware campaign has just shattered that sense of security. </p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/novoice-android-malware-on-google-play-infected-23-million-devices/" target="_blank">BleepingComputer</a>, researchers at the cybersecurity firm McAfee have discovered 50 <a href="https://www.tomsguide.com/computing/malware-adware/more-than-250-malicious-apps-are-spreading-info-stealing-malware-on-android-and-ios-delete-these-right-now">malicious apps</a> that hid in plain sight on Google's official store, racking up 2.3 million downloads while quietly infecting devices with a dangerous new Android malware strain.</p><p>Just like in previous malware campaigns, these bad apps posed as system cleaners, mobile games and other utilities. When opened, the apps in question worked as intended and to avoid suspicion, they didn’t request access to <a href="https://www.tomsguide.com/news/these-predatory-loan-apps-have-been-installed-over-15-million-times-delete-them-now">unnecessary permissions</a> which is typically a major red flag that an app is malicious.</p><p>Although Android users who installed and used these apps didn’t get the sense that anything was off, in the background, that couldn’t be further from the truth. You see, after contacting a hacker-controlled server, the apps profiled the devices they were installed on to look for exploitable weaknesses. If any are found, the new NoVoice Android malware then seizes complete and total control over an infected device, essentially turning it into a hacker’s plaything.</p><p>Here’s everything you need to know about this new malware and why it’s one of the most dangerous strains I’ve seen yet, along with some tips and tricks to help keep you and your Android smartphone safe from hackers.</p><h2 id="a-factory-reset-proof-infection">A factory-reset proof infection</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4865px;"><p class="vanilla-image-block" style="padding-top:57.06%;"><img id="b6kHN5w33oqtSXyNEacmve" name="Android malware on phone.jpg" alt="Android malware on phone" src="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve.jpg" mos="" align="middle" fullscreen="" width="4865" height="2776" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>With most malware, performing a <a href="https://www.tomsguide.com/how-to/how-to-reset-an-android-phone">factory reset</a> on one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> should do the trick. However, with NoVoice, that won’t work because the malware burrows into the one area a system wipe can't touch.</p><p>To do so, NoVoice establishes root access by exploiting older vulnerabilities that have since been patched. Since many people don’t update their phones as often as they should — or own older devices that no longer receive security updates — the malware is able to use this to its advantage.</p><p>After being installed via one of those 50 malicious apps, the malware collects a wide variety of device information such as hardware details, the phone’s current Android version and patch level, a list of installed apps, and root status. With this info in hand, NoVoice then reaches out to a command and control (<a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-spyware-has-returned-via-malicious-play-store-apps-delete-them-right-now">C2</a>) server operated by the hackers. It does this every 60 seconds; in addition to sharing info on an infected device, the malware also downloads device-specific exploits used to seize root access.</p><p>According to a <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-research-operation-novoice-rootkit-malware-android/" target="_blank">blog post</a> from McAfee, its security researchers observed 22 different exploits being used by NoVoice. By exploiting known vulnerabilities, the malware is able to bypass Android’s built-in security protections and establish several layers of persistence. NoVoice even rewrites an infected device’s core system libraries to ensure that even if a victim performs a full wipe by factory resetting their phone, the malware remains installed.</p><p>NoVoice’s creators have gone to great lengths to maintain control over infected Android phones. For instance, a watchdog daemon checks the rootkit’s integrity every 60 seconds. If part of the malware has been removed, the missing components are automatically reinstalled. If the malware can't repair itself, it forces the infected device to reboot, which triggers a fresh infection from scratch.</p><p>So far, this new malware has primarily been used to target Android users in Africa, though it’s also been deployed against users in India, the U.S., and Europe. McAfee says a main reason for this is that budget devices running older versions of Android are more common in those regions. However, any Android user running an outdated security patch is squarely in its crosshairs.</p><p>The hackers behind NoVoice have primarily used the malware to target WhatsApp. When the messaging app is launched on an infected device, NoVoice extracts sensitive data to clone a victim’s WhatsApp session. This allows hackers to effectively hijack a victim’s digital identity and message their contacts in real-time. <br><br>Given the modular nature of NoVoice though, the malware could easily be reconfigured to target <a href="https://www.tomsguide.com/computing/malware-adware/godfather-malware-is-now-hijacking-legitimate-banking-apps-and-you-wont-see-it-coming">banking apps</a> or any other app running on an infected device.</p><h2 id="how-to-stay-safe-from-the-novoice-malware">How to stay safe from the NoVoice malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Fortunately, all 50 malicious apps used to spread NoVoice have been removed from the Google Play Store. However, if any of them are already on your phone, you will need to manually uninstall them. While that would normally be enough to keep you safe, the multiple levels of persistence used by this malware mean that simply deleting one of these bad apps isn't a guaranteed fix.</p><p>To see if your Android phone is at risk, you should immediately check your security patch level. This can be found by going to <strong>Settings</strong> > <strong>About Phone</strong> > <strong>Software Information</strong>. If your device’s security patch is dated before May 1, 2021, it is vulnerable to the exact exploits NoVoice uses to gain root access.</p><p>Since a standard factory reset won’t clear this infection, your only technical option is to "reflash" your phone with its official factory firmware. This process completely replaces the corrupted system files with a clean copy, but it also wipes all of your data and can be difficult for less experienced users. If your current phone is no longer receiving Android updates and security patches, the safest move is likely to start over with a brand-new Android device.</p><p>While the full list of all 50 malicious apps hasn't been released, you can still check your device for signs of infection. Open <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> which comes pre-installed on most Android phones and run a manual scan immediately. <br><br>In an email to Tom's Guide, a Google spokesperson provided further insight into how NoVoice really only affects older Android smartphones, saying:<br><br>"Android addressed the vulnerabilities this malware relies on in security updates years ago, so if your device has been updated since May 2021, it's been protected. As an added layer of defense, Google Play Protect automatically removes these apps and blocks new installs. Users should always install the latest security updates available for their device.”</p><p>Going forward, you need to be extremely selective about the apps you install. Stick to trusted developers, check ratings, and always read reviews before hitting download. In addition to keeping Google Play Protect enabled, you may also want to run one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it for an extra layer of defense.</p><p>NoVoice marks a significant shift in the Android malware landscape, and we may see other attackers emulate its 'reset-proof' design in the future. Until then, the best defense is to keep your device updated — and if your phone is too old to receive critical security patches, it may finally be time for an upgrade</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/phones/iphones/more-than-220-million-iphones-under-attack-from-new-darksword-exploit-how-to-stay-safe">More than 220 million iPhones under attack from new DarkSword exploit — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/online-age-verification-timeline">Online age verification in the USA – a complete timeline</a></li><li><a href="https://www.tomsguide.com/computing/online-security/identity-protection-company-aura-suffers-massive-900-000-person-data-breach-customer-information-exposed">Identity protection company Aura suffers massive 900,000 person data breach: customer information exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Drive just rolled out new tools to protect you from ransomware — here's how they work ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/google-drive-just-rolled-out-new-tools-to-protect-you-from-ransomware-heres-how-they-work</link>
                                                                            <description>
                            <![CDATA[ Google Drive has just rolled out free ransomware protection for desktop users, keeping you alerted to potential attacks and making sure you can get your files back. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">H9uD8yTpb2cgLZxQRDBAWE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pCTDWFqfTErYyUmDTN5v4X-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 31 Mar 2026 12:29:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing Peripherals]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ tom.pritchard@futurenet.com (Tom Pritchard) ]]></author>                    <dc:creator><![CDATA[ Tom Pritchard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/biCewUkKfSA6QnT2HxVc3f.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pCTDWFqfTErYyUmDTN5v4X-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of Google Drive logo on a laptop screen]]></media:description>                                                            <media:text><![CDATA[Image of Google Drive logo on a laptop screen]]></media:text>
                                <media:title type="plain"><![CDATA[Image of Google Drive logo on a laptop screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pCTDWFqfTErYyUmDTN5v4X-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Last year, Google added new beta features to Google Drive, designed to detect ransomware and aid file restoration where needed. Today, <a href="https://workspaceupdates.googleblog.com/2026/03/ransomware-detection-and-file-restoration-for-Google-Drive-now-generally-available.html" target="_blank"><u>Google </u></a><a href="https://workspaceupdates.googleblog.com/2026/03/ransomware-detection-and-file-restoration-for-Google-Drive-now-generally-available.html" target="_blank"><u>announced</u></a> that those same tools are rolling out to everyone, with upgraded AI detection that can recognize 14 times as many infections as before.</p><p>onsidering today is<a href="https://www.tomsguide.com/gaming/playstation/ive-seen-people-lose-their-most-precious-photos-9-products-you-should-buy-this-world-backup-day-chosen-by-an-ex-apple-genius"><u> World Backup Day</u></a>, it's pretty handy to get a bunch of tools designed to protect your backups from harm.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/pyBhWAIwToU" allowfullscreen></iframe></div></div><p>So how does this work, exactly? The tools are built into Google Drive for desktop, and should the app detect ransomware on a connected device, it will automatically pause all file syncing. This is to stop the ransomware from interfering with files stored in your Drive account and from spreading to other connected devices.</p><p> Google Drive will start by scanning your backups for potential ransomware, and if anything is detected, it will automatically pause syncing. This is to prevent you from spreading those files to your other devices and causing significantly more damage. The user is then notified about the file, and emails will be sent out to all connected users. It's not a subtle warning and includes a list of everything you need to do to solve the issue. </p><p>The first step is to disconnect your account from the Drive client, then use the Drive restoration tool to quickly and easily restore previous versions of your files. Google stores older versions for 25 days, giving you plenty of time to retrieve your data and undo any damage caused by the ransomware attack.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2048px;"><p class="vanilla-image-block" style="padding-top:69.43%;"><img id="k5UsH2fXCBVdbknLaU5VNe" name="Ransomware detection and file restoration for Google Drive-6" alt="google drive ransomware detected warning" src="https://cdn.mos.cms.futurecdn.net/k5UsH2fXCBVdbknLaU5VNe.png" mos="" align="middle" fullscreen="" width="2048" height="1422" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google )</span></figcaption></figure><p>This isn't designed to be a replacement for antivirus or other defensive tools that would protect from ransomware. It's an additional layer of protection designed to help you catch the problem before the damage is irreversible — and ensure you can safely restore backed-up files later.</p><p>Google Drive's tools are free to use as well, which means regular users won't have to invest in expensive or business-focused software to better protect themselves against ransomware.</p><p>Google says that ransomware protection is now enabled by default and will be available in Google Drive version 114 and later. You can set the detection level in the settings or disable these protections altogether. Since Google has said it won't scan your files to train its AI without your express permission, we recommend that you only switch it off if you have better, more powerful ransomware protection tools at your disposal.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/phones/android-phones/ive-been-waiting-a-decade-for-airdrop-on-android-and-its-finally-fixed-my-biggest-frustration">I’ve been waiting a decade for AirDrop on Android — and it’s finally fixed my biggest frustration</a></li><li><a href="https://www.tomsguide.com/phones/i-put-iphone-17-pro-max-vs-samsung-galaxy-s26-ultra-through-a-7-round-face-off-heres-which-is-best-for-you">I put iPhone 17 Pro Max vs Samsung Galaxy S26 Ultra through a 7-round face-off — here's which is best for you</a></li><li><a href="https://www.tomsguide.com/phones/iphones/iphone-fold-tipped-to-be-the-most-significant-overhaul-in-iphone-history-and-heres-why-i-agree">iPhone Fold tipped to be most 'significant overhaul' in iPhone history — here's why I agree</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This dangerous iPhone spyware can completely disable Apple's privacy indicators and spy on you in secret ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-dangerous-iphone-spyware-can-completely-disable-apples-privacy-indicators-and-spy-on-you-in-secret</link>
                                                                            <description>
                            <![CDATA[ The Predator spyware has been updated with new capabilities that make it harder to know when your iPhone’s camera and microphone have been hijacked. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">teRjLhh2MFegENfmAdY9ka</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SH2rjMfqfB45gtNa6R85EJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Feb 2026 20:07:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SH2rjMfqfB45gtNa6R85EJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[iPhone 15 Pro shown in hand]]></media:description>                                                            <media:text><![CDATA[iPhone 15 Pro shown in hand]]></media:text>
                                <media:title type="plain"><![CDATA[iPhone 15 Pro shown in hand]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SH2rjMfqfB45gtNa6R85EJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In order to help iPhone users know when their device’s camera and microphone were currently in use, Apple added <a href="https://www.tomsguide.com/phones/iphones/that-mysterious-black-dot-on-your-iphone-screen-is-actually-protecting-your-privacy-heres-how">privacy indicators</a> back in 2020 with the release of iOS 14. Now though, the creators of the notorious <a href="https://www.tomsguide.com/news/this-dangerous-android-malware-spies-on-your-every-move-what-to-do">Predator spyware</a> have figured out how to completely disable them to make spying on potential victims a whole lot easier.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/predator-spyware-hooks-ios-springboard-to-hide-mic-camera-activity/" target="_blank">BleepingComputer</a>, the European-based surveillance company Intellexa has given its spyware a major update which allows it to hide the green and orange dots that let you know when your iPhone is recording video or audio. It’s worth noting that, instead of exploiting a vulnerability in Apple’s mobile operating system, the spyware uses previously obtained kernel-level access to pull this off.</p><p>Here’s everything you need to know about this latest development with the Predator spyware along with how to keep your iPhone safe from being spied on.</p><h2 id="intercepting-recording-indicators">Intercepting recording indicators</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="QhTpUEDBuRqPb9dJSPKqdL" name="iPhone black dot" alt="iPhone black dot" src="https://cdn.mos.cms.futurecdn.net/QhTpUEDBuRqPb9dJSPKqdL.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: GuideRealm / Youtube)</span></figcaption></figure><p>In order to learn more about this new Predator capability, researchers at the mobile device management firm <a href="https://www.tomsguide.com/news/hackers-are-using-a-fake-pdf-viewer-to-infect-macs-with-malware-how-to-stay-safe">Jamf</a> analyzed recent spyware samples to see how Intellexa managed to disable Apple’s privacy indicators.</p><p>According to a <a href="https://www.jamf.com/blog/predator-spyware-ios-recording-indicator-bypass-analysis/" target="_blank">new report</a>, the firm’s security researchers discovered that the spyware hides all recording indicators on iOS 14 and later versions of Apple’s mobile operating system by using a single hook function in the core system application SpringBoard. This method is used whenever an iPhone’s camera or microphone is opened and the device’s sensor activity changes.</p><p>By intercepting these changes quickly, Predator is able to prevent any sensor activity changes from showing up on iPhone’s UI which means the green and orange dots won’t appear. Interestingly, since the hook nullifies all sensor update activity, it can be used to disable a device’s camera and microphone indicator at the same time.</p><p>Fortunately as Jamf’s researchers explain, “the technique outlined in this analysis requires a device to first be fully compromised, including kernel-level access to install hooks and the ability to inject code into system processes,” which means that it only works on iPhones that have already been fully hacked.</p><h2 id="how-to-stay-safe-from-spyware-on-your-iphone">How to stay safe from spyware on your iPhone</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="DgqWmPAUgj3TpRQWmkkka7" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/DgqWmPAUgj3TpRQWmkkka7.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>With one of the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html">best iPhones</a>, you don’t have to worry about malicious apps spreading malware like on Android. However, since Apple’s phones are so popular and known for being difficult to hack, there’s a very lucrative spyware market built around them.</p><p>The good news is that with spyware, cybercriminals and others who use it in their attacks typically tend to go after high-profile targets such as CEOs, celebrities, politicians and other government officials.</p><p>Still, in order to keep your iPhone safe from spyware, the first and most important thing you can do is to keep it updated and running the latest version of iOS. The reason why is that Predator and other spyware strains often rely on now patched vulnerabilities to gain a foothold on targeted devices. By keeping your iPhone updated and restarting it at least once a week, you’re making your phone a whole lot harder to hack.</p><p>If you want to find out if there is spyware installed on your iPhone, then you should check out <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-pegasus-spyware-could-be-hiding-on-your-iphone-this-usd1-app-can-find-it">iVerify’s $1 Basics app</a>. Once installed, it scans your iPhone on a monthly basis to check for the infamous <a href="https://www.tomsguide.com/computing/malware-adware/apple-issues-new-spyware-warning-for-iphone-users-in-98-countries-how-to-stay-safe">Pegasus spyware</a> created by the <a href="https://www.tomsguide.com/news/ios-16-getting-extreme-lockdown-mode-what-it-means-for-your-iphone">NSO Group</a> but it can find other spyware strains too.</p><p>Although there isn’t an iOS equivalent to the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a>, one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> suites in particular can scan an iPhone or iPad for spyware and other types of malware. When connected to a Mac via a USB cable, <a href="https://www.tomsguide.com/reviews/intego-premium-bundle-x9">Intego’s Mac antivirus</a> can scan an iPhone for viruses just like it would with an Apple computer.</p><p>The Predator spyware might not be the biggest threat to ordinary people but if you open your camera app or Apple’s Voice Memos and suddenly don’t see a green or orange privacy indicator light, you’ll now know why.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/new-zerodayrat-spyware-gives-hackers-total-control-over-your-iphone-or-android-and-it-all-starts-with-a-text">A new spyware called ZeroDayRat can take over your iPhone or Android via text</a></li><li><a href="https://www.tomsguide.com/computing/online-security/1-billion-personal-records-from-26-countries-exposed-in-massive-new-data-leak-how-to-stay-safe">1 billion personal records exposed in massive new data leak — full names, addresses, phone numbers and more</a></li><li><a href="https://www.tomsguide.com/computing/online-security/300-000-chrome-users-installed-these-malicious-extensions-posing-as-ai-assistants-delete-them-right-now">300,000+ Chrome users installed these malicious extensions posing as AI assistants — delete them right now</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Multiple Android devices found to have dangerous built-in backdoor: how to know if yours is safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-new-keenadu-malware-found-pre-installed-on-cheap-android-phones-and-tablets-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ A new Android malware was found to be pre-installed on some budget Android phones and tablets by security researchers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VK7RU3JGPK5ZqTyiUWFpng</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/v6Ro3B6LfmJmFroAuNUBf8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 17 Feb 2026 23:22:16 +0000</pubDate>                                                                                                                                <updated>Wed, 18 Feb 2026 17:00:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Android Tablets]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                    <category><![CDATA[Tablets]]></category>
                                                                                                <author><![CDATA[ scott.younker@futurenet.com (Scott Younker) ]]></author>                    <dc:creator><![CDATA[ Scott Younker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RZsUpqcJ6Uj2q83oCUwNhQ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the latest tech news, including phones, computing and more. He’s been involved in tech since 2011 covering everything from cameras and swimming pool equipment to the latest gaming consoles and smart TVs. He is on a seemingly never ending hunt to build the easiest to use home media system. &lt;/p&gt;&lt;p&gt;Before Tom’s Guide, Scott worked for publications like &lt;em&gt;Digital Trends, Outdoor Photographer, Dead Beats Panel&lt;/em&gt;, and in a brief detour, &lt;em&gt;America’s Funniest Home Videos&lt;/em&gt;. Yes, he has seen more pratfalls, silly pets and ridiculous home movie fails than is reasonably healthy. &lt;/p&gt;&lt;p&gt;When not writing about the latest devices or advances in chipsets, be sure to ask about Scott about disc golf and sustainability, or just if you’re being cheeky, ask about his noodle arm. If you truly want to get nerdy, bring up board games and his ongoing losing streak. &lt;/p&gt;&lt;p&gt;Scott joined Tom&#039;s Guide in 2024 as the West Coast Reporter. He graduated from the School of Journalism at the University of Oregon with a degree in magazine journalism and a minor in communications. While there he blogged or wrote for several magazines including the Fluxx, Ethos and the Oregon Commentator. He briefly wrote and managed a moderately successful blog focused on web comics. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/v6Ro3B6LfmJmFroAuNUBf8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android logo on phone next to Malware sign]]></media:description>                                                            <media:text><![CDATA[Android logo on phone next to Malware sign]]></media:text>
                                <media:title type="plain"><![CDATA[Android logo on phone next to Malware sign]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/v6Ro3B6LfmJmFroAuNUBf8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Most Android malware is spread through <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now">dodgy apps</a> and sideloaded programs, meaning that you can slightly control what gets on your device. However, researchers at Kaspersky have discovered a new Android backdoor, dubbed Keenadu, that is embedded in the firmware of tablets from several manufacturers. </p><p>The <a href="https://securelist.com/keenadu-android-backdoor/118913/" target="_blank">new report</a> indicates that Keenadu can be distributed via compromised firmware images, other backdoors, embedded in system apps or modified from third-party sources or even the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a>.</p><p>The firmware version is the most potent and has infected more than 13,000 devices mostly in Russia, Japan, Germany, Brazil and the Netherlands. Keenadu apparently does not activate if the language or time zone is associated with China, which indicates a potential clue as to its origin.</p><h2 id="how-it-works-2">How it works</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:5451px;"><p class="vanilla-image-block" style="padding-top:57.24%;"><img id="vLvwDcmL4mXhep5vxCdjGH" name="Android robot.jpg" alt="An image of a Google Android robot" src="https://cdn.mos.cms.futurecdn.net/vLvwDcmL4mXhep5vxCdjGH.jpg" mos="" align="middle" fullscreen="" width="5451" height="3120" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Kaspersky researchers noted that it's mostly being used for fraudulent ads, but that it's capabilities go far beyond that. It can inject itself into the Android "Zygote" process, a core system process that launches every app on your device. </p><p>This means it can give bad actors broad control and visibility over your system. </p><p>“Keenadu is a fully functional backdoor that provides the attackers with unlimited control over the victim’s device,” Kaspersky told <a href="https://www.bleepingcomputer.com/news/security/new-keenadu-backdoor-found-in-android-firmware-google-play-apps/" target="_blank">BleepingComputer</a>. "It can infect every app installed on the device, install any apps from APK files, and give them any available permissions.”</p><p>The researchers also found the malware in several apps that were available on the Google Play Store, including a smart home camera app that had over 300,000 downloads.</p><p>In a confirmed example, firmware images on the Alldocube iPlay 50 mini Pro tablet were compromised, including in tablets released after the vendor was informed of the malware. The firmware has valid signatures, meaning that it's a supply-chain issue where malicious code was injected during software development or even the manufacturing process.</p><p>Here's the silver lining: if you have one of the <a href="https://www.tomsguide.com/best-picks/best-tablet">best tablets</a> from a flagship brand like OnePlus or Samsung, you likely won't be affected by this malware. However, lesser-known Android manufacturers or knock-off ones seem to be more dangerous, and affected vendors haven't been totally named. This is quite similar to how malware was found on <a href="https://www.tomsguide.com/news/millions-of-cheap-android-tv-boxes-come-pre-infected-with-botnet-malware">millions of budget Android TV boxes</a> last year.</p><h2 id="how-to-stay-safe">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:6000px;"><p class="vanilla-image-block" style="padding-top:42.85%;"><img id="3z8zoqArEPDcAmipKQ4pJg" name="RedMagic Astra" alt="The RedMagic Astra Android gaming tablet" src="https://cdn.mos.cms.futurecdn.net/3z8zoqArEPDcAmipKQ4pJg.jpg" mos="" align="middle" fullscreen="" width="6000" height="2571" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tom's Guide)</span></figcaption></figure><p>If you have a budget Android tablet, especially from a smaller or knock-off brand, it's worth checking for software updates. You can also try installing fresh firmware from a reliable third-party. Kaspersky did say that vendors have been notified and hopefully are working on clean firmware updates.</p><p>Beyond that, it may be safer to invest in a tablet from a trusted manufacturer. We can help you with choices of the <a href="https://www.tomsguide.com/best-picks/best-tablets-under-dollar500">best tablets under $500</a> and the <a href="https://www.tomsguide.com/best-picks/best-android-tablets">best Android tablets</a> overall.</p><p>A Google spokesperson told Android Authority that "Android users are automatically protected from known versions of this malware by Google Play Protect." The spokesperson added that <a href="https://www.tomsguide.com/reviews/google-play-protect">Play Protect</a> will warn you and disable apps known to exhibit Keenadu behavior. </p><p>Google Play Protect is on by default, but if you want an extra layer of protection, you can run one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it for scanning and defending your tablet or phone.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/300-000-chrome-users-installed-these-malicious-extensions-posing-as-ai-assistants-delete-them-right-now">300,000+ Chrome users installed these malicious extensions posing as AI assistants — delete them right now</a></li><li><a href="https://www.tomsguide.com/computing/online-security/how-did-the-fbi-get-nancy-guthries-google-nest-camera-footage-if-it-was-disabled-and-what-does-it-mean-for-your-privacy">How did the FBI get Nancy Guthrie's Google Nest camera footage if it was disabled — and what does it mean for your privacy?</a></li><li><a href="https://www.tomsguide.com/computing/vpns/i-visited-a-vpn-data-center-heres-what-i-learned">I visited a VPN data center – here's what I learned</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A new spyware called ZeroDayRat can take over your iPhone or Android via text — here is how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-zerodayrat-spyware-gives-hackers-total-control-over-your-iphone-or-android-and-it-all-starts-with-a-text</link>
                                                                            <description>
                            <![CDATA[ From hijacking your accounts to tracking your every move in real-time ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7HTzPKW4JhAdSb2myTNWM3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VazMxhsAYV5RMjE6KLzpHe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Feb 2026 20:01:44 +0000</pubDate>                                                                                                                                <updated>Tue, 10 Feb 2026 22:35:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VazMxhsAYV5RMjE6KLzpHe-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[spyware on phone]]></media:description>                                                            <media:text><![CDATA[spyware on phone]]></media:text>
                                <media:title type="plain"><![CDATA[spyware on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VazMxhsAYV5RMjE6KLzpHe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Whether you use an iPhone or an Android phone, hackers have a brand new tool that’s capable of completely hijacking it to steal your data, track your location, log your keystrokes, intercept your 2FA codes and more. The worst part? The tool is sold on the <a href="https://www.tomsguide.com/news/hackers-have-earned-millions-selling-your-data-on-the-dark-web-how-to-stay-safe">dark web</a> with full customer support in case they run into any problems.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/zerodayrat-malware-grants-full-access-to-android-ios-devices/" target="_blank">BleepingComputer</a>, the new ZeroDayRAT malware is a commercial mobile spyware platform that’s currently being advertised to cybercriminals on <a href="https://www.tomsguide.com/computing/malware-adware/that-innocent-looking-calendar-invite-could-infect-your-mac-with-malware-dont-fall-for-this">Telegram</a>. Thanks to its very detailed dashboard, any hacker that deploys this malware in their attacks is easily able to manage infected devices while stealing all of their data and tracking them in real-time.</p><p>Here’s everything you need to know about this new mobile threat along with what it’s capable of, along with some tips on how to stay safe so you can recognize a potential infection before it takes over your phone.</p><h2 id="full-access-to-your-device-location-and-more">Full access to your device, location and more</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iUW5SS59PPhYiBQVLRsDBJ" name="zerodayrat-screenshot-iverify" alt="A screenshot of the ZeroDayRAT malware's dashboard showing an infected phone's location in real time" src="https://cdn.mos.cms.futurecdn.net/iUW5SS59PPhYiBQVLRsDBJ.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: iVerify/Tom's Guide)</span></figcaption></figure><p>ZeroDayRAT acts like a one-stop shop for hackers when it comes to the sensitive data, login info and crypto stored on one of the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html">best iPhones</a> or <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a>. And to make matters worse, it can allegedly infect devices running the latest software, whether that be <a href="https://www.tomsguide.com/phones/iphones/ios-26-review-new-features-liquid-glass">iOS 26</a> or <a href="https://www.tomsguide.com/phones/google-pixel-phones/google-just-launched-android-16-plus-a-bunch-of-other-useful-software-upgrades">Android 16</a>.</p><p>In a <a href="https://iverify.io/blog/breaking-down-zerodayrat---new-spyware-targeting-android-and-ios" target="_blank">new report</a>, researchers at <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-pegasus-spyware-could-be-hiding-on-your-iphone-this-usd1-app-can-find-it">iVerify</a> explain that they first discovered ZeroDayRAT after seeing it openly sold on Telegram at the start of this month. In addition to customer support, the malware’s developer also provides regular updates so it will remain a viable tool in a hacker’s arsenal for even longer.</p><div><blockquote><p>A hacker can also use ZeroDayRAT to activate a phone’s front and rear cameras and  microphone to spy on victims. From there, GPS access gives them the ability to track a victim’s location in real time.</p></blockquote></div><p>ZeroDayRAT is quite sophisticated on its own with the ability to glean all kinds of useful information from an infected device. Besides a phone’s make and model, operating system version, battery life, SIM details, country of origin and lock state, the malware can also log a victim’s app usage, their text messages, notifications and more. Likewise, a hacker can also use ZeroDayRAT to activate a phone’s front and rear cameras as well as its microphone to spy on victims in real-time.</p><p>From there, GPS access gives them the ability to track a victim’s location in real time and even see their current position on Google Maps. Then with SMS access, ZeroDayRAT can capture one-time passwords to bypass two-factor authentication (<a href="https://www.tomsguide.com/news/rilide-malware-is-stealing-2fa-codes-and-passwords-what-you-need-to-know">2FA</a>) which lets an attacker take over a victim’s social media and banking accounts.</p><p>If that wasn’t enough, the malware even features a cryptocurrency stealer module that scans an infected device to look for wallet IDs and balances from Coinbase, Binance, MetaMask and Trust Wallet. As we’ve seen with other malware in the past, ZeroDayRAT also uses <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-banking-trojan-now-shows-a-fake-lock-screen-to-steal-your-pin-and-your-cash-dont-fall-for-this">overlay attacks</a> to steal online banking logins as well as credentials for Apple Pay, Google Pay and PayPal.</p><p>Perhaps the most surprising thing about ZeroDayRAT for me though is its online dashboard. Right from their browser, hackers have all the info they need from devices they’ve infected with the malware to launch additional attacks and keep tabs on any that are currently underway. It’s clear a lot of work went into creating this new spyware platform and depending on how much it costs, ZeroDayRAT could become a household name among cybercriminals.</p><h2 id="how-to-stay-safe-from-spyware">How to stay safe from spyware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>As iVerify points out in its report, a ZeroDayRAT infection begins by getting a malicious binary onto a targeted device: either as an APK for Android or a payload for iOS. While we don’t know exactly how cybercriminals are spreading this spyware yet, the firm’s security researchers believe that SMS phishing or <a href="https://www.tomsguide.com/computing/vpns/what-is-smishing-one-ingenious-way-to-avoid-it">smishing</a> is likely the easiest infection method.</p><p>Whether you have an iPhone or an Android device, you want to be on the lookout for text messages from unknown senders containing a link that try to coerce you into downloading an app. They might use a <a href="https://www.tomsguide.com/news/this-new-phishing-scam-can-steal-your-social-security-number-how-to-stay-safe">sense of urgency</a> or other common tactics to do so. While fake text messages are one probable delivery method, <a href="https://www.tomsguide.com/news/this-is-the-one-thing-to-look-out-for-in-scam-emails">phishing emails</a>, <a href="https://www.tomsguide.com/computing/malware-adware/amazon-appstore-used-to-spread-android-malware-delete-this-malicious-app-right-now">fake app stores</a> and links on WhatsApp or Telegram are other ways the ZeroDayRAT spyware can be distributed too.</p><p><strong>To stay safe from this new mobile threat, your best bet is to avoid clicking on any links sent to you via text messages, emails or through social media. </strong>It’s always best to avoid clicking on anything <a href="https://www.tomsguide.com/news/avoid-these-email-attachments-if-you-dont-want-to-get-phished">sent from an unknown sender</a> but I’d also recommend being wary of links sent from friends or even acquaintances that you haven’t spoken with in a while. Once hackers take over one person’s accounts, they often use them in other attacks. A message from an old friend on social media about a new app that’s changed their life or made a common task a lot easier is the kind of lure that I could easily see unsuspecting users falling for.</p><p>In order to stay safe from the latest threats, you should be using the <a href="https://www.tomsguide.com/computing/antivirus/best-antivirus-software">best antivirus software</a> on your PC or the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> on your Apple computer. On mobile, the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> can keep your phone safe from malware but due to Apple’s own restrictions, there aren’t any antivirus apps for iPhone. However, many antivirus makers do offer protection for iOS through their main software suites. For instance, <a href="https://www.tomsguide.com/reviews/intego-premium-bundle-x9">Intego’s Mac antivirus</a> can scan an iPhone or iPad for malware but only when it’s connected to a Mac via a USB cable.</p><p>While we haven’t heard about any major attacks carried out using the ZeroDayRAT yet, chances are, we likely will soon. I’ll be keeping a close eye on this new mobile spyware platform just in case. In the meantime though, by practicing good cyber hygiene and being careful where you click or tap, you should be able to avoid falling victim to the ZeroDayRAT and other mobile malware.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/149-million-passwords-for-gmail-facebook-instagram-and-other-popular-services-exposed-online-how-to-stay-safe-after-this-major-leak"><strong>149 million logins and passwords exposed for Gmail, Facebook, Instagram and more — everything you need to know</strong></a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hugging-face-ai-platform-used-to-deliver-android-malware-via-fake-apps-dont-fall-for-this"><strong>Total phone hijack: New Hugging Face malware grants hackers full remote access</strong></a></li><li><a href="https://www.tomsguide.com/computing/online-security/massive-government-tech-data-breach-expands-to-more-than-25-million-more-americans-a-year-after-it-was-discovered"><strong>Massive government tech data breach expands to more than 25 million more Americans a year after it was discovered</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Total phone hijack: New Hugging Face malware grants hackers full remote access ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hugging-face-ai-platform-used-to-deliver-android-malware-via-fake-apps-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ Hugging Face may be hosting a fake app that is being used to send out Android malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xJemxwEz8UiTfrFZWccbX8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/v6Ro3B6LfmJmFroAuNUBf8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Jan 2026 19:49:16 +0000</pubDate>                                                                                                                                <updated>Mon, 02 Feb 2026 18:22:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ scott.younker@futurenet.com (Scott Younker) ]]></author>                    <dc:creator><![CDATA[ Scott Younker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RZsUpqcJ6Uj2q83oCUwNhQ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the latest tech news, including phones, computing and more. He’s been involved in tech since 2011 covering everything from cameras and swimming pool equipment to the latest gaming consoles and smart TVs. He is on a seemingly never ending hunt to build the easiest to use home media system. &lt;/p&gt;&lt;p&gt;Before Tom’s Guide, Scott worked for publications like &lt;em&gt;Digital Trends, Outdoor Photographer, Dead Beats Panel&lt;/em&gt;, and in a brief detour, &lt;em&gt;America’s Funniest Home Videos&lt;/em&gt;. Yes, he has seen more pratfalls, silly pets and ridiculous home movie fails than is reasonably healthy. &lt;/p&gt;&lt;p&gt;When not writing about the latest devices or advances in chipsets, be sure to ask about Scott about disc golf and sustainability, or just if you’re being cheeky, ask about his noodle arm. If you truly want to get nerdy, bring up board games and his ongoing losing streak. &lt;/p&gt;&lt;p&gt;Scott joined Tom&#039;s Guide in 2024 as the West Coast Reporter. He graduated from the School of Journalism at the University of Oregon with a degree in magazine journalism and a minor in communications. While there he blogged or wrote for several magazines including the Fluxx, Ethos and the Oregon Commentator. He briefly wrote and managed a moderately successful blog focused on web comics. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/v6Ro3B6LfmJmFroAuNUBf8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android logo on phone next to Malware sign]]></media:description>                                                            <media:text><![CDATA[Android logo on phone next to Malware sign]]></media:text>
                                <media:title type="plain"><![CDATA[Android logo on phone next to Malware sign]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/v6Ro3B6LfmJmFroAuNUBf8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Update: Google spokesperson says malware not found in Google Play Store.</em></p><p>Hackers are reportedly using the popular Hugging Face AI platform to release Android malware that can take over your device. The malware is delivered via a fake app.</p><p>For the unfamiliar, Hugging Face is an open platform that hosts AI tools and machine learning bots. Users and creators can distribute and download AL, NLP and ML models. Unfortunately, sometimes it can be used to release bad models as well.</p><p>Researchers at the <a href="https://www.bitdefender.com/en-us/blog/labs/android-trojan-campaign-hugging-face-hosting-rat-payload" target="_blank">cybersecurity firm Bitdefender</a> found that this new malware first appeared in an app called TrustBastion. Hugging Face "doesn’t seem to have meaningful filters that govern what people can upload," the researchers said.</p><p>Apparently, TrustBastion pretends to be an Android antivirus program by "offering" virus protection, phishing defense and malware blocking. In reality, this app is "scareware": once you install it, it claims your device is infected and demands an update. Once you update the app, it installs the malicious code.</p><h2 id="what-this-malware-does">What this malware does</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PbeFVKqQsQuuMkjGf5fKaS" name="malware shutterstock_1454959559 final.jpg" alt="Malware on phone" src="https://cdn.mos.cms.futurecdn.net/PbeFVKqQsQuuMkjGf5fKaS.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Bitdefender says TrustBastion connects to a third-party server, which then redirects to a Hugging Face repository with 6,000 commits. Despite being reported, Bitdefender says a new repository almost immediately appeared with a new name and icons, but the same malicious code.</p><p>This Trojan malware is quite powerful. According to Bitdefender, it can take screenshots, display fake login interfaces for financial serives and capture your lock screen pin. That information is then sent to a third-party server.</p><h2 id="malware-isn-t-in-google-play-says-google">Malware isn't in Google Play, says Google</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="i5cgxeu9C8nriveZ9RTMGg" name="Google Play Collections.jpg" alt="Google Play Collections show on Android phone." src="https://cdn.mos.cms.futurecdn.net/i5cgxeu9C8nriveZ9RTMGg.jpg" mos="" align="middle" fullscreen="" width="2000" height="1124" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Future)</span></figcaption></figure><p>A Google spokesperson told Tom's Guide that according to their systems this malware and apps containing it are not in the Google Play store. </p><p>"Based on our current detection, no apps containing this malware are found on Google Play," the spokesperson said.</p><p>They added that Android users are automatically protected against "known versions of this malware" by Google Play Protect, which scans apps for malicious behavior and can warn users or block apps.</p><h2 id="how-to-stay-safe-2">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LHpZVYPdyJuvFiGy8SXsHX" name="google-play-stock-image.jpg" alt="Google Play on a Samsung Galaxy phone" src="https://cdn.mos.cms.futurecdn.net/LHpZVYPdyJuvFiGy8SXsHX.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The simplest thing you can do is download Android apps only from reputable sources with some form of moderation and security filtering, such as the Google Play Store or the Samsung Galaxy Store. Even in those places, be sure to scour the reviews and note the overall downloads and rating.</p><p>Avoid sideloading APKs outside of the store. If you are triple-checking that the publisher and URL are correct before you download. Be wary of any apps that ask for accessibility permissions.</p><p>You should periodically scan your Android device with Play Protect and bolster your security with some of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps.</a></p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/fake-chrome-extension-breaks-your-computer-before-it-hits-you-with-malware-how-to-stay-safe">Fake Chrome extension ‘breaks’ your computer before it hits you with malware — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/malicious-zoom-stealer-extensions-can-leak-your-private-meeting-details-how-to-stay-safe">Malicious Zoom Stealer extensions can leak your private meeting details — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-malicious-code-to-take-over-legitimate-banking-apps-and-your-phone-dont-fall-for-this">New malware turns trusted banking apps into phone hijacking tools — how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malicious Zoom Stealer extensions can leak your private meeting details — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/malicious-zoom-stealer-extensions-can-leak-your-private-meeting-details-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Chrome, Edge and Firefox users are under attack by a new malware that uses malicious browser extensions to steal meeting info. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nDMgUNKSLPjs2uTTSf6GbR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PRoTgserWs88RaSbncJX9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Jan 2026 17:36:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PRoTgserWs88RaSbncJX9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zoom Shutterstock]]></media:description>                                                            <media:text><![CDATA[Zoom Shutterstock]]></media:text>
                                <media:title type="plain"><![CDATA[Zoom Shutterstock]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PRoTgserWs88RaSbncJX9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new <a href="https://www.tomsguide.com/computing/malware-adware/chrome-and-edge-users-infected-with-malicious-browser-extensions-that-steal-your-personal-data-what-to-do-now">malicious browser extension</a> has been discovered that along with two others, are designed to steal credentials, take over browsers and more. Discovered by security researchers at <a href="https://www.koi.ai/blog/darkspectre-unmasking-the-threat-actor-behind-7-8-million-infected-browsers" target="_blank">Koi Security</a>, all three extensions are believed to be created by the same threat actor and put millions of Chrome, Edge and Firefox users at risk.</p><p>This most recent malware has been dubbed Zoom Stealer and its uses 18 different extensions to steal online meeting information like URLs, embedded passwords, meeting IDs, schedule times, registration status, topics and descriptions. These extensions affect up to 2.2 million Chrome, Firefox and Edge users and are specifically designed to imitate enterprise level tools for video conferencing apps like Google Meet and Zoom.</p><p>The extensions, which succeed specifically because they perform as advertised and have positive reviews, also silently run surveillance in the background to exfiltrate details of the meeting like links, participant lists and credentials using a WebSocket connection. If a users visits a webinar registration page with one of the malicious extensions installed in their browser, the threat actors can harvest all sorts of data including information about the speakers, the hosts and the session metadata. </p><p>The Zoom Stealer campaign is the third rolled out from the threat actor known as DarkSpectre. The first, known as <a href="https://www.tomsguide.com/computing/malware-adware/this-spyware-campaign-can-turn-your-browser-extensions-into-malware-how-to-stay-safe">ShadyPanda</a>, was found by the same researchers last month and was used to commit fraud, hijack search queries and carry out data theft from more than five million users. The second campaign, known as <a href="https://www.tomsguide.com/computing/online-security/multiple-firefox-add-ons-infected-with-ghostposter-malware-how-to-stay-safe">GhostPoster</a>, used hidden malicious JavaScript code inside logo files in order to gain full control over a browser. </p><h2 id="how-to-stay-safe-from-malicious-browser-extensions">How to stay safe from malicious browser extensions</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:60.00%;"><img id="uUoJKen9wwfAxwn6WvpUbW" name="chrome-ledeimage.jpeg" alt="A computer showing the Chrome Web Store" src="https://cdn.mos.cms.futurecdn.net/uUoJKen9wwfAxwn6WvpUbW.jpeg" mos="" align="middle" fullscreen="" width="970" height="582" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tom's Guide)</span></figcaption></figure><p>As with any other malicious extension, if you've downloaded anything that you suspect isn't entirely legitimate, you should remove it immediately. </p><p>After removing a problematic  extension, you should always reset your account passwords – often, the recommendation is for all your high profile accounts like your email, online banking and social media ones too. Since this could be a hassle, you should use one of the <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">best password managers</a> to make it easier since many can update compromised passwords for you. A password manager can also help keep your passwords organized, safe and can automatically generate <a href="https://www.tomsguide.com/opinion/im-a-security-editor-and-this-is-how-i-create-strong-passwords-that-are-also-easy-to-remember">strong and unique passwords</a> for each of your online accounts.</p><p>I also always recommend using the <a href="https://www.tomsguide.com/computing/antivirus/best-antivirus-software">best antivirus software</a> as well. An antivirus program may not have caught these malicious extensions, but they can scan for malware, spyware and viruses to help you deal with the fallout from a campaign like this one. Antivirus programs also have browser extensions that can warn you when you try to visit suspicious websites, help protect your data with cloud backups and can provide you with a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a> and other extras to add an extra layer of security to protect you when you're online.</p><p>Given how effective malicious extensions like the ones described above have been in the past, I highly doubt cybercriminals are going to stop using them soon. Instead, it's up to you to remain vigilant when it comes to downloading and using new browser extensions. When in doubt though, consider whether or not you really need a particular extension before downloading and adding it to your browser.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/i-write-about-hackers-for-a-living-but-these-are-the-3-real-world-threats-that-worry-me-most">I write about hackers for a living but these are the 3 real-world threats that worry me most — and how to avoid them in 2026</a></li><li><a href="https://www.tomsguide.com/computing/online-security/from-misinformation-to-ai-powered-cyberattacks-the-top-cybersecurity-risks-for-2026">From misinformation to AI-powered cyberattacks – the top cybersecurity risks for 2026</a></li><li><a href="https://www.tomsguide.com/computing/online-security/im-a-security-editor-and-these-are-my-3-security-new-years-resolutions">I’m a security editor and these are my 3 security New Years resolutions</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New malware uses infected VPN apps to take over your device — here's how to stay safe  ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-malware-uses-infected-vpn-apps-to-take-over-your-device-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Newly identified malware can steal your information, as well as gather keystrokes and screenshots. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oESx9aG4wa2KTHGBa7SMpk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m6Kyu58S6jyoyKHFGzRC7M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jan 2025 19:47:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m6Kyu58S6jyoyKHFGzRC7M-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mobile malware]]></media:description>                                                            <media:text><![CDATA[Mobile malware]]></media:text>
                                <media:title type="plain"><![CDATA[Mobile malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m6Kyu58S6jyoyKHFGzRC7M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new malware has been identified by cybersecurity researchers, and it is capable of many information gathering techniques like screen capture, audio capture, remote shell (which permits the threat actor to launch further attacks), keylogging and file transfer and execution. It’s called PLAYFULGHOST and it’s known to be delivered via phishing or SEO poisoning techniques that then distribute trojanized VPN apps. </p><p>Capable of setting up persistence on the host in four different manners (run registry key, scheduled task, Windows Startup folder and Windows service), the feature set in the PLAYFULGHOST malware allows it to gather an extensive set of data. Including keystrokes and screenshots; it can also collect audio, QQ account information, installed security products, clipboard content and system metadata. </p><p>The malware is also capable of dropping more payloads, blocking mouse or keyboard input, clearing Windows event logs, wiping clipboard data, performing file operations, delete caches, deleting web browser profiles, and erasing profiles and storage for messaging apps. </p><p>Also, it can deploy Mimikatz, an open-source application that can extract passwords, a rootkit that is capable of hiding registry, files and processes specified by the threat actor and brings along with it an open-source utility called Terminator that can kill security processes using a BYOVD (Bring Your Own Vulnerable Driver) attack. </p><p>The way that PLAYFULGHOST gains access, or its initial pathway into your system, is usually a phishing email that has a lure mentioning a code of conduct violation, problem or issue; it is also known to use SEO poisoning techniques to send out a malicious version of a legitimate VPN app like LetsVPN. </p><p>One victim was tricked by opening a malicious RAR archive disguised as an image file by using a .jpg extension, which then dropped a malicious Windows executable. That in turn downloaded and executed PLAYFULGHOST from a remote server. <a href="https://www.googlecloudcommunity.com/gc/Community-Blog/Finding-Malware-Unveiling-PLAYFULGHOST-with-Google-Security/ba-p/850676"><u>Google’s Managed Defense team</u></a> has said that the backdoor shares functionality with Gh0st RAT, which had source code publicly leaked in 2008.</p><p>The SEO poisoning attacks attempt to get victims to download malware laced with installers for LetsVPN which then drop an interim payload that will retrieve the backdoor components. </p><p>A PLAYFULGHOST infection leverages DLL search order hijacking and side loading to launch malicious DLL which is used to decrypt and load PLAYFULGHOST into memory. It’s also been observed using combined Windows shortcuts that leverage multiple files to construct rogue DLL to sideload it into a renamed version. </p><p><strong>How to stay safe from PLAYFULGHOST</strong></p><p>Because PLAYFULGHOST is using phishing as a technique, the best way to avoid it is to know common phishing techniques and make sure you can detect them. Only give away personal information to legitimate websites and companies. Never click on an unexpected link or attachment — if you know the sender, contact them directly to see what they sent and why before clicking through. </p><p>If you’re not expecting a code of conduct violation, don’t click on a link in an email. Contact the sender or your HR department to ask about the email first. Only download applications directly from a website you’ve gone to yourself, not from a link sent to you. </p><p>If your company contacts you about an urgent matter regarding your account, don’t click anything in an email, text or message. Instead go directly to their website in the browser’s address bar and type in their web address manually and enter in your log in details yourself. This way, you can make sure you’ve got the company name spelled correctly. (A common phishing technique is to misspell a company name with a “0” instead of an “o.”)</p><p>Maintain best practices with your online accounts: Never reuse passwords, remember you can always use a password manager to help keep your passwords secure. Use <a href="https://www.tomsguide.com/us/how-to-enable-2fa,news-26607.html">two-factor authentication</a> when possible. Keep one of the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus</a> software programs current, updated and running on all your devices – both your PC and even your mobile device. </p><p>We have recommendations for the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> if you don’t already have one installed. And for added protection make sure your antivirus program has a – real – <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a>, or offers a hardened browser for an added layer of security.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/hackers-can-steal-your-accounts-and-all-it-takes-is-a-double-click-dont-fall-for-this-new-form-of-clickjacking">Hackers can steal your accounts, and all it takes is a double click  –  don't fall for this new form of clickjacking</a></li><li><a href="https://www.tomsguide.com/computing/online-security/millions-of-email-users-at-risk-passwords-could-be-exposed-to-hackers-experts-warn">Millions of email users at risk – passwords could be exposed to hackers, experts warns</a></li><li><a href="https://www.tomsguide.com/computing/online-security/the-top-cyber-threats-to-watch-out-for-in-2025">These are the top cyber threats to watch out for in 2025</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using the Amazon Appstore to spread malware — delete this malicious app now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/amazon-appstore-used-to-spread-android-malware-delete-this-malicious-app-right-now</link>
                                                                            <description>
                            <![CDATA[ Hackers have turned to the Amazon Appstore as a way to distribute their malicious apps after the Google Play Store has tightened its security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">964Micj5AMdDzg8bC2xsa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Dec 2024 22:07:49 +0000</pubDate>                                                                                                                                <updated>Thu, 10 Apr 2025 14:03:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Even if you’re not <a href="https://www.tomsguide.com/news/over-60000-compromised-android-apps-found-spreading-adware-how-to-stay-safe"><u>sideloading apps</u></a>, you still need to be careful when downloading new ones from official app stores as you might just end up with a <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now"><u>malicious app</u></a> that can infect even the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a> with dangerous malware.</p><p>Case in point, McAfee Labs researchers have discovered a bad app masquerading as a legitimate health app on the Amazon Appstore. While not nearly as popular as the <a href="https://www.tomsguide.com/news/the-google-play-store-is-making-a-big-change-to-fend-off-malware-heres-how"><u>Google Play Store</u></a>, Amazon’s app store works on phones as well as the <a href="https://www.tomsguide.com/best-picks/best-android-tablets"><u>best Android tablets</u></a>, though it comes pre-installed on the ecommerce giant’s own Fire tablets and Fire TV devices.</p><p>Now that Google has been working hard to lock down the Play Store, hackers have turned to third-party app stores as a means of distributing their malicious apps. I wouldn’t be surprised if they tried something similar on Samsung’s <a href="https://www.tomsguide.com/news/galaxy-store-flaws-can-be-exploited-by-hackers-update-your-samsung-phone-now"><u>Galaxy Store</u></a> going forward.</p><p>Here’s everything you need to know about this new malicious app along with what you should do next to remove it from your phone if you have it installed along with some tips and tricks to help you stay safe from Android malware.</p><h2 id="hiding-in-a-health-utility-app">Hiding in a health utility app</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gUCYmjPWzzzuTSFq9EtFaK" name="malicious bmi app" alt="Screenshots from the malicious BMI CalculationsVsn app McAfee's researchers discovered on the Amazon Appstore" src="https://cdn.mos.cms.futurecdn.net/gUCYmjPWzzzuTSFq9EtFaK.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: McAfee / Tom's Guide)</span></figcaption></figure><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/android-spyware-found-on-amazon-appstore-disguised-as-health-app/" target="_blank"><u>BleepingComputer</u></a>, the app in question is called BMI CalculationsVsn and up until recently, was being promoted as a simple body mass index (BMI) calculator. </p><p>When opened, the app appears to be fairly simple with a single page where users can input their weight and height to calculate their BMI. However, while its user interface does look like a standard health app, it’s performing a range of malicious activities in the background.</p><p>In its <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/spyware-distributed-through-amazon-appstore/" target="_blank"><u>report</u></a> on the matter, McAfee’s researchers explain that the app starts recording a user’s screen whenever they click the “Calculate” button to find out their BMI. A pop-up request to grant the necessary permissions to screen record appears and if a user taps on “Start now” the malicious app begins recording. </p><p>McAfee believes this functionality is most likely used to capture gesture passwords or sensitive data from other apps. However, the firm’s researchers found that the app’s developer “PT Visionet Data Internasional” wasn’t quite ready to make use of this function since the app doesn’t upload the mp4 video files it captures to a command and control (<a href="https://www.tomsguide.com/news/this-new-macos-backdoor-lets-hackers-take-over-your-mac-remotely-how-to-stay-safe"><u>C2</u></a>) server.</p><p>At the same time though, this malicious app is also able to scan a victim’s device to retrieve a list of all of their other installed apps. This info could then be used to identify potential targets as well as to plan out more advanced attacks. Likewise, the BMI CalculationsVsn app also collects every text message received from an infected phone. This is likely done to capture one-time passwords (OTP), verification codes or other sensitive information sent via text.</p><p>The app itself was uploaded to the Amazon Appstore at the beginning of October of this year. While it started out as a screen recording app, its creators pivoted half way through its development cycle and changed it to a BMI calculator with its original screen recording capabilities still enabled. Its app icon was also changed to reflect this.</p><p>Fortunately, McAfee reached out to Amazon upon discovering this malicious app and it has since been delisted. If you happened to install it on your Android phone or tablet while it was still up though, you’re going to need to manually delete it from your device.</p><h2 id="how-to-stay-safe-from-android-malware">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Since bad apps have a habit of ending up on official app stores like the Google Play Store and in this case, the Amazon Appstore, you need to be extremely careful when downloading any new app.</p><p>This means checking its ratings and reviews but since these can be faked, it’s always a good idea to look for external reviews or even a video review since they show you the app in question in action. You also want to look into an app’s developer to make sure they’re legit. A good way to get around installing a malicious app onto your Android devices is to stick with known, trusted apps that often show up on a respective app store’s top charts.</p><p>As for staying safe from Android malware, your first line of defense should be <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect </u></a>as it comes pre-installed on most Android devices. This free security app scans all of your existing apps and any new ones you download for malware, even if you didn’t happen to download them from the Play Store. For extra protection though, I highly recommend using one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside Google Play Protect. They’re updated more frequently and often include other useful extras like a <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a> or a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a>.</p><p>Hackers, scammers and other cybercriminals have been using malicious apps as a way to infect people with malware for years now and as such, I don’t think they’re going to stop doing so anytime soon. This is why it’s up to you to be security savvy and exercise caution when installing new apps on your Android smartphone or tablet.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/news/hackers-are-sneaking-malware-on-to-the-google-play-store-how-to-stay-safe">Hackers are sneaking malware on to the Google Play Store — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/5-million-u-s-credit-cards-were-just-leaked-online-how-to-stay-safe-and-what-to-do-next">5 million Americans just had their credit card details leaked online</a></li><li><a href="https://www.tomsguide.com/computing/online-security/android-phones-under-attack-from-malicious-apps-with-over-8-million-installs-delete-these-now">Android phones under attack from malicious apps with over 8 million installs</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Only 3 of the top 150 Android apps can detect reverse engineering tool Frida — here's why that's bad ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/only-3-of-the-top-150-android-apps-can-detect-reverse-engineering-tool-frida-heres-why-thats-bad</link>
                                                                            <description>
                            <![CDATA[ Frida is a popular tool used by security researchers to examine apps but hackers could also use it to reverse engineer them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ESibXDHaiSYpEgPibGwmCn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Dec 2024 15:05:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A recent analysis of the 150 top Android apps by Norwegian cybersecurity firm Promon found that 144 of them could be successfully configured to operate within the controlled testing environment of the reverse engineering tool Frida. Only three of the apps tested actively detected Frida’s presence and shut down or limited functionality. </p><p>What does that mean? Well, it means that roughly 97% of the most popular Android apps are vulnerable to exploitation by threat actors and have a security gap that needs to be addressed. </p><p>As reported by <a href="https://cybernews.com/security/android-apps-vulnerable-reverse-engineering/" target="_blank">Cybernews</a>, Frida is a dynamic instrumentation toolkit that has grown in popularity among security researchers, reverse engineers and malware analysts. It can be used legitimately but has also become a primary tool used by malicious actors to attack apps. This tookit is considered an essential first step to reverse engineer any app. </p><p>A security researcher at Promon, Simon Lardinois, says that though not all apps are required to detect Frida, the fact that 97% do not “raises significant concerns as it becomes an open invitation for exploitation.” He adds that “For apps that process sensitive data or have sensitive features, this is certainly a wake up call to implement more robust detections for Frida.”</p><p>The cybersecurity experts involved were surprised to find that so few of the top apps tested were protected from common hooking framework, and the reports findings state that this “underscores the need for increased awareness and proactive security measures within the Android development community.” </p><p>Organizations that want to keep user data secure should seek to incorporate Frida detection techniques; these would range from identifying unique library names and memory strings commonly associated with Friday to examining names threads, enumerating exported functions and monitoring network resources. </p><p>Promon also points out that attackers are evolving in their evasion techniques, customizing Frida by stripping down its footprint to bypass these detection mechanisms. </p><p>Unfortunately, the apps tested were not named in the report, however they were the most popular apps based on monthly active users as of November 2024 – with more than 550 million users daily and 206 million monthly users on average. </p><h2 id="how-to-stay-safe-3">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>In order to stay safe from <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now">malicious apps</a> and other mobile threats, you should always keep your phone up to date by installing the latest updates as soon as they become available. In addition to its operating system though, you also want periodically update all of your apps too.<br><br>For an added layer of protection, you want to make sure you've got one of the<a href="https://www.tomsguide.com/best-picks/best-android-antivirus"> best Android antivirus apps</a> installed on your phone as well. They can help remove malware, flag suspicious activity like fraud and phishing attempts and provide you with a secure <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a> or even a <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a>. If you're on a tight budget though, <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> can help keep your phone safe from bad apps and best of all, it comes pre-installed on all of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a>.</p><p>Now that Promon has found that so many of the most popular apps can be used with Frida by attackers in addition to security researchers, expect the makers of this security tool to add additional safeguards to it soon.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/fake-video-conferencing-app-is-stealing-passwords-and-spreading-malware-how-to-stay-safe">Fake video conferencing app is stealing passwords and spreading malware - how to stay safe</a></li><li><a href="https://www.tomsguide.com/phones/android-phones/fbi-tells-iphone-and-android-users-to-stop-texting-each-other-amid-major-security-breach">FBI tells iPhone and Android users to stop texting each other amid major security breach</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/dangerous-pegasus-spyware-could-be-hiding-on-your-iphone-this-usd1-app-can-find-it">Dangerous Pegasus spyware could be hiding on your iPhone — this $1 app can find it</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are posing as job recruiters to spread a dangerous banking trojan and steal your money — don’t fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-posing-as-job-recruiters-to-spread-a-dangerous-banking-trojan-and-steal-your-money-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ Hackers have begun impersonating recruiters and HR representatives to distribute a new version of the Antidot banking trojan to unsuspecting job seekers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TTTchEg29C2L3yxXSMrEEG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Dec 2024 04:30:12 +0000</pubDate>                                                                                                                                <updated>Sat, 14 Dec 2024 00:59:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture depicting how banking trojans steal credit card data]]></media:description>                                                            <media:text><![CDATA[A picture depicting how banking trojans steal credit card data]]></media:text>
                                <media:title type="plain"><![CDATA[A picture depicting how banking trojans steal credit card data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Looking for a new job is already a difficult process on its own, but now hackers want to make things even harder for prospective job seekers by infecting their phones with a <a href="https://www.tomsguide.com/computing/malware-adware/this-nasty-android-banking-trojan-lets-hackers-completely-hijack-your-phone-how-to-stay-safe">banking trojan</a> designed to target any financial apps and services they have installed on their device.</p><p>As reported by <a href="https://thehackernews.com/2024/12/fake-recruiters-distribute-banking.html" target="_blank">The Hacker News</a>, cybersecurity researchers have discovered a new mobile phishing campaign used to distribute an updated version of the <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-banking-trojan-uses-fake-google-play-updates-to-take-over-your-phone-how-to-stay-safe">Antidot banking trojan</a>. Codenamed AppLite Banker by the mobile security company <a href="https://www.tomsguide.com/news/hackers-can-use-this-chrome-extension-to-hijack-your-pc-how-to-stay-safe">Zimperium</a> who first spotted this new campaign, this malware can steal a victim’s PIN in order to remotely take over their smartphone.</p><p>AppLite Banker isn’t done there, though, as the banking trojan specifically targets 172 banking, finance and crypto apps and then uses <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts">overlay attacks</a> to harvest a user’s credentials when they go to log into one of these apps.</p><p>Here’s everything you need to know about the AppLite Banker trojan along with some tips and tricks to help you stay safe from hackers during your next job search.</p><h2 id="impersonating-recruiters-and-hr-reps">Impersonating recruiters and HR reps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YwKRVzwvLwup6hDGh5bVNM" name="RzdqY6hhVUXJjJYEgfCrVe.jpg" alt="A hacker typing quickly on a keyboard" src="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>In a new <a href="https://www.zimperium.com/blog/applite-a-new-antidot-variant-targeting-mobile-employee-devices/" target="_blank">blog post</a>, Zimperium’s zLabs team explains that the hackers behind this campaign pose as recruiters or HR representatives (like we saw with a <a href="https://www.tomsguide.com/computing/malware-adware/hackers-target-job-hunters-with-dangerous-new-windows-backdoor-how-to-stay-safe">similar Windows-based campaign</a> this summer) to lure in potential victims with job offers. To make matters worse, they pretend to be from well-known organizations including Euskatel, Eminic, Distributel, and Oasis and use carefully crafted emails to avoid raising suspicion.</p><p>To get victims to respond to their offers, the hackers also promise them an hourly rate of $25. If a job seeker falls for this initial email, they are led to a malicious landing page where they can continue the application process or schedule an interview. Instead though, this page manipulates them into downloading a CRM or customer relationship management app for Android. While the app itself appears legitimate at first glance, it’s actually a <a href="https://www.tomsguide.com/news/new-android-malware-dropper-sneaks-past-google-protect-yourself-now">malware dropper</a> used to deploy the primary payload onto their device.</p><p>In order to bypass the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a>, this fake app uses a number of obfuscation techniques like manipulating ZIP file structures and Android Manifest files. These methods can often render antivirus apps and other anti-malware tools ineffective which allows the malware to take hold of a vulnerable Android phone.</p><p>When this malicious app is loaded for the first time, it shows an account creation page. After creating an account and logging in, users are then told they need to install an "update" for the app to function properly. However, as you might have guessed, this update is actually the AppLite banking trojan.</p><p>Clicking on the “Update” button within the app shows a fake <a href="https://www.tomsguide.com/news/the-google-play-store-is-making-a-big-change-to-fend-off-malware-heres-how">Google Play Store</a> icon to reassure users before the malware is installed on their phone. As with other Android malware strains, AppLite abuses Android’s <a href="https://www.tomsguide.com/news/android-13-security-feature-designed-to-stop-malware-has-already-been-bypassed">Accessibility Services</a> permissions to grant itself even more permissions but they are also used in the overlay attacks launched by the malware.</p><p>Once installed on one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a>, AppLite can be used by a hacker to launch all sorts of different commands including opening their keyboard, unlocking their device, downloading their text messages, uninstalling apps, sending push notifications and more.</p><h2 id="how-to-stay-safe-from-hackers-during-your-next-job-search">How to stay safe from hackers during your next job search</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ie5A9KWfaaQmUjjzEz2Soh" name="stressed man looking at laptop.jpg" alt="A man looking at his laptop in a stressed and upset manner" src="https://cdn.mos.cms.futurecdn.net/ie5A9KWfaaQmUjjzEz2Soh.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>Just like any other day on the internet, when you’re looking for your next job, you need to be extra careful when it comes to who and what you interact with online.</p><p>In this case, victims should have done their due diligence about the recruiter and why they contacted them out of the blue in the first place. Were they actively looking for a job? Had they submitted their resume on job sites? If not, an email with an offer like this one would definitely seem too good to be true. However, if their job hunt hadn’t gone as planned and they had been looking for a while, they might be more likely to let their guard down and head to the site included in the initial email.</p><p>Still though, if a job requires you to <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps">sideload an app</a> in order to apply for a position, that should be a major red flag. A real business would direct you to their app on the Google Play Store or on the App Store; even then, when was the last time you had to download an app to just apply for a job? I could see if a company made you download Zoom or another popular workplace tool, but one of their own internal apps would be very unlikely.</p><p>When looking for a new job, you'll want to stick to trusted and well-known recruitment sites like Indeed, Monster, ZipRecruiter and others as well as LinkedIn. From there, be wary when you’re told to download files and especially apps. Most job applications and recruitment is done via web portals, so there’s nothing you would need to download in the first place.</p><p>It's worth noting that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> does does protect against known versions of AppLite according to my contact at the search giant. Likewise, you should also consider using of one of the <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html">best identity theft protection services</a> to recover any lost funds or even your identity after a run-in with a campaign like this one.</p><p>Hackers love to go after those who are vulnerable, and people actively looking for a new job after getting laid off or fired certainly fit the bill. This is why it’s up to you to practice good security habits and excellent cyber hygiene and who knows, your ability to <a href="https://www.tomsguide.com/computing/vpns/how-to-spot-a-phishing-scam-and-protect-yourself">spot a phishing email</a> or a scam could give you a leg up over other potential candidates.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/android-phones-under-attack-from-malicious-apps-with-over-8-million-installs-delete-these-now">Android phones under attack from malicious apps with over 8 million installs — delete these now</a></li><li><a href="https://www.tomsguide.com/home/home-security/charging-your-iphone-stay-away-from-third-party-usb-c-cables">Charging your iPhone? You might want to stay away from third-party USB-C cables</a></li><li><a href="https://www.tomsguide.com/computing/online-security/thousands-of-children-exposed-in-major-data-breach-including-names-addresses-and-social-security-numbers">Thousands of children exposed in major data breach — including names, addresses and social security numbers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ I used iVerify’s $1 app to scan my iPhone for the dangerous Pegasus spyware — here's what happened ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-pegasus-spyware-could-be-hiding-on-your-iphone-this-usd1-app-can-find-it</link>
                                                                            <description>
                            <![CDATA[ Spyware is one of the biggest threats for iPhone users but this new app can scan your device to look for any signs of danger. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">U4jmErHcAs2XLFBnPHEqFF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UUZ4kbeqPX434vMEePgxnJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Dec 2024 19:29:52 +0000</pubDate>                                                                                                                                <updated>Sat, 07 Dec 2024 07:16:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UUZ4kbeqPX434vMEePgxnJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The iVerify app running on an iPhone ]]></media:description>                                                            <media:text><![CDATA[The iVerify app running on an iPhone ]]></media:text>
                                <media:title type="plain"><![CDATA[The iVerify app running on an iPhone ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UUZ4kbeqPX434vMEePgxnJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.tomsguide.com/computing/malware-adware/apple-issues-new-spyware-warning-for-iphone-users-in-98-countries-how-to-stay-safe">Pegasus spyware</a> is a dangerous zero-day exploit that requires no action from users in order to compromise one of the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html">best iPhones</a> and expose your personal data. That means that simply receiving an infected iMessage is enough to compromise your device and allow the spyware to access almost all the data on your phone. </p><p>Fortunately though, there's now an easy way for you to tell if you’ve been targeted. For just $1, the <a href="https://apps.apple.com/us/app/iverify-basic/id1466120520" target="_blank">iVerify Basics</a> app lets you scan your iPhone on a monthly basis to check for the Pegasus spyware and analyze the results. </p><p>Since the app launched in May, <a href="https://www.tomsguide.com/phones/google-pixel-phones/google-removes-hidden-pixel-app-that-could-have-left-millions-of-phones-vulnerable-to-malware-spyware-and-other-attacks">iVerify</a> has scanned roughly 2,500 devices and found seven infected ones. The company has also been surprised by who they’ve found carrying these compromised iPhones. </p><p>While the <a href="https://www.tomsguide.com/news/ios-16-getting-extreme-lockdown-mode-what-it-means-for-your-iphone">NSO Group</a>, the company that purchases info on zero-day vulnerabilities from hackers to create its spyware, usually sells Pegasus to governments that target political opponents and journalists, the victims detected by iVerify were business leaders and people in government positions or commercial enterprises.</p><p>Although Apple does attempt to detect when iPhones have been compromised by Pegasus and alert owners about potential spyware infections, the iVerify Basics app provides smartphone owners a free version of their subscription service which they can run on their device once a month.</p><p>Meanwhile, business users are offered continuous scans of the “Mobile Threat Hunting” feature which uses iVerify’s signature-based malware detection, machine learning and heuristics to hunt down anomalies in mobile device operating systems that would indicate signs of spyware or malware infection. </p><h2 id="putting-iverify-to-the-test">Putting iVerify to the test</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KJJgi5UfYyndSvWdA5Ttvk" name="iverify" alt="Screenshots showing the iVerify app scanning an iPhone for spyware" src="https://cdn.mos.cms.futurecdn.net/KJJgi5UfYyndSvWdA5Ttvk.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tom's Guide/iVerify)</span></figcaption></figure><p>Using the iVerify Basics app is straightforward: the app downloads and then shows an introduction screen which explains that it will “provide insight backed by high-end security research along with the knowledge of the latest attacker techniques to help you stay secure.”</p><p>From there I tapped continue to be taken to a Ready to Scan: screen that offers options for Protection Measures or Threat Hunting: the Protection Measures option provides a scan for <a href="https://www.tomsguide.com/computing/online-security/new-darcula-phishing-service-using-imessage-to-target-iphone-users-how-to-stay-safe">SMS phishing</a> and continuous monitoring while the Threat Hunting is where the monthly scan for threats like Pegasus is contained. I ran the New Forensic Scan, which took about ten minutes. Thankfully, I didn’t have to leave the app open or the phone on while it ran.</p><p>When the scan was complete, it told me that my device was secure and that no threats had been detected. It gave me instructions on how to submit my scan results to iVerify for analysis and I provided my email address so I could be contacted if the company found anything suspicious or concerning in the results.</p><p>The entire process was easy to follow, quick and reassuring. It’s also nice that iVerify provides additional layers of security along the bottom of its app with buttons for guides (Protect Against Theft, Protect Wireless Data), Online (Use Security Software which details how to further protect your accounts by using a<a href="https://www.tomsguide.com/news/how-a-password-manager-can-help-you-work-from-home-in-complete-safety" target="_blank"> password manager</a> or using two-step verification), and security news.</p><p>Due to Apple's own malware scanning restrictions, there's no iPhone equivalent for the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps.</a> However, some of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> from <a href="https://www.tomsguide.com/reviews/intego-premium-bundle-x9">Intego</a> does let you scan an iPhone or iPad for malware but the device needs to be connected to a Mac via USB. For just $1 though, the iVerify Basics app is an easy to use and much cheaper alternative.</p><p>Even if you're not a high-profile target, it could be worth downloading this app just for the peace of mind you get after a successful scan with no threats found.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/phones/iphones/dangerous-lightspy-iphone-spyware-can-steal-your-files-location-data-and-messages-how-to-stay-safe">Dangerous LightSpy iPhone spyware can steal your files, location data and messages</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-now-using-corrupted-files-to-bypass-your-antivirus-software-how-to-stay-safe">Hackers are now using corrupted files to bypass your antivirus software — how to stay safe</a></li><li><a href="https://www.tomsguide.com/news/worried-about-spyware-on-your-iphone-ishutdown-can-reveal-if-youve-been-infected">Worried about spyware on your iPhone? iShutdown can reveal if you’ve been infected</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are now using corrupted files to bypass your antivirus software — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-now-using-corrupted-files-to-bypass-your-antivirus-software-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Hackers are now using broken and corrupt files to spread malware since antivirus software struggles to scan them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mCAjzqAdR2v6Swrc26UTUn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Dec 2024 18:38:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker typing quickly on a keyboard]]></media:description>                                                            <media:text><![CDATA[A hacker typing quickly on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker typing quickly on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YwKRVzwvLwup6hDGh5bVNM" name="RzdqY6hhVUXJjJYEgfCrVe.jpg" alt="A hacker typing quickly on a keyboard" src="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Hackers have come up with a clever new way to deliver malware to your Windows PC that both you and even the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> might completely miss.</p><p>As reported by <a href="https://cybernews.com/security/antivirus-blind-spot-corrupted-files-turn-deadly/" target="_blank">Cybernews</a> and first discovered by the threat intelligence services firm ANY.RUN, hackers have started sending out <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing emails</a> which contain broken or corrupt Microsoft Office or ZIP files.</p><p>Since these ‘broken’ or intentionally corrupted files cannot be properly read by antivirus software (and Outlook spam filters too), they bypass any security measures that are in place which results in these emails appearing in a victim’s inbox. Once a victim attempts to recover the corrupted files by executing the corresponding program in recovery mode, the malicious content they contain is able to infect their computer.</p><p>For example, a victim receives a broken .docx document that won’t open in Word, but a prompt appears that asks if they want to recover its contents. If the user presses yes, then Word will reconstruct and process the malicious file which then infects their system. </p><p>In a <a href="https://x.com/anyrun_app/status/1861024182210900357" target="_blank">post on X</a>, ANY.RUN explains that the threat actors are deliberately corrupting these file types to make it more difficult for security tools to detect the malicious content they contain. At the same time though, the apps used in these attacks were chosen specifically as they have built-in recovery mechanisms that the hackers behind this campaign can abuse in their attacks.</p><p>After being provided with the corrupted files, security solutions will assume they need to scan their contents but will fail to extract them. Since they don't find any files inside the archive and overlook the archive itself, the scanning process never really starts.</p><p>This basically means that the attackers are exploiting the recovery mechanisms of popular apps in a way that the corresponding programs, like Word or Outlook, inherently handle these types of files.<br><br>In a <a href="https://app.any.run/tasks/6839e806-56b6-4504-99a4-cc41c9b509df/" target="_blank">separate post on its site</a>, ANY.RUN provides an example of one of the phishing emails used in this campaign which impersonates an HR department email hinting at a potential salary increase. However, it  contains a <a href="https://www.tomsguide.com/news/hackers-are-now-hiding-malicious-word-documents-in-pdfs-how-to-stay-safe">malicious Word document</a> with an additional <a href="https://www.tomsguide.com/news/think-twice-before-scanning-this-qr-code-it-could-be-a-phishing-scam">malicious QR code</a> to open a supposedly secure file which likely leads to a malicious domain. These phishing attacks are similar to those used by <a href="https://www.tomsguide.com/computing/online-security/massive-netflix-scam-is-stealing-account-and-credit-card-info-from-users-in-23-countries"><u>infostealers</u></a> to steal login credentials, credit card details and other sensitive information. </p><h2 id="how-to-stay-safe-from-phishing-attacks">How to stay safe from phishing attacks</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1280px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="J7ewBFPXUpB7ZbDnm7ZrRn" name="Phishing" alt="Hooded cybercriminal sitting with laptop surround by hooks" src="https://cdn.mos.cms.futurecdn.net/J7ewBFPXUpB7ZbDnm7ZrRn.jpg" mos="" align="middle" fullscreen="" width="1280" height="720" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>It should go without saying but don’t click on any email or message from an <a href="https://www.tomsguide.com/news/avoid-these-email-attachments-if-you-dont-want-to-get-phished">unknown sender</a>. When it comes to emails that are supposed to be internal or within your company, know the policies: Would your HR department send you a QR code normally? Check the sender’s email: Is this a regular, known source or person? Is the subject line suspicious, urgent or poorly spelled?</p><p>Also, if you don’t already have one of the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>best antivirus software</u></a> solutions set up and running on your PC, then go ahead and get that handled immediately. Make sure all your devices are protected against malware and threats, even your mobile devices - we have recommendations for the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> too but due to Apple's restrictions, there's no equivalent for the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html">best iPhones</a>. </p><p>Whenever you’re in doubt about an email, you can always contact the sender directly and even ask them to resend an attachment through a secure method or you can manually visit a link using a secure browser. When it comes to this kind of attack, you and your knowledge are the last line of defense. </p><p>Given that malicious attachments are one of the main ways that hackers distribute malware in the first place, don't expect this campaign to die off anytime soon. Instead, you just need to be extra careful when checking your inbox and under no circumstances should you download an attachment from an unknown sender or an email that doesn't pass the smell test.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ I'm a security editor and I just found the best antivirus Cyber Monday deals for up to 85% off ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/black-friday-antivirus-deals-2024</link>
                                                                            <description>
                            <![CDATA[ These Cyber Monday sales on antivirus software will keep all your devices safe throughout the year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Kfbo384rzSLcBA3coTfvrT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MRE9RhjdfJGjaybrkky99-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Nov 2024 21:27:40 +0000</pubDate>                                                                                                                                <updated>Mon, 02 Dec 2024 17:13:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MRE9RhjdfJGjaybrkky99-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a woman security her laptop using antivirus software with a Tom&#039;s Guide Black Friday deals badge]]></media:description>                                                            <media:text><![CDATA[A picture of a woman security her laptop using antivirus software with a Tom&#039;s Guide Black Friday deals badge]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a woman security her laptop using antivirus software with a Tom&#039;s Guide Black Friday deals badge]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MRE9RhjdfJGjaybrkky99-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.tomsguide.com/live/news/black-friday-deals-live-blog-best-sales-right-now">Black Friday</a> deals have turned into <a href="https://www.tomsguide.com/live/news/cyber-monday-deals-live-blog-best-sales-right-now-2024" target="_blank" rel="nofollow">Cyber Monday</a> deals and folks are snapping up everything from TVs to kitchen appliances, and while antivirus software might not be the first (or even the third) thing you think to buy today it absolutely should be. </p><p>Firstly, everyone needs to invest in some strong protection for all their home tech devices and antivirus software is a non-negotiable. You never, ever want to wait until it is too late to realize that you should have protected your home PC or Mac with strong antivirus software. </p><p>Secondly, there are some truly amazing sales going on right now for some of the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> solutions that we've tested and reviewed. The deals listed below are up to 85% off on some of our favorite antivirus security suites and will cover your laptops, desktops, tablets, smartphones and sometimes, all the devices for an entire household. </p><p>It is definitely worth adding antivirus deals to your Cyber Monday shopping list. While you're at it, keep your eyes open for all the other amazing Cyber Monday deals that are going strong from <a href="https://www.tomsguide.com/home/home-security/black-friday-security-camera-deals-2024">home security cameras</a> and<a href="https://www.tomsguide.com/home/home-security/black-friday-video-doorbell-deals-2024"> video doorbells </a>to laptops and accessories. </p><div class="product"><a data-dimension112="c130269d-2b81-4aa3-81bc-e8beabc0f0f8" data-action="Deal Block" data-label="Now through December 4, you can get Norton's antivirus software bundled with identity theft protection for 63% off your first year. Norton 360 includes malware, ransomware and hacking protection along with useful extras like a VPN, password manager, parental controls, dark web monitoring and more. With LifeLock Select Plus, you get Social Security and credit alerts, one bureau credit monitoring and up to $25,000 in stolen funds reimbursement if you have your identity stolen. This deal is a great way to protect your entire digital life at a very affordable price." data-dimension48="Now through December 4, you can get Norton's antivirus software bundled with identity theft protection for 63% off your first year. Norton 360 includes malware, ransomware and hacking protection along with useful extras like a VPN, password manager, parental controls, dark web monitoring and more. With LifeLock Select Plus, you get Social Security and credit alerts, one bureau credit monitoring and up to $25,000 in stolen funds reimbursement if you have your identity stolen. This deal is a great way to protect your entire digital life at a very affordable price." data-dimension25="$69" href="https://us.norton.com/promo/affiliate/norton360deluxe?SID=hawk-custom-tracking&cjid=8900245&clickid=8585b789ab6c11ef81ed0ba40a1cb827&af_sub4=aff&af_sub5=CJ&c=CJ&cjevent=8585b789ab6c11ef81ed0ba40a1cb827" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1695px;"><p class="vanilla-image-block" style="padding-top:89.38%;"><img id="KJkai76tbXckKAdtdhiGHg" name="NortonFull-Vertical-Light-RGB-Web" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/KJkai76tbXckKAdtdhiGHg.png" mos="" align="middle" fullscreen="" width="1695" height="1515" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>Now through December 4, you can get Norton's antivirus software bundled with identity theft protection for 63% off your first year. Norton 360 includes malware, ransomware and hacking protection along with useful extras like a VPN, password manager, parental controls, dark web monitoring and more. With LifeLock Select Plus, you get Social Security and credit alerts, one bureau credit monitoring and up to $25,000 in stolen funds reimbursement if you have your identity stolen. This deal is a great way to protect your entire digital life at a very affordable price.<a class="view-deal button" href="https://us.norton.com/promo/affiliate/norton360deluxe?SID=hawk-custom-tracking&cjid=8900245&clickid=8585b789ab6c11ef81ed0ba40a1cb827&af_sub4=aff&af_sub5=CJ&c=CJ&cjevent=8585b789ab6c11ef81ed0ba40a1cb827" target="_blank" rel="nofollow" data-dimension112="c130269d-2b81-4aa3-81bc-e8beabc0f0f8" data-action="Deal Block" data-label="Now through December 4, you can get Norton's antivirus software bundled with identity theft protection for 63% off your first year. Norton 360 includes malware, ransomware and hacking protection along with useful extras like a VPN, password manager, parental controls, dark web monitoring and more. With LifeLock Select Plus, you get Social Security and credit alerts, one bureau credit monitoring and up to $25,000 in stolen funds reimbursement if you have your identity stolen. This deal is a great way to protect your entire digital life at a very affordable price." data-dimension48="Now through December 4, you can get Norton's antivirus software bundled with identity theft protection for 63% off your first year. Norton 360 includes malware, ransomware and hacking protection along with useful extras like a VPN, password manager, parental controls, dark web monitoring and more. With LifeLock Select Plus, you get Social Security and credit alerts, one bureau credit monitoring and up to $25,000 in stolen funds reimbursement if you have your identity stolen. This deal is a great way to protect your entire digital life at a very affordable price." data-dimension25="$69">View Deal</a></p></div><h3 class="article-body__section" id="section-quick-links"><span>Quick Links</span></h3><ul><li><strong>McAfee Total Protection: </strong><a href="https://www.amazon.com/McAfee-Protection-Exclusive-Monitoring-Subscription/dp/B0BB2N69J8" target="_blank" rel="nofollow"><u><strong>was $99 now $15 @ Amazon</strong></u></a><strong></strong></li><li><strong>Norton 360 Deluxe: </strong><a href="https://www.amazon.com/NEW-Norton-360-Deluxe-Monitoring/dp/B07Q33SJDW" target="_blank" rel="nofollow"><u><strong>was $89 now $19 @ Amazon</strong></u></a><strong></strong></li><li><strong>Malwarebytes Premium: </strong><a href="https://www.amazon.com/Malwarebytes-Amazon-Exclusive-Devices-Android/dp/B084L8X5VV" target="_blank" rel="nofollow"><u><strong>was $40 now $20 @ Amazon</strong></u></a></li><li><strong>ESET Home Security Essential: </strong><a href="https://www.amazon.com/ESET-Multi-Device-Internet-Antivirus-Protection/dp/B08X2L57CT/" target="_blank" rel="nofollow"><strong>was $60 now $27 @ Amazon</strong></a></li><li><strong>Webroot Internet Security Complete: </strong><a href="https://www.amazon.com/Webroot-Internet-Antivirus-Protection-Subscription/dp/B07DDJRW7Y?th=1" target="_blank" rel="nofollow"><u><strong>was $99 now $20 @ Amazon</strong></u></a><strong></strong></li><li><strong>Bitdefender Total Security: </strong><a href="https://www.amazon.com/Bitdefender-Total-Security-Download-Online/dp/B07CYFFH4H" target="_blank" rel="nofollow"><u><strong>was $89 now $45 @ Amazon</strong></u></a></li></ul><h3 class="article-body__section" id="section-best-cyber-monday-antivirus-deals"><span>Best Cyber Monday antivirus deals</span></h3><div class="product"><a data-dimension112="1b63772c-7c11-4db4-ac0a-85facd77ca3d" data-action="Deal Block" data-label="McAfee" data-dimension48="McAfee" data-dimension25="$15" href="https://www.amazon.com/McAfee-Protection-Exclusive-Monitoring-Subscription/dp/B0BB2N69J8?th=1" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1500px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="QJvAMGQZdjrfvRhwxwcnqQ" name="71sgomvLdfL._AC_SL1500_" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/QJvAMGQZdjrfvRhwxwcnqQ.jpg" mos="" align="middle" fullscreen="" width="1500" height="1500" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.tomsguide.com/computing/online-security/mcafee-antivirus-review" data-dimension112="1b63772c-7c11-4db4-ac0a-85facd77ca3d" data-action="Deal Block" data-label="McAfee" data-dimension48="McAfee" data-dimension25="$15">McAfee</a> offers an easy to use interface, and sets itself apart by providing a security suite that doesn't require a lot of effort or extra thought. In addition to the antivirus protection, McAfee provides a password manager, parental controls, 24/7 phone support, a VPN, a firewall, credit bureau monitoring and a file shredder. However, it does lack a hardened browser and a ransomware rollback. <a class="view-deal button" href="https://www.amazon.com/McAfee-Protection-Exclusive-Monitoring-Subscription/dp/B0BB2N69J8?th=1" target="_blank" rel="nofollow" data-dimension112="1b63772c-7c11-4db4-ac0a-85facd77ca3d" data-action="Deal Block" data-label="McAfee" data-dimension48="McAfee" data-dimension25="$15">View Deal</a></p></div><div class="product"><a data-dimension112="f2fe173f-29fc-4e0c-b2d4-f53e3a7a4ddd" data-action="Deal Block" data-label="reviewed" data-dimension48="reviewed" data-dimension25="$20" href="https://www.amazon.com/NEW-Norton-360-Deluxe-Monitoring/dp/B07Q33SJDW?th=1" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="Qh4xd6zGLsLhTc4aNti8DJ" name="61+wn4LJx3L._AC_SL1000_" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/Qh4xd6zGLsLhTc4aNti8DJ.jpg" mos="" align="middle" fullscreen="" width="1000" height="1000" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>We've called Norton "almost everything you could want" in a security suite - and from malware protection, a VPN, a firewall, parental controls, password manager, hardened browser, and ransomware rollback this package includes almost everything you can shake a malicious stick at (except a file shredder or file encryption). When we <a href="https://www.tomsguide.com/reviews/norton" data-dimension112="f2fe173f-29fc-4e0c-b2d4-f53e3a7a4ddd" data-action="Deal Block" data-label="reviewed" data-dimension48="reviewed" data-dimension25="$20">reviewed</a> it, our only drawbacks were the false positives and the price - which given the current Cyber Monday sale, is not an issue for the time being. <a class="view-deal button" href="https://www.amazon.com/NEW-Norton-360-Deluxe-Monitoring/dp/B07Q33SJDW?th=1" target="_blank" rel="nofollow" data-dimension112="f2fe173f-29fc-4e0c-b2d4-f53e3a7a4ddd" data-action="Deal Block" data-label="reviewed" data-dimension48="reviewed" data-dimension25="$20">View Deal</a></p></div><div class="product"><a data-dimension112="a30b56dd-86ad-451e-b9bf-17bfe6ecd77c" data-action="Deal Block" data-label="testing" data-dimension48="testing" data-dimension25="$19.5" href="https://www.amazon.com/Malwarebytes-Amazon-Exclusive-Devices-Android/dp/B084L8X5VV?th=1" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1050px;"><p class="vanilla-image-block" style="padding-top:95.24%;"><img id="C4uQB4HCHcceWw3h74FM9Z" name="51ar4vgTBCL._AC_SL1060_" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/C4uQB4HCHcceWw3h74FM9Z.jpg" mos="" align="middle" fullscreen="" width="1050" height="1000" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>Malwarebytes puts a focus on, of course, malware as well as online identity security but leaves out some of the other features like password manager, parental controls, a hardened browser and a firewall.  It does include a VPN however. During <a href="https://www.tomsguide.com/reviews/malwarebytes-premium-privacy-for-mac" data-dimension112="a30b56dd-86ad-451e-b9bf-17bfe6ecd77c" data-action="Deal Block" data-label="testing" data-dimension48="testing" data-dimension25="$19.5">testing</a> we found it to be very fast while scanning for malicious files, we also found that it was quick because it really only worked at the folder, not file, level. Overall, we found the defenses here were a more rudimentary approach.  <a class="view-deal button" href="https://www.amazon.com/Malwarebytes-Amazon-Exclusive-Devices-Android/dp/B084L8X5VV?th=1" target="_blank" rel="nofollow" data-dimension112="a30b56dd-86ad-451e-b9bf-17bfe6ecd77c" data-action="Deal Block" data-label="testing" data-dimension48="testing" data-dimension25="$19.5">View Deal</a></p></div><div class="product"><a data-dimension112="9e124fcc-6530-4bae-a52e-5aad94738b60" data-action="Deal Block" data-label="reviewed ESET products" data-dimension48="reviewed ESET products" data-dimension25="$27" href="https://www.amazon.com/ESET-Multi-Device-Internet-Antivirus-Protection/dp/B08X2L57CT/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:133.30%;"><img id="7EJ69BSSx3cYBxapNiLqg8" name="614viPJ9G6L._AC_SL1333_" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/7EJ69BSSx3cYBxapNiLqg8.jpg" mos="" align="middle" fullscreen="" width="1000" height="1333" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>ESET's 2024 Home Security Essential package offers protection for up to three devices and includes  browser security, a gamer mode, and webcam protection which monitors for attempts to use your webcam. When we've <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html#section-the-best-antivirus-software-for-performance" data-dimension112="9e124fcc-6530-4bae-a52e-5aad94738b60" data-action="Deal Block" data-label="reviewed ESET products" data-dimension48="reviewed ESET products" data-dimension25="$27">reviewed ESET products</a> in the past, we liked how little impact they've had on performance and that the suite's Ransomware Shield relies on advanced heuristic monitoring that aims to block threats before they can do damage to your PC.  <a class="view-deal button" href="https://www.amazon.com/ESET-Multi-Device-Internet-Antivirus-Protection/dp/B08X2L57CT/" target="_blank" rel="nofollow" data-dimension112="9e124fcc-6530-4bae-a52e-5aad94738b60" data-action="Deal Block" data-label="reviewed ESET products" data-dimension48="reviewed ESET products" data-dimension25="$27">View Deal</a></p></div><div class="product"><a data-dimension112="af986d3b-532d-41c9-8514-e4724972308b" data-action="Deal Block" data-label="Like the others on this list, Webroot will protect your system from malware, provide identity theft protection and anti-phishing measures, and has secure password management from LastPass. This version is compatible with Windows, macOS, iOS and Android but has security measures specifically designed for Chromebooks, as well as a system maintenance tool that improves performance and clears hard drive space by deleting cookies and clearing the cache. However, as we have not yet tested it we cannot vouch for its efficacy." data-dimension48="Like the others on this list, Webroot will protect your system from malware, provide identity theft protection and anti-phishing measures, and has secure password management from LastPass. This version is compatible with Windows, macOS, iOS and Android but has security measures specifically designed for Chromebooks, as well as a system maintenance tool that improves performance and clears hard drive space by deleting cookies and clearing the cache. However, as we have not yet tested it we cannot vouch for its efficacy." data-dimension25="$20" href="https://www.amazon.com/Webroot-Internet-Antivirus-Protection-Subscription/dp/B07DDJRW7Y?th=1" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1257px;"><p class="vanilla-image-block" style="padding-top:119.33%;"><img id="jgFVZ2H8EXbr4JiawN7NJi" name="71usJ80hjZL._AC_SL1500_" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/jgFVZ2H8EXbr4JiawN7NJi.jpg" mos="" align="middle" fullscreen="" width="1257" height="1500" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>Like the others on this list, Webroot will protect your system from malware, provide identity theft protection and anti-phishing measures, and has secure password management from LastPass. This version is compatible with Windows, macOS, iOS and Android but has security measures specifically designed for Chromebooks, as well as a system maintenance tool that improves performance and clears hard drive space by deleting cookies and clearing the cache. However, as we have not yet tested it we cannot vouch for its efficacy. <a class="view-deal button" href="https://www.amazon.com/Webroot-Internet-Antivirus-Protection-Subscription/dp/B07DDJRW7Y?th=1" target="_blank" rel="nofollow" data-dimension112="af986d3b-532d-41c9-8514-e4724972308b" data-action="Deal Block" data-label="Like the others on this list, Webroot will protect your system from malware, provide identity theft protection and anti-phishing measures, and has secure password management from LastPass. This version is compatible with Windows, macOS, iOS and Android but has security measures specifically designed for Chromebooks, as well as a system maintenance tool that improves performance and clears hard drive space by deleting cookies and clearing the cache. However, as we have not yet tested it we cannot vouch for its efficacy." data-dimension48="Like the others on this list, Webroot will protect your system from malware, provide identity theft protection and anti-phishing measures, and has secure password management from LastPass. This version is compatible with Windows, macOS, iOS and Android but has security measures specifically designed for Chromebooks, as well as a system maintenance tool that improves performance and clears hard drive space by deleting cookies and clearing the cache. However, as we have not yet tested it we cannot vouch for its efficacy." data-dimension25="$20">View Deal</a></p></div><div class="product"><a data-dimension112="056fae82-e6e8-44dc-8bfd-f6c6d9b5c478" data-action="Deal Block" data-label="best overall antivirus software" data-dimension48="best overall antivirus software" data-dimension25="$45" href="https://www.amazon.com/Bitdefender-Total-Security-Download-Online/dp/B07CYFFH4H?th=1" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1056px;"><p class="vanilla-image-block" style="padding-top:142.05%;"><img id="MRZJwgfznrr3KGixixQKW8" name="714clBtOSiL._AC_SL1500_" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/MRZJwgfznrr3KGixixQKW8.jpg" mos="" align="middle" fullscreen="" width="1056" height="1500" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>Bitdefender has earned our <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html#section-the-best-antivirus-software-for-families" data-dimension112="056fae82-e6e8-44dc-8bfd-f6c6d9b5c478" data-action="Deal Block" data-label="best overall antivirus software" data-dimension48="best overall antivirus software" data-dimension25="$45">best overall antivirus software </a>spot for its excellent antivirus protection paired with its fantastic feature set. Not only does it include as complete security as you could expect from both existing and new threats, but it also throws in all the extras you can list off: VPN, firewall, parental controls, password manager, ransomware rollback, a Wi-Fi scanner and a hardened browser. During<a href="https://www.tomsguide.com/reviews/bitdefender"> testing</a>, we found it could bog down a system a bit and the only other drawback was the price - which you can sidestep right now during the Cyber Monday sale. <a class="view-deal button" href="https://www.amazon.com/Bitdefender-Total-Security-Download-Online/dp/B07CYFFH4H?th=1" target="_blank" rel="nofollow" data-dimension112="056fae82-e6e8-44dc-8bfd-f6c6d9b5c478" data-action="Deal Block" data-label="best overall antivirus software" data-dimension48="best overall antivirus software" data-dimension25="$45">View Deal</a></p></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This popular Windows utility for ZIP files has a dangerous vulnerability ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-popular-windows-utility-for-zip-files-has-a-dangerous-vulnerability</link>
                                                                            <description>
                            <![CDATA[ Windows now lets you extract ZIP files right from File Explorer but if you're still using 7-Zip to do so, you need to update the app immediately. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eC2He7fPZFWgKiMXpCu2RM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 22 Nov 2024 22:51:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Early versions of <a href="https://www.tomsguide.com/computing/macbooks/i-review-laptops-for-a-living-and-i-install-these-7-apps-on-every-windows-11-pc#section-7-zip">7-Zip</a>, a file compression program, are affected by a security flaw with a severity score of 7.8 out of 10. </p><p>Disclosed by <a href="https://www.zerodayinitiative.com/advisories/ZDI-24-1532/" target="_blank">Trend Micro’s Zero Day Initiative</a> and first discovered by Trend Micro Security researcher Nicholas Zubrisky back in June of this year, the flaw affects all 7-Zip versions prior to 24.07 and allows attackers to execute code on a victim’s machine. </p><p>An easy exploit, the threat actors could use any of several attack vectors to exploit a specific flaw in the implementation of the program's Zstandard decompression. The ZDI advisory goes on to explain that the proper validation of user-supplied data can then be leveraged to execute code in the context of the current process. </p><p>Basically, this means that although it would likely require victim interaction such as opening a file, the archives could be used to install malware on your PC.</p><p>The current version of 7-Zip is 24.08, released on June 19, 2024. However, as the program doesn’t have automatic updates, the app itself and subsequent updates need to be manually installed to protect users. </p><h2 id="how-to-stay-safe-4">How to stay safe</h2><p>So, if you are running 7-Zip and especially a version earlier than 24.07, make sure to manually install the latest update immediately to avoid falling victim to any cyberattacks leveraging these flaws.</p><p>As always though, never open any files you didn't ask for, don’t open them when you don't recognize the sender and when you're not sure what they are. To protect yourself further, make sure you’re using the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>best antivirus software</u></a> to keep your Windows PC safe from the latest threats.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/expressvpn-steps-up-its-game-with-new-credit-scanner-tool">ExpressVPN steps up its game with new Credit Scanner tool</a></li><li><a href="https://www.tomsguide.com/computing/online-security/is-vpn-by-google-coming-to-pixel-tablet">Is VPN by Google coming to Pixel Tablet?</a></li><li><a href="https://www.tomsguide.com/computing/online-security/microsoft-is-changing-the-way-admin-privileges-work-in-windows-heres-why">Microsoft is changing the way admin privileges work in Windows - here's why</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ iOS 18.1.1 is live with critical security fixes — update your iPhone right now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/ios-18-1-1-is-live-with-critical-security-fixes-update-your-iphone-right-now</link>
                                                                            <description>
                            <![CDATA[ Apple has released updates for iOS and iPadOS to address two critical vulnerabilities that could be exploited by hackers if left unpatched. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">d4uwtqQYETXsY84GcZes23</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/63eKCb5gRgyofxfaq6Nfc4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Nov 2024 22:25:49 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/63eKCb5gRgyofxfaq6Nfc4-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Apple iPhone 16 held in the hand.]]></media:description>                                                            <media:text><![CDATA[Apple iPhone 16 held in the hand.]]></media:text>
                                <media:title type="plain"><![CDATA[Apple iPhone 16 held in the hand.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/63eKCb5gRgyofxfaq6Nfc4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Three months after their launch back in September of this year, Apple has released a new <a href="https://support.apple.com/en-us/121752" target="_blank">iOS 18.1.1 and iPadOS 18.1.1 </a>update that includes some minor changes as well as some important security fixes. </p><p>The two security fixes concern issues with JavaScriptCore (tracked as CVE-2024-44308) and WebKit (tracked as CVE-2024-44309). The JavaScriptCore threat involved processing maliciously crafted web content that could lead to <a href="https://www.tomsguide.com/ai/apple-intelligence/apple-will-pay-up-to-usd1-million-to-anyone-who-finds-a-privacy-flaw-inside-apple-intelligence">arbitrary code execution</a> and was mainly found on Intel-based Mac systems. It was solved by improved checks. </p><p>Similarly, the Webkit fix used maliciously crafted web content to carry out <a href="https://www.tomsguide.com/phones/iphones/ios-18-fixes-urgent-security-flaws-for-millions-update-your-iphone-right-now">cross site scripting attacks</a> and also exploited Intel-based Mac systems. The security fix on iOS 18.1.1 and iPadOS 18.1.1 solved this by fixing a cookie management issue with improved state management.  </p><p>Recommended for everyone using one of the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html">best iPhones</a>, the fixes come three weeks after the launch of iOS 18.1 which mainly focused on <a href="https://www.tomsguide.com/ai/apple-intelligence-unveiled-all-the-new-ai-features-coming-to-ios-18-ipados-18-and-macos-sequoia">Apple Intelligence</a> features. </p><h2 id="how-to-protect-an-ios-or-ipados-device">How to protect an iOS or iPadOS device</h2><p>Though Apple's own rules prohibiting malware scanning apps mean there isn't an iOS or iPadOS equivalent of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a>, it doesn't mean you're out of options entirely. </p><p>Either <a href="https://www.tomsguide.com/reviews/intego-mac-internet-security-x9">Intego Mac Internet Security X9</a> or <a href="https://www.tomsguide.com/reviews/intego-premium-bundle-x9">Intego Mac Premium Bundle X9</a> can be used to scan your Apple devices for malware, and both are considered some of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> solutions you can get right now. They can scan an iPhone or an iPad for malware, but either device will have to be connected to a Mac via a USB cable. </p><p>If you want an extra layer of protection for your Apple devices and the sensitive data they contain, it's worth signing up for either product. </p><p>Regardless though, the most important thing you can do to keep your iPhone or iPad safe from hackers is to install the latest updates as soon as they become available. I know installing updates can be time consuming as well as slightly annoying but hackers love to prey on people running outdated software. By keeping your devices updated regularly, you will be much less likely to fall victim to one of their attacks.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/microsoft-is-changing-the-way-admin-privileges-work-in-windows-heres-why">Microsoft is changing the way admin privileges work in Windows — here’s why</a></li><li><a href="https://www.tomsguide.com/computing/online-security/123456-is-the-worlds-most-popular-password-again">123456 is the world's most popular password – again</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/this-fake-ai-image-generator-is-pushing-info-stealing-malware-onto-macs-and-pcs">This fake AI image generator is pushing info-stealing malware onto Macs and PCs</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This fake AI image generator is pushing info-stealing malware onto Macs and PCs ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-fake-ai-image-generator-is-pushing-info-stealing-malware-onto-macs-and-pcs</link>
                                                                            <description>
                            <![CDATA[ Hackers are using AI tools as a lure in their attacks and downloading this fake AI image generator will leave your PC or Mac with a nasty malware infection. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HZ4GVS5KXHzixBm9Np9r9Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Nov 2024 23:21:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Threat actors have been using links to fake AI image and video generators to steal login credentials and browsing history from infected Windows PCs and Macs</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/fake-ai-video-generators-infect-windows-macos-with-infostealers/" target="_blank">BleepingComputer</a> and first discovered by cybersecurity researcher <a href="https://x.com/g0njxa/status/1857485682299519034" target="_blank">gonjxa</a> on X, these fake apps are being spread through both search results and ads on the social media platform showing political deepfakes. The <a href="https://www.tomsguide.com/computing/malware-adware/that-innocent-looking-calendar-invite-could-infect-your-mac-with-malware-dont-fall-for-this">malicious links</a> they contain lead to very professional appearing websites purporting to be for the fake AI image and video editing software application EditProAi. </p><p>Though it feels legitimate and even looks so at first glance, the download link for this fake AI app actually contains malware, namely the Windows variant of <a href="https://www.tomsguide.com/news/chatgpt-is-now-being-used-by-hackers-to-spread-dangerous-malware-dont-fall-for-this">Lumma Stealer</a> on PC and the macOS version of <a href="https://www.tomsguide.com/computing/online-security/hackers-are-using-fake-google-meet-errors-to-infect-pcs-and-macs-with-malware-dont-fall-for-this">AMOS</a> on Apple computers.</p><p>The malware itself attacks Chromium-based browsers to steal credentials, passwords, credit cards, cookies and browsing history, as well as cryptocurrency. Google Chrome, Microsoft Edge, Mozilla Firefox, Opera and Samsung Internet are all among the affected browsers. </p><p>Data is then archived and sent back to the attackers where it can be sold on the <a href="https://www.tomsguide.com/news/hackers-have-earned-millions-selling-your-data-on-the-dark-web-how-to-stay-safe">dark web</a> or used in further attacks. The PC malware used in this campaign leverages a stolen code signing certificate from the freeware utility developer Softwareok.com to help it bypass Microsoft's built-in defenses. <br><br>If you’ve downloaded and installed this program, all of your authentications, saved passwords and crypto wallets should be considered compromised. Every site you visited after installing it should have its password reset with a <a href="https://www.tomsguide.com/opinion/im-a-security-editor-and-this-is-how-i-create-strong-passwords-that-are-also-easy-to-remember">strong, unique password</a>. Likewise, any online banking or  email services you visited with it installed on your computer need to be secured by using <a href="https://www.tomsguide.com/computing/online-security/how-to-set-up-two-factor-authentication-for-your-microsoft-account">2FA </a>or multi-factor authentication if you haven't done so already. </p><h2 id="how-to-stay-safe-from-malware">How to stay safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="Re2sDX92s3QG6dFsFnyrX6" name="6KXS4iqE4rw2D8SCHP62JF.jpg" alt="A woman looking at a smartphone while using a laptop" src="https://cdn.mos.cms.futurecdn.net/Re2sDX92s3QG6dFsFnyrX6.jpg" mos="" align="middle" fullscreen="" width="1000" height="562" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>It’s been said before but it bears repeating: you can never be too safe online. Whether it’s a new game or an AI image generator, if something seems too good to be true, it almost certainly is. That’s why you want to stick with known sites, services and in this case, AI tools like the ones on our list of the <a href="https://www.tomsguide.com/best-picks/best-ai-image-generators">best AI image generators</a>. </p><p>You also obviously will want to have strong protection against viruses on your Mac or PC, so make sure you have the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> on your PC and the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> on your Apple computer. This ensures that malware is detected and blocked from infecting your machine which prevents your sensitive personal and financial data from being stolen by hackers in the first place. </p><p>At the same time, you want to stick to known sites and services with a good reputation and background, when in doubt, use Google or another reputable search engine for background information and reviews. And for the love of Dolly Parton, don’t just click on any link from social media or share your personal info all over the internet. If you do, you're just asking for trouble and you could even end up becoming a victim of <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html">identity theft</a>.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/1-5-million-americans-hit-in-massive-debt-relief-service-data-breach-names-addresses-ssns-and-more-exposed">1.5 million Americans hit in massive debt relief service data breach — names, addresses, SSNs and more exposed</a></li><li><a href="https://www.tomsguide.com/computing/online-security/us-confirms-chinese-hacker-group-salt-typhoon-behind-several-telecom-breaches-what-you-need-to-know">US confirms Chinese hacker group Salt Typhoon behind several telecom breaches</a></li><li><a href="https://www.tomsguide.com/computing/online-security/temu-exploded-out-of-nowhere-to-become-a-mega-online-store-but-should-you-trust-it">Temu exploded out of nowhere to become a mega online store — but should you trust it?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This nasty Android trojan is hijacking calls to your bank and sending them to hackers — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-nasty-android-trojan-is-hijacking-calls-to-your-bank-and-sending-them-to-hackers-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ The FakeCall banking trojan is back with new capabilities and now it can redirect calls to your bank directly to hackers to steal your financial info. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fNne9rakerSzGSUYwK2gvc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Oct 2024 23:07:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:description>                                                            <media:text><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Imagine making a call to your bank after discovering fraudulent activity on one of your accounts, only for the person on the other end of the phone to be a hacker. Well, that is exactly what’s happening to victims of this updated <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-banking-trojan-uses-fake-google-play-updates-to-take-over-your-phone-how-to-stay-safe"><u>Android banking trojan</u></a>.<br><br>As reported by <a href="https://www.bleepingcomputer.com/news/security/android-malware-fakecall-now-reroutes-bank-calls-to-attackers/" target="_blank"><u>BleepingComputer</u></a>, a new version of the FakeCall trojan is currently making the rounds online. First discovered by the cybersecurity firm Kaspersky back in 2022, this malware uses <a href="https://www.tomsguide.com/news/this-new-phishing-scam-can-steal-your-social-security-number-how-to-stay-safe">voice phishing</a> <a href="https://www.tomsguide.com/news/this-new-phishing-scam-can-steal-your-social-security-number-how-to-stay-safe"><u></u></a>(or vishing), <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts"><u>overlay attacks</u></a> and other tricks to convince victims they’re actually on a call with someone from their bank.</p><p>Late last year, CheckPoint released its <a href="https://research.checkpoint.com/2023/south-korean-android-banking-menace-fakecalls/"><u>own report</u></a> warning that FakeCall had gained the ability to impersonate more than 20 different financial organizations. Since then though, its capabilities have grown even stronger and now, the malware is able to hijack both incoming and outgoing calls made from the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a>.</p><p>Here’s everything you need to know about this banking trojan, along with some tips and tricks to help you stay safe from hackers and the malware they use in their attacks.</p><h2 id="hijacking-outgoing-and-incoming-calls">Hijacking outgoing and incoming calls</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jooLQTGPeDLH8jBwTuAjXe" name="stressed-woman-phone-shutterstock.jpg" alt="A nervous woman looking at her phone" src="https://cdn.mos.cms.futurecdn.net/jooLQTGPeDLH8jBwTuAjXe.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Just like most other banking trojans, FakeCall is spread through <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now"><u>malicious apps</u></a> which are usually <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps"><u>sideloaded</u></a> onto a victim’s phone. Previous versions of the trojan had users call their bank from within one of these bad apps and from there, hackers impersonated a bank employee while a fake overlay displayed their bank’s number during the call to prevent them from catching on.<br><br>Now though, this new version of FakeCall analyzed by cybersecurity researchers at Zimperium uses a new trick to appear even more convincing. Instead of an overlay on top of a legitimate app, the malicious app used to spread this malware sets itself as a phone’s default call handler. This is done by abusing <a href="https://www.tomsguide.com/news/look-out-this-android-malware-can-take-over-your-banking-and-crypto-accounts"><u>Android’s accessibility services</u></a> and after installation, victims are prompted to approve this.</p><p>With full control of an Android phone’s call handler, the hackers behind this campaign are able to hijack both incoming and outgoing calls. To make this appear more legitimate, a fake call interface that copies the real Android dialer is used which displays the names and info of a victim’s most frequent contacts.</p><p>If a victim goes to call their bank or other financial institution, FakeCall hijacks their call and redirects it to a hacker-controlled phone number. While the victim believes they're speaking with a bank employee who may ask for some sensitive information over the phone, they’re actually speaking with a hacker who is recording everything they say to use in subsequent attacks or even to commit fraud.</p><p>In addition to this new feature, this latest version of FakeCall has some other upgrades as well. These include the ability to live stream what’s on their screen, taking screenshots on an infected device, unlocking a phone to temporarily turn off auto-lock and more. Since so many new features have been added to this malware, it’s clear that it is currently under active development and that its creators are making it more powerful with each subsequent release.</p><p>In its <a href="https://www.zimperium.com/blog/mishing-in-motion-uncovering-the-evolving-functionality-of-fakecall-malware/"><u>report</u></a>, Zimperium provides more details on this banking trojan and explains that it identified 13 malicious apps used to spread FakeCall. However, instead of their names, the firm has only released <a href="https://github.com/Zimperium/IOC/tree/master/2024-10-FakeCall"><u>indicators of compromise</u></a> (IoC) on GitHub. I'll try to get the full list of app names and will update this piece if I do so.</p><h2 id="how-to-stay-safe-from-android-malware-2">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Just like with a lot of other Android malware, the easiest way to avoid having your phone infected with the FakeCall banking trojan is to not sideload apps. While installing apps this way may be convenient, you’re putting yourself at additional risk since these apps don’t go through the same rigorous security checks that ones on official app stores like the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know"><u>Google Play Store</u></a>, Samsung Galaxy Store and the Amazon App Store do.</p><p>When in doubt, don’t install any apps as APK files on your phone. Instead, go to an official app store and search for the app you want to use by name. Google and other search engines are often used by hackers to host malicious ads, so it’s always better to navigate directly to an app store and search for new apps yourself. Likewise, you also want to limit the number of apps on your phone as even <a href="https://www.tomsguide.com/news/popular-android-screen-recorder-app-went-from-legitimate-to-malicious-overnight-what-you-need-to-know"><u>good apps can go bad</u></a>.</p><p>In order to stay protected from malware and other online threats, you want to ensure that Google Play Protect is enabled on your device. This built-in security app scans all of the new apps you download and the existing ones on your smartphone for malware. For additional protection though, you might also want to consider using one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside Google Play Protect.</p><p>As long as there are apps, hackers are going to find a way to abuse them in their attacks. However, if you avoid sideloading new apps and don’t give the apps you do install access to permissions they don’t need, you should be safe from hackers. At the same time, it’s always a good idea to <a href="https://www.tomsguide.com/phones/nsa-issues-warning-to-iphone-and-android-users-do-this-to-stop-hackers"><u>periodically restart your device</u></a> to prevent hackers from using zero-click exploits to infect your phone with malware.</p><p>Since FakeCall is currently in active development, this likely isn’t the last time that we’ll hear about this banking trojan being used in cyberattacks.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/news/that-emergency-phone-call-from-a-loved-one-could-actually-be-scammers-using-ai-how-to-stay-safe">That emergency phone call from a loved one could actually be scammers using AI</a></li><li><a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">These are the best antivirus software solutions for your PC</a></li><li><a href="https://www.tomsguide.com/computing/online-security/800-000-people-just-had-their-full-names-ssns-and-more-exposed-in-a-massive-insurance-admin-company-data-breach">800,000 people just had their full names, SSNs and more exposed in massive data breach</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Android banking trojan uses a fake lock screen to steal your PIN and your cash — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-banking-trojan-now-shows-a-fake-lock-screen-to-steal-your-pin-and-your-cash-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ The TrickMo banking trojan is back with upgraded capabilities that make it easier for hackers to use it to commit on-device fraud from vulnerable Android phones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wTgvpT3PEbskMDLNP2SfGH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FP9vpJQzmJU8GP2ZFHpc8K-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Oct 2024 10:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Oct 2024 15:23:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FP9vpJQzmJU8GP2ZFHpc8K-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[banking trojan on phone illustration]]></media:description>                                                            <media:text><![CDATA[banking trojan on phone illustration]]></media:text>
                                <media:title type="plain"><![CDATA[banking trojan on phone illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FP9vpJQzmJU8GP2ZFHpc8K-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Just like with apps you use on your phone, <a href="https://www.tomsguide.com/computing/malware-adware/new-android-malware-drains-your-bank-accounts-and-completely-wipes-your-device-how-to-stay-safe"><u>mobile malware</u></a> is always improving. Case in point, forty new variants of the TrickMo banking trojan have been spotted in the wild and some can even steal the PIN or unlock pattern from your Android phone.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/trickmo-malware-steals-android-pins-using-fake-lock-screen/" target="_blank" rel="nofollow"><u>BleepingComputer</u></a>, the cybersecurity firm Zimperium has identified dozens of new TrickMo variants that are linked to 16 <a href="https://www.tomsguide.com/news/new-android-malware-dropper-sneaks-past-google-protect-yourself-now"><u>malware droppers</u></a> and use 22 different command and control (<a href="https://www.tomsguide.com/news/move-over-joker-harly-malware-infects-millions-of-android-phones"><u>C&C</u></a>) infrastructures to steal your data and your hard-earned cash.</p><p>First discovered by IBM’s X-Force cybersecurity division back in 2020 though it’s likely been used to target the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a> since 2019, TrickMo has now been upgraded with new capabilities that make it even more dangerous. These include one-time password (OTP) interception, screen recording, data exfiltration, automatic permission granting, the ability to launch overlay attacks and more.</p><p>What’s particularly concerning about these new TrickMo variants though is their ability to steal an Android phone’s PIN or unlock pattern. With this info in hand, hackers can wait until a device is idle — like when you’re sleeping — to perform on-device fraud.</p><p>Here’s everything you need to know about the TrickMo banking trojan along with some tips on how you can keep your Android phone and other devices safe from malware.</p><h2 id="harvesting-pins-and-unlock-patterns"> Harvesting PINs and unlock patterns  </h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="x7wbRnmfyDuUdspQCbvhTY" name="TG_Android lock screen.jpg" alt="Android lock screen vulnerability" src="https://cdn.mos.cms.futurecdn.net/x7wbRnmfyDuUdspQCbvhTY.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>As TrickMo is a banking trojan after all, it uses fake login screens — like the ones used in <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts"><u>overlay attacks</u></a> — to harvest usernames and passwords from unsuspecting Android users. You might think you’re logging into a banking app when really, you’re giving your credentials to hackers.</p><p>One of the ways in which TrickMo accomplishes this is by abusing Android’s <a href="https://www.tomsguide.com/news/this-new-android-malware-can-unlock-your-phone-and-drain-your-bank-accounts-how-to-stay-safe"><u>Accessibility services</u></a> to grant itself access to additional permissions. However, it  also has the ability to tap on prompts automatically when they pop up on your phone.</p><p>In its <a href="https://www.zimperium.com/blog/expanding-the-investigation-deep-dive-into-latest-trickmo-samples/" target="_blank"><u>report</u></a> on the matter, Zimperium explains that these upgraded versions of TrickMo can mimic the unlock prompts you see on your Android phone when you turn on its screen. These are actually HTML pages hosted on an external website which are displayed in full-screen mode on an infected device. This makes them look legitimate and as we haven’t seen this type of attack in the past, you could see how someone could easily fall for it.</p><p>Once a PIN or unlock pattern is harvested by the hackers using TrickMo in their attacks, this info along with a <a href="https://www.tomsguide.com/news/these-popular-travel-apps-could-put-your-summer-vacation-plans-at-risk"><u>unique device identifier</u></a> is written as a PHP script that gets sent back to them. From there, they can unlock your phone remotely whenever they want and perform additional attacks or on-device fraud.</p><p>As it stands now, Zimperium has identified TrickMo victims in Canada, the United Arab Emirates, Turkey and Germany. However, a sophisticated banking trojan like this could easily be reconfigured to target Android users in the U.S., the U.K. and in other countries around the world.</p><h2 id="how-to-stay-safe-from-android-malware-3"> How to stay safe from Android malware  </h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>These new TrickMo variants are currently being spread through <a href="https://www.tomsguide.com/reference/what-are-phishing-scams"><u>phishing attacks</u></a>. As such, you want to be careful when checking your email, messages or downloading new apps from unofficial sources.</p><p>For instance, if you get an <a href="https://www.tomsguide.com/news/avoid-these-email-attachments-if-you-dont-want-to-get-phished"><u>email from an unknown sender</u></a>, you want to avoid clicking on any links or downloading any attachments it may contain. The same goes for text messages and messages on social media.</p><p>Fortunately, <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> — which comes pre-installed on most Android phones — is able to identify and block known variants of TrickMo. To stay safe, you want to make sure that this free security app is enabled and running on your Android phone. However, for additional protection, you may also want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside it.</p><p>Hackers are constantly looking for unique and clever new ways to gain access to our smartphones given how much personal and financial information they contain. For this reason, you want to be extra careful online and use a discerning eye when checking your email, messages or downloading new apps.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/this-nasty-android-adware-is-making-phones-unusable-how-to-stay-safe">This nasty Android adware is making phones unusable</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/11-million-android-users-infected-with-dangerous-necro-trojan-how-to-stay-safe">11 million Android users infected with dangerous Necro trojan</a></li><li><a href="https://www.tomsguide.com/computing/online-security/100-million-americans-just-had-their-background-check-data-exposed-online-how-to-stay-safe">100 million Americans just had their background check data exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This nasty Android adware is making phones unusable — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-nasty-android-adware-is-making-phones-unusable-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ The MobiDash Android adware has returned and is targeting users through phishing emails and posts on Facebook. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nby7oRjD87Buu768Kp66jV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Oct 2024 21:19:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:description>                                                            <media:text><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>I often warn about the dangers posed by <a href="https://www.tomsguide.com/computing/malware-adware/new-android-malware-drains-your-bank-accounts-and-completely-wipes-your-device-how-to-stay-safe"><u>info-stealing malware</u></a> and <a href="https://www.tomsguide.com/computing/malware-adware/this-android-banking-trojan-just-got-a-serious-upgrade-to-take-over-your-phone-and-it-now-hides-in-legitimate-apps"><u>banking trojans</u></a> but there’s another mobile threat you need to worry about: adware. In fact, an adware infection can render one of the best Android phones unusable with ads popping out of nowhere when you least expect it.</p><p>According to a new <a href="https://www.malwarebytes.com/blog/news/2024/10/android-users-targeted-on-facebook-and-porn-sites-served-adware" target="_blank"><u>blog post</u></a> from the cybersecurity firm Malwrebytes, the MobiDash adware has returned to wreak havoc on vulnerable Android phones. First discovered back in 2015, this adware has continued to spread in the time since through hundreds of different variants. </p><p>At the same time though, it also comes as a pre-packaged set of tools that hackers and scammers can add to any Android Application Package or <a href="https://www.tomsguide.com/news/hackers-are-using-a-new-trick-to-fool-android-users-into-installing-malicious-apps-how-to-stay-safe">APK file</a> which makes distributing  it even easier.</p><p>Here’s everything you need to know about the MobiDash adware along with some tips on how to stay safe from having your own Android phone infested with annoying ads.</p><h2 id="hiding-in-plain-sight">Hiding in plain sight</h2><p>One of the main things that helps MobiDash stand out from other types of adware is that it can easily be added to legitimate Android apps without changing how they work. </p><p>For instance, let’s say you download and install a flashlight app (<a href="https://www.tomsguide.com/news/these-16-malicious-android-apps-have-over-20-million-downloads-delete-them-now"><u>which I don’t recommend</u></a> for obvious reasons). The app itself will still work as intended but hidden inside it, there will be adware waiting to fill your phone’s screen with unwanted ads.</p><p>To make matters worse, MobiDash often waits for several days before activating on an infected phone. This makes the annoying ads it serves up harder to detect, especially if you recently installed several new apps on your Android smartphone.</p><p>Malwarebytes’ <a href="https://www.threatdown.com/blog/watch-out-mobidash-android-adware-spread-through-phishing-and-online-links/?_ga=2.98701662.1379219456.1727793482-303056225.1722866883" target="_blank"><u>ThreatDown</u></a> cybersecurity platform recently uncovered a new MobiDash campaign that spread through <a href="https://www.tomsguide.com/news/hackers-are-using-this-new-gmail-scam-to-steal-your-personal-data-how-to-stay-safe"><u>phishing emails</u></a> as well as in links on social media posts made by real people as well as bots. </p><p>With these posts on Facebook, users who click on a link in a screenshot (something you should absolutely avoid) are then sent through a chain of redirects which ends in an APK file being automatically downloaded to their phone. Likewise, Malwarebytes’ researchers also found that MobiDash was being spread on adult sites in a similar way.</p><h2 id="how-to-stay-safe-from-adware">How to stay safe from adware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Staying safe from this particular campaign is quite easy and you can avoid falling victim to the MobiDash malware by not sideloading apps. While you <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps"><u>shouldn’t sideload apps</u></a> in the first place, you definitely should install any APK file that’s randomly downloaded onto your smartphone after clicking on a link in an email or social media post.</p><p>Besides adware, sideloading apps can leave you with a <a href="https://www.tomsguide.com/news/this-new-malware-exploit-can-take-over-your-google-account-even-after-a-password-reset-what-you-need-to-know"><u>nasty malware infection</u></a> and those who did fall for this latest MobiDash campaign got off lucky. Instead of sideloading, you should only download apps from the<a href="https://www.tomsguide.com/news/the-google-play-store-is-making-a-big-change-to-fend-off-malware-heres-how"><u> Google Play Store</u></a> or from official third-party app stores like the Samsung Galaxy Store or the Amazon Appstore.</p><p>To keep your Android phone protected from adware, malware, spyware and other threats, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled. This pre-installed app scans any new apps you download as well as your existing ones to help keep you and your data safe. For extra protection though, you may also want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside it on your phone.</p><p>Hackers and scammers are always coming up with clever new campaigns designed to steal your data and your hard-earned cash or in this case, to bombard your phones with ads in order to commit ad fraud. However, MobiDash could also serve up <a href="https://www.tomsguide.com/news/hackers-have-found-an-insidious-way-to-attack-you-with-malware-dont-fall-for-this">malicious ads</a> which can infect your phone with malware. Either way, you want to be extra careful where you click and avoid installing apps from unknown sources.</p><p>This likely isn’t the last we’ve heard of MobiDash as this particular adware has been going strong for almost a decade.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/11-million-android-users-infected-with-dangerous-necro-trojan-how-to-stay-safe">11 million Android users infected with dangerous Necro trojan — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/100-million-americans-just-had-their-background-check-data-exposed-online-how-to-stay-safe">100 million Americans just had their background check data exposed</a></li><li><a href="https://www.tomsguide.com/computing/online-security/29-billion-hit-in-one-of-largest-data-breaches-ever-full-names-addresses-and-ssns-exposed">2.9 billion hit in one of the largest data breaches ever — full names, addresses and SSNs exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Octo2 banking trojan is taking over Android phones and stealing cash — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-android-banking-trojan-just-got-a-serious-upgrade-to-take-over-your-phone-and-it-now-hides-in-legitimate-apps</link>
                                                                            <description>
                            <![CDATA[ After its source code leaked earlier this year, the Octo malware is back with a new version that can completely take over infected Android phones remotely. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2MyVFte2MdykVDno94yDvR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Sep 2024 17:08:51 +0000</pubDate>                                                                                                                                <updated>Tue, 24 Sep 2024 20:23:11 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture depicting how banking trojans steal credit card data]]></media:description>                                                            <media:text><![CDATA[A picture depicting how banking trojans steal credit card data]]></media:text>
                                <media:title type="plain"><![CDATA[A picture depicting how banking trojans steal credit card data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>After a two-year hiatus, the <a href="https://www.tomsguide.com/news/octo-android-malware-can-take-over-your-phone-how-to-protect-yourself"><u>Octo malware</u></a> has returned with improved capabilities that make it easier for hackers to use it to completely take over the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a>.</p><p>As reported by <a href="https://thehackernews.com/2024/09/new-octo2-android-banking-trojan.html" target="_blank"><u>The Hacker News</u></a>, security researchers at ThreatFabric have discovered a new version of this <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-banking-trojan-uses-fake-google-play-updates-to-take-over-your-phone-how-to-stay-safe"><u>Android banking trojan</u></a> called Octo2. So far, it’s mainly been used in campaigns across Europe but this malware could easily be reconfigured to target Android users in the U.S., Canada and other countries around the world.</p><p>What makes Octo2 so dangerous is the fact that it’s currently being distributed in malicious versions of popular apps including <a href="https://www.tomsguide.com/computing/online-security/new-malware-locks-google-chrome-in-kiosk-mode-until-you-enter-your-password-how-to-stay-safe"><u>Google Chrome</u></a> and <a href="https://www.tomsguide.com/reviews/nordvpn-review"><u>NordVPN</u></a>. Once your phone is infected with this malware, not only can hackers completely take it over but they can also perform <a href="https://www.tomsguide.com/computing/online-security/17-million-people-hit-in-massive-credit-card-data-breach-what-to-do-now"><u>fraudulent transactions</u></a> right from the device itself. This helps the hackers behind this campaign avoid being detected by banks and other financial institutions.</p><p>Here’s everything you need to know about this new version of Octo 2 including how it has managed to infiltrate legitimate apps along with some tips on how to stay safe from Android malware.</p><h2 id="hiding-in-legitimate-apps">Hiding in legitimate apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="gwfFXM6EmU37ZTAj75i5hQ" name="infected-phone2-shst.jpg" alt="One phone with skull and crossbones on screen among several other clean-looking phones." src="https://cdn.mos.cms.futurecdn.net/gwfFXM6EmU37ZTAj75i5hQ.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Marcos_Silva/Shutterstock)</span></figcaption></figure><p>The original Octo malware was first discovered back in 2022. However, it’s actually based on the Exobot malware that was first detected in 2016 according to a <a href="https://www.threatfabric.com/blogs/octo2-european-banks-already-under-attack-by-new-malware-variant" target="_blank"><u>blog post</u></a> from ThreatFabric.</p><p>The reason we’re now seeing the emergence of Octo 2 is due to the fact that the source code for the original version leaked earlier this year. With Octo’s source code in hand, hackers have begun creating their own variations of this malware to use in their attacks.</p><p>At the same time, Octo has moved to a malware-as-a-service (<a href="https://www.tomsguide.com/news/password-stealing-erbium-malware-is-spreading-fast-and-loved-by-cybercriminals"><u>MaaS</u></a>) operating model in which other cybercriminals pay its developer a small fee to use the malware in their own attacks. Octo’s developer even promoted this new version by informing its clients that existing users would be able to get Octo2 for the same price with early access.</p><p>To make their attacks harder to detect, the hackers deploying Octo2 are using it alongside an APK binding service called <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps"><u>Zombinder</u></a>. This may sound a bit too technical but here’s the gist, Zombinder lets hackers take legitimate Android apps and add malware to them in such a way that to the end user, they appear nearly identical to the original app.</p><p>Octo2 is downloaded by these rogue Android apps by convincing users that they need to install a “necessary plugin”. If an unsuspecting user falls for this, hackers then have complete control over their phone remotely which enables them to carry out all manner of attacks.</p><h2 id="how-to-stay-safe-from-android-malware-4">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>When it comes to staying safe from Android malware, the first and most important thing is that you avoid installing apps from unknown sources. This means only installing apps from trusted app stores like the Google Play Store, Samsung Galaxy Store or the Amazon Appstore.</p><p><a href="https://www.tomsguide.com/phones/android-phones/google-play-may-be-about-to-fix-the-biggest-issue-with-sideloading-apps-heres-how"><u>Sideloading apps</u></a> may be convenient but by doing so, you put yourself at risk of installing a malicious app that can then infect your phone with malware. This is why you should avoid doing so unless, of course, you need to install an app for work that can’t be hosted on an official store. However, this is extremely rare and most employers would never ask you to do this.</p><p>From here, you want to ensure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled on your Android phone. This free app comes pre-installed on most Android devices and it can scan all of your existing apps and any new ones you install for malware. For extra protection though, you should also consider using one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside it.</p><p>Now that Octo’s source code is out in the open, it’s very likely we will see even more variations of the malware. However, if you’re careful online, avoid sideloading apps and keep your phone updated with Google Play Protect enabled, you should be fine.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/11-million-android-users-infected-with-dangerous-necro-trojan-how-to-stay-safe">11 million Android users infected with dangerous Necro trojan — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/think-tap-to-pay-is-safer-new-android-malware-uses-stolen-nfc-data-to-drain-your-accounts">This Android malware uses stolen NFC data to drain your accounts</a></li><li><a href="https://www.tomsguide.com/computing/online-security/17-million-people-hit-in-massive-credit-card-data-breach-what-to-do-now">1.7 million people hit in massive credit card data breach — what to do now</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 11 million Android users infected with dangerous Necro trojan — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/11-million-android-users-infected-with-dangerous-necro-trojan-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ The Necro trojan has resurfaced and is now being injected into legitimate apps by hackers through malicious SDKs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pKVgUebWvderL72JDx7he5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Sep 2024 21:24:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Android phones are once again under attack from a <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-banking-trojan-uses-fake-google-play-updates-to-take-over-your-phone-how-to-stay-safe"><u>dangerous trojan</u></a> which has resurfaced to infect at least 11 million devices.</p><p>According to a <a href="https://www.kaspersky.co.uk/blog/necro-infects-android-users/28199/" target="_blank"><u>blog post</u></a> from the cybersecurity firm Kaspersky, the Necro trojan, which its security researchers first discovered in 2019, has returned. The trojan is now being distributed via official apps on the <a href="https://www.tomsguide.com/news/hackers-are-sneaking-malware-on-to-the-google-play-store-how-to-stay-safe"><u>Google Play Store</u></a>, unofficial modded versions of popular apps and in Android game mods.</p><p>Once installed on one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a>, Necro then downloads additional payloads that are used to activate a number of malicious plugins. From <a href="https://www.tomsguide.com/news/35-million-android-users-hit-with-adware-delete-these-apps-now"><u>adware</u></a> to <a href="https://www.tomsguide.com/news/malicious-android-apps-are-signing-users-up-for-paid-subscriptions-delete-these-now"><u>subscription fraud</u></a> to using infected devices as proxies to send malicious traffic, this malware is extremely versatile as a result of these plugins.</p><p>Here’s everything you need to know about the Necro trojan and how it can infect your smartphone along with some tips on how to stay safe from Android malware.</p><h2 id="hiding-in-official-and-unofficial-apps">Hiding in official and unofficial apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4865px;"><p class="vanilla-image-block" style="padding-top:57.06%;"><img id="b6kHN5w33oqtSXyNEacmve" name="Android malware on phone.jpg" alt="Android malware on phone" src="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve.jpg" mos="" align="middle" fullscreen="" width="4865" height="2776" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Even if you download a legitimate app from the Play Store, there’s still a slight chance it could be malicious as <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-these-android-apps-on-the-play-store-to-stage-attacks-delete-them-all-right-now"><u>good apps can go bad</u></a> thanks to the work of hackers. That appears to be exactly what happened in this case, as <a href="https://www.bleepingcomputer.com/news/security/android-malware-necro-infects-11-million-devices-via-google-play/" target="_blank"><u>BleepingComputer</u></a> points out, that the Necro trojan was installed through malicious advertising software development kits (<a href="https://www.tomsguide.com/news/over-400-million-infected-with-android-spyware-delete-these-apps-right-now"><u>SDK</u></a>).</p><p>The first and most downloaded app on the Play Store is <a href="https://play.google.com/store/apps/details?id=com.benqu.wuta&hl=en_US&pli=1" target="_blank"><u>Wuta Camera</u></a>, which lets you take pictures, touch them up and add a number of effects. This app alone was downloaded 10 million times. Based on Kasperky’s data, the Necro trojan was added to version 6.3.2.148 of Wuta Camera. However, versions starting from  6.3.7.138 no longer contain the trojan. This means if you’re using an older version of this app, you need to update it immediately.</p><p>The next official app infected with the Necro trojan is a web browser called Max Browser with one million downloads. The trojan was added to its code in version 1.2.0 but the app was removed from the Play Store after Kaspersky informed Google that it had become malicious. However, it’s still available on third-party app stores, so it’s best to recommend downloading Max Browser for the time being.</p><p>Kaspersky also found the Necro trojan lurking in a modified version of the Spotify Plus app. Users were invited to download a new version of the app from an unofficial source. However, unlike with the official <a href="https://www.tomsguide.com/opinion/spotifys-redesign-is-so-bad-im-considering-switching-to-apple-music"><u>Spotify app</u></a>, this version was free and came with an unlocked subscription. This should have been a red flag but some unsuspecting users decided to download and install it despite the risk which led to their phones being infected with the Necro trojan.</p><p>Finally, Kaspersky found the Necro trojan lurking in mods for WhatsApp, <a href="https://www.tomsguide.com/news/35-million-android-users-hit-with-adware-delete-these-apps-now"><u>Minecraft</u></a> and other popular games including Stumble Guys, Car Parking Multiplayer and Melon Sandbox. Hackers often use mods to popular games as a lure, so when in doubt, you should avoid modding mobile games altogether.</p><h2 id="how-to-stay-safe-from-android-malware-5">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>When it comes to malware-filled apps, the first and most important thing you can do is to avoid downloading apps from unofficial sources. <a href="https://www.tomsguide.com/phones/android-phones/google-play-may-be-about-to-fix-the-biggest-issue-with-sideloading-apps-heres-how"><u>Sideloading apps</u></a> may be easy and convenient but doing so can also be extremely dangerous. This is why you should stick to official app stores like the Google Play Store, Samsung Galaxy Store and the Amazon Appstore.</p><p>From here, you want to ensure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> (which comes pre-installed) is enabled on your Android smartphone. This first-party app scans all of the new apps as well as your existing ones for malware and other threats. For even more protection though, you should consider using one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside it.</p><p>Even when you download apps from the Play Store or other official app stores, you want to check their ratings and reviews first. As these can be faked though, it’s always a good idea to look for a video review online, so that you can see the app in question in action before downloading it.</p><p>Recently, Google has made great strides at eliminating malicious apps from the Play Store but they still manage to slip through the cracks from time to time. This is why it’s a good idea to limit the number of apps on your phone overall.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/17-million-people-hit-in-massive-credit-card-data-breach-what-to-do-now">1.7 million people hit in massive credit card data breach — what to do now</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/think-tap-to-pay-is-safer-new-android-malware-uses-stolen-nfc-data-to-drain-your-accounts">This Android malware uses stolen NFC data to drain your accounts</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/new-macos-malware-poses-as-legitimate-apps-to-steal-passwords-crypto-wallets-and-more-how-to-stay-safe">New macOS malware poses as legitimate apps to steal passwords and personal data</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Think tap to pay is safer? New Android malware uses stolen NFC data to drain your accounts ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/think-tap-to-pay-is-safer-new-android-malware-uses-stolen-nfc-data-to-drain-your-accounts</link>
                                                                            <description>
                            <![CDATA[ The newly discovered NGate malware uses a malicious app to relay payment data from a victim’s phone to hackers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ssBMZaKz3Mv9ukiYwxanf5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 26 Aug 2024 16:38:58 +0000</pubDate>                                                                                                                                <updated>Mon, 26 Aug 2024 18:42:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture depicting how banking trojans steal credit card data]]></media:description>                                                            <media:text><![CDATA[A picture depicting how banking trojans steal credit card data]]></media:text>
                                <media:title type="plain"><![CDATA[A picture depicting how banking trojans steal credit card data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Switching from pin and chip cards to contactless ones seemed like the perfect way to stay safe from <a href="https://www.tomsguide.com/news/hackers-can-steal-your-credit-card-details-in-the-real-world-how-to-stay-safe"><u>credit card skimmers</u></a>. However, a new <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now"><u>Android malware</u></a> abuses the same technology used for tap and pay to steal payment data from unsuspecting victims.</p><p>As reported by <a href="https://thehackernews.com/2024/08/new-android-malware-ngate-steals-nfc.html?m=1" target="_blank"><u>The Hacker News</u></a>, the malware in question has been dubbed NGate by security researchers at ESET, and it steals <a href="https://www.tomsguide.com/phones/android-phones/google-just-released-android-15-beta-11-to-fix-critical-bug-what-we-know"><u>NFC</u></a> data to clone contactless credit and debit cards on a hacker’s smartphone. With these cloned payment cards on their phone, they can drain a victim’s bank accounts by using them to withdraw funds at ATMs.</p><p>Here’s everything you need to know about this new Android malware strain and how to stay safe from hackers.</p><h2 id="impersonating-banks-to-takeover-phones">Impersonating banks to takeover phones</h2><p>The NGate malware is based on a legitimate tool called NFCGate, originally created by students at TU Darmstadt’s Secure Mobile Networking Lab in 2015. In the years since, though, the technique used by this tool has been weaponized by hackers.</p><p>According to a <a href="https://www.welivesecurity.com/en/eset-research/ngate-android-malware-relays-nfc-traffic-to-steal-cash/" target="_blank"><u>new report</u></a> from ESET, the attackers behind this recent NGate campaign use a combination of <a href="https://www.tomsguide.com/news/this-social-engineering-trick-can-infect-your-pc-with-malware-what-you-need-to-know"><u>social engineering</u></a> and <a href="https://www.tomsguide.com/news/this-fake-text-message-from-amazon-can-steal-your-account-dont-fall-for-this-nasty-phishing-scam"><u>SMS phishing</u></a> to trick unsuspecting Android users into installing the malware directly. This is done through fake sites impersonating actual banks or their mobile apps on the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know"><u>Google Play Store</u></a>.</p><p>Between November of last year and March of this year, as many as six different malicious apps spreading the NGate malware were identified. However, malicious activity slowed significantly after a 22-year-old was arrested by law enforcement in Czechia after they were found withdrawing funds using stolen cards at ATMs.</p><p>Once one of the <a href="https://www.tomsguide.com/computing/malware-adware/these-malicious-android-malware-apps-were-downloaded-150000-times-from-the-play-store-delete-them-right-now">malicious apps</a> used to distribute the NGate malware is installed on a victim’s smartphone, it asks them to enter sensitive financial information, including their banking client ID, date of birth and the PIN code for their bank card via a <a href="https://www.tomsguide.com/news/hackers-often-use-this-clever-trick-to-take-you-to-phishing-sites-can-you-spot-it"><u>phishing page</u></a> presented with a WebView. However, they’re also asked to turn on NFC on their phone and instructed to place their debit or credit card up against it until the malicious app recognizes their card.</p><p>To make matters worse, victims also receive calls from their attacker, who pretends to be a bank employee that informs them their account has been compromised due to installing the malicious app in question. From there, victims are then asked to change their PIN and validate their card using another NGate app.</p><h2 id="how-to-stay-safe-from-advanced-android-malware">How to stay safe from advanced Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>At the moment, the NGate malware is only being used by hackers to target owners of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a> in Czechia. However, like with other online threats, this one could easily spread to the U.S., the U.K., Canada, Australia and other countries around the world. For this reason, you need to be on the lookout for more complicated malware attacks like this one. </p><p>To avoid getting infected with the NGate malware, ESET recommends that Android users only download apps from official app stores like the Google Play Store, Samsung Galaxy Store and the Amazon Appstore. You also want to carefully scrutinize the URLs of any websites you visit and avoid clicking on links in emails and messages from unknown senders.</p><p>As this attack abuses NFC to steal your bank and credit cards, you may want to consider turning this feature off when you’re not actively using it. It could also be worth investing in a phone case that blocks unwanted RFID scans, which can prevent hackers from using NFC to steal your payment cards. You may also want to consider using digital versions of your physical cards on your phone. These digital versions are stored securely on your device, and you can use biometrics like your fingerprint or a face scan to keep them even safer.</p><p>Since we are dealing with malware, you also want to ensure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled on your device, as it can scan all of your existing apps and any new ones you download for viruses. For additional protection, though, you should also consider using one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside it.</p><p>In an email to Tom&apos;s Guide, a Google spokesperson provided further insight on this new Android malware threat, saying:<br><br>"Based on our current detections, no apps containing this malware are found on Google Play. Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play."</p><p>Hackers are always coming up with clever new ways to steal your hard-earned cash, and the NGate malware is the perfect example of this. However, if you take the necessary precautions and are careful online, you should have no problem at all avoiding falling victim to this new threat.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/fbi-issues-warning-over-scammers-impersonating-banks-to-steal-your-debit-cards">FBI issues warning over scammers impersonating banks to steal your debit cards</a></li><li><a href="https://www.tomsguide.com/phones/google-pixel-phones/google-removes-hidden-pixel-app-that-could-have-left-millions-of-phones-vulnerable-to-malware-spyware-and-other-attacks">Google removes hidden Pixel app that could have left millions of phones vulnerable</a></li><li><a href="https://www.tomsguide.com/computing/online-security/hackers-can-gain-access-to-your-macs-microphone-camera-and-more-through-flaws-in-these-popular-microsoft-apps-how-to-stay-safe">Hackers can exploit these new flaws in Microsoft's macOS apps to spy on your Mac</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New macOS malware poses as legitimate apps to steal passwords and personal data — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-macos-malware-poses-as-legitimate-apps-to-steal-passwords-crypto-wallets-and-more-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Security researchers issue public warning about Cthulhu Stealer, a malware-as-a-service sold cheaply to criminals looking to target macOS users ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uZuneDmrAqczpoCymhXdT9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 25 Aug 2024 16:36:15 +0000</pubDate>                                                                                                                                <updated>Sun, 25 Aug 2024 18:12:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alyse Stanley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/BxNnQuBWRHqkv5xWZsjrjc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alyse Stanley is a news editor at Tom’s Guide, overseeing weekend coverage and writing about the latest in tech, gaming, and entertainment. Before Tom’s Guide, Alyse worked as an editor for the Washington Post’s sunsetted video game section, Launcher, where she also wrote about indie games you shouldn’t miss, how to tackle your gaming backlog, and all things Nintendo. She previously led Gizmodo’s weekend news desk covering breaking tech news and has written game reviews and features for outlets like Polygon, Unwinnable, and Rock, Paper, Shotgun. A recent Chicago-area transplant born and raised in Virginia, Alyse is a big fan of horror movies, cartoons, and roller skating. She&#039;s also a puzzle fan and can often be found contributing to the NYT Connections coverage on Tom&#039;s Guide &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While Apple&apos;s Macs aren&apos;t targeted by hackers as much as Windows PCs, they aren&apos;t impenetrable. Security researchers recently uncovered malware dubbed "Cthulhu Stealer" that impersonates popular apps to harvest passwords and steal data from macOS users. </p><p>As first reported by <a href="https://thehackernews.com/2024/08/new-macos-malware-cthulhu-stealer.html" target="_blank">The Hacker News</a>, <a href="https://www.cadosecurity.com/blog/from-the-depths-analyzing-the-cthulhu-stealer-malware-for-macos" target="_blank">Cado Security</a> pushed out a public warning this week about Cthulhu Stealer, a malware-as-a-service targeting macOS users launched in late 2023 that sells for $500 a month. "The malware is written in Golang and disguises itself as legitimate software," said Cado Security researcher Tara Gould. </p><p>To trick users into installing it, it&apos;s appeared as software programs like CleanMyMac, Grand Theft Auto IV, or Adobe GenP, an open-source tool some Adobe users employ to get around having a Creative Cloud subscription. The malware comes packaged as a disk image (DMG) file that contains a pair of binaries, which lets it attack both Intel and Apple Silicon Macs depending on which architecture it detects. </p><p>When a user tries to open the fake app, macOS&apos;s built-in security feature, Gatekeeper, warns that the software is unsigned. If the user opts to bypass Gatekeeper protections and let it run anyway, they&apos;re given an otherwise legitimate-looking prompt to enter their system password, followed by a second prompt for the MetaMask cryptocurrency wallet. Once it has the necessary permissions, Cthulhu Stealer can siphon a wide range of sensitive data, including saved passwords from iCloud Keychain, web browser cookies and Telegram account information. </p><p>"The main functionality of Cthulhu Stealer is to steal credentials and cryptocurrency wallets from various stores, including game accounts," Gould explained. </p><p>It&apos;s an osascript-based technique that we&apos;ve seen in infostealers and malware before like <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-from-info-stealing-malware-dont-fall-for-this-microsoft-teams-scam">Atomic Stealer</a>, Cuckoo, MacStealer, and Banshee Stealer. But even if Cthulhu Stealer isn&apos;t the most sophisticated malware out there, it still poses a serious threat to Mac users who could stumble into this trap. </p><h2 id="how-to-stay-safe-from-mac-malware-2">How to stay safe from Mac malware</h2><p>So what can you do to keep <a href="https://www.tomsguide.com/best-picks/best-macbook">the best Macs</a> protected from malware like Cthulhu Stealer? First and foremost, be vigilant about the apps you download and do your due diligence to make sure whoever you&apos;re downloading it from is who they say they are. While your Mac comes with built-in antivirus software in the form of <a href="https://www.tomsguide.com/news/macos-is-getting-even-better-at-scanning-for-malware-heres-how">XProtect</a>, consider using that in tandem with one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> solutions. Paid antivirus software is updated more regularly and will often throw in a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a> to help you stay safe online.</p><p>Apple is also working on making it harder to bypass Gatekeeper protections with <a href="https://www.tomsguide.com/computing/macos/macos-sequoia">macOS Sequoia</a>, which is expected to roll out in mid-September. Rather than being able to override Gatekeeper warnings by Control-clicking, users will instead have to go through System Settings to allow unsigned software to run. Hopefully, the annoyance of going through an extra step will be enough of a deterrent to make users think twice before running potentially dangerous apps.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-from-info-stealing-malware-dont-fall-for-this-microsoft-teams-scam">Macs under threat from info-stealing malware — don’t fall for this Microsoft Teams scam</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/apple-issues-new-spyware-warning-for-iphone-users-in-98-countries-how-to-stay-safe">Apple issues urgent spyware warning for iPhone users in 98 countries</a></li><li><a href="https://www.tomsguide.com/news/the-fbi-now-recommends-using-an-ad-blocker-heres-why">The FBI now recommends using an ad blocker — here’s why</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Chrome and Edge users infected with malicious browser extensions that steal your personal data — what to do now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/chrome-and-edge-users-infected-with-malicious-browser-extensions-that-steal-your-personal-data-what-to-do-now</link>
                                                                            <description>
                            <![CDATA[ Security researchers have discovered a new malware campaign that uses malicious extensions distributed via fake sites impersonating popular software and services. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pzZoxxZe9JRfZhiKdEqhn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/62aHxnvmKJvfMzFqKzR96H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 12 Aug 2024 22:34:05 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Aug 2024 04:22:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/62aHxnvmKJvfMzFqKzR96H-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[and image of the Google Chrome logo on a laptop]]></media:description>                                                            <media:text><![CDATA[and image of the Google Chrome logo on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[and image of the Google Chrome logo on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/62aHxnvmKJvfMzFqKzR96H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are using <a href="https://www.tomsguide.com/news/millions-under-threat-from-malicious-browser-extensions-what-to-do">malicious browser extensions</a> to infect both Google Chrome and Microsoft Edge with dangerous malware that can steal your personal data and leave your computer at risk of further attacks.</p><p>As reported by <a href="https://thehackernews.com/2024/08/new-malware-hits-300000-users-with.html"><u>The Hacker News</u></a>, this recently discovered malware campaign has been active since 2021 and so far, at least 300,000 Chrome and Edge users have fallen victim to it.</p><p>What makes this malware particularly dangerous is the fact that it can achieve <a href="https://www.tomsguide.com/news/hackers-are-using-fake-chrome-updates-to-spread-malware-dont-fall-for-this">persistence</a> on infected PCs. This means that even if you delete the malicious extension, the malware will reactivate itself the next time you restart your computer.</p><p>Here’s everything you need to know about this malware campaign and how you can actually remove the malicious extension used in it once and for all.</p><h2 id="using-malvertising-to-push-fake-sites">Using malvertising to push fake sites</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="Re2sDX92s3QG6dFsFnyrX6" name="6KXS4iqE4rw2D8SCHP62JF.jpg" alt="A woman looking at a smartphone while using a laptop" src="https://cdn.mos.cms.futurecdn.net/Re2sDX92s3QG6dFsFnyrX6.jpg" mos="" align="middle" fullscreen="" width="1000" height="562" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Like other malware campaigns, this one uses <a href="https://www.tomsguide.com/news/hackers-have-found-an-insidious-way-to-attack-you-with-malware-dont-fall-for-this">malvertising</a> to trick unsuspecting users into downloading and installing risky software.</p><p>The hackers behind it have created lookalike sites that impersonate popular software and services like Roblox FPS Unlocker, YouTube, VLC media player, Steam or Keepass. While potential victims think they’re installing legitimate software or extensions, they’re actually downloading a trojan that installs the malicious extensions used by this malware.</p><p>The digitally signed malicious installers used in this campaign register a scheduled task on vulnerable PCs that then executes a <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-chrome-word-and-onedrive-errors-to-trick-people-into-installing-malware-how-to-stay-safe">PowerShell script</a> which downloads and executes the next-stage payload from a hacker-controlled remote server.</p><p>As part of this next-stage payload, the malware modifies an infected PCs Windows Registry to force the installation of Chrome and Edge extensions which are used for <a href="https://www.tomsguide.com/news/malicious-chrome-extensions-with-1-million-downloads-can-hijack-your-browser-delete-these-now">ad fraud</a> by hijacking web searches on Google and Bing and then redirecting them through the hackers’ servers. To make matters worse, newer versions of this malware can even prevent browser updates from being installed, putting victims at risk of other attacks.</p><p>Fortunately, there is a fix but it does take some technical know how.</p><h2 id="how-to-remove-this-malware-from-your-pc-for-good">How to remove this malware from your PC for good</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ynU5BuH6Taj5rNfWw8mmpV" name="LG Gram 17 Pro-5.jpg" alt="LG Gram 17 Pro (2023) review unit on table outdoors running Windows 11" src="https://cdn.mos.cms.futurecdn.net/ynU5BuH6Taj5rNfWw8mmpV.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tom's Guide)</span></figcaption></figure><p>In a <a href="https://reasonlabs.com/research/new-widespread-extension-trojan-malware-campaign"><u>blog post</u></a> detailing the findings of its security researchers, ReasonLabs provides further insight on how to properly remove this malware and the malicious extensions used in this campaign from your PC.</p><p>First things first, you need to remove the scheduled task from your PC. This is done by clicking on the <strong>Start Menu</strong> or pressing the <strong>Windows key</strong> on your keyboard and then searching for <strong>Task Scheduler</strong>. </p><p>Once Task Scheduler is opened, you need to click on the <strong>Task Scheduler Library</strong> to show all of the tasks on your PC. While the task name used by this malware varies, you can identify it by clicking on tasks, opening them and then clicking on <strong>Actions</strong>. In the table below Actions, you can look at their <strong>Details</strong> and here, you want to look for a path to “c:\windows\system32” and a PowerShell script or a file ending with “.ps1”. ReasonLabs notes that the task name will often be similar to the PowerShell script name.  Once you’ve found the malicious task, right click on its name and then click <strong>Delete</strong>.</p><p>After this, you then need to remove the registry keys that are forcing the malicious extensions in your browser. This is more difficult but you can open the <strong>Registry Editor</strong> the same way that you did with the Task Scheduler. Keep in mind though that you shouldn’t mess with your computer’s registry unless you absolutely know what you’re doing. When in doubt, ask a friend for help or take your PC to a professional.</p><p>With the Registry Editor opened, you need to go to “Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist”. In the right pane here, there will be a list of extensions with a numerical value as “Name” and Extension ID as “Data”. Then right click on the name and then click <strong>Delete</strong>. You also have to do this for this registry key as well: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Policies\Google\Chrome\ExtensionInstallForcelist.”</p><p>As this malware affects both Chrome and Edge, you will need to repeat the same process for the Edge extensions at this path: “Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallForcelist”.</p><p>While you could delete the malware files yourself, you’re much better off using one of the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>best antivirus software</u></a> solutions to do it for you. If you do want to do so manually, you can find instructions at the end of ReasonLabs’ blog post linked above.</p><p>Going through the process of removing these malicious extensions and the malware they’ve dropped on your PC will likely be more than enough to ensure you think twice before downloading new software or browser extensions from untrustworthy sources. If you do want to download a new extension, do so from the Chrome Web Store or from the Microsoft Edge Add-on Store instead.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/phones/live/made-by-google-august-2024-event-live-blog">Made by Google event live blog — Pixel 9, Pixel 9 Pro Fold and Pixel Watch 3 news</a></li><li><a href="https://www.tomsguide.com/computing/online-security/chrome-safari-and-other-browsers-vulnerable-to-0000-day-vulnerability-what-you-need-to-knowhttps://www.tomsguide.com/computing/online-security/29-billion-hit-in-one-of-largest-data-breaches-ever-full-names-addresses-and-ssns-exposed">2.9 billion hit in one of the largest data breaches ever</a></li><li><a href="https://www.tomsguide.com/phones/android-phones/google-just-fixed-46-security-flaws-including-an-actively-exploited-zero-day-update-your-android-phone-now">Google just fixed 46 security flaws, including an actively exploited zero-day</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new Android malware drains your bank accounts and completely wipes your device — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-android-malware-drains-your-bank-accounts-and-completely-wipes-your-device-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Hackers have created a new malware strain that’s being spread through text messages while posing as an Android antivirus app. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xqkWfF2kdKHzoXt8pT7cdY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Aug 2024 21:43:25 +0000</pubDate>                                                                                                                                <updated>Fri, 02 Aug 2024 17:28:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Having your bank accounts drained by hackers is bad enough but a new <a href="https://www.tomsguide.com/news/this-android-malware-installs-backdoor-on-your-phone-delete-these-malicious-apps-now"><u>Android malware</u></a> is taking things a step further by completely wiping your phone clean afterwards.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/new-android-malware-wipes-your-device-after-draining-bank-accounts/" target="_blank"><u>BleepingComputer</u></a>, this new malware strain has been dubbed “BingoMod” by the security researchers at the online fraud management company <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts"><u>Cleafy</u></a> who first discovered it back in May of this year.</p><p>Like other dangerous malware, this one is designed to steal your hard-earned cash by accessing your financial accounts. However, BingoMod is capable of performing on-device fraud (ODF) which allows the hackers behind it to easily bypass anti-fraud systems.</p><p>If you have one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a> and don’t want to end up with an empty bank account and a completely wiped phone, here’s everything you need to know about this new malware strain and what to look out for to help you stay safe.</p><h2 id="committing-on-device-fraud">Committing on-device fraud</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:5000px;"><p class="vanilla-image-block" style="padding-top:65.86%;"><img id="FP9vpJQzmJU8GP2ZFHpc8K" name="banking trojan.jpg" alt="banking trojan on phone illustration" src="https://cdn.mos.cms.futurecdn.net/FP9vpJQzmJU8GP2ZFHpc8K.jpg" mos="" align="middle" fullscreen="" width="5000" height="3293" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>In their <a href="https://www.cleafy.com/cleafy-labs/bingomod-the-new-android-rat-that-steals-money-and-wipes-data" target="_blank"><u>report</u></a> on the matter, Cleafy’s researchers explain that the new BingoMod malware is currently being spread through phishing messages sent via text. </p><p>In order to get potential victims to open and interact with them, these malicious messages use a variety of names which closely resemble actual Android security software. For example, some of these phishing texts use the icon for <a href="https://www.tomsguide.com/reviews/avg-free-antivirus"><u>AVG AntiVirus Free</u></a> which is available on the Google Play Store.</p><p>When a potential victim does try to install one of these <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now"><u>malicious apps</u></a>, BingoMod asks for permissions for Android’s <a href="https://www.tomsguide.com/news/android-13-security-feature-designed-to-stop-malware-has-already-been-bypassed"><u>Accessibility Service</u></a> which is often abused by mobile malware strains to gain even greater control over an infected smartphone.</p><p>From here, BingoMod steals login credentials, takes screenshots and intercepts any text messages sent to the now compromised Android device. However, in order to perform on-device fraud, it also establishes a socket-based channel to receive commands along with an HTTP-based channel to send screenshots back to hackers behind this malware.</p><p>By obtaining real-time screen content from an infected device, it’s much easier for BingoMod to bypass anti-fraud systems that use identity verification and authentication since they are using a victim’s actual smartphone and not just their credentials. In fact, the malware actually gives cybercriminals a great deal of command over an infected Android phone; they can click on a particular area, write text anywhere they want and launch apps. </p><p>At the same time, BingoMod also allows hackers to launch manual <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-banking-trojan-uses-fake-google-play-updates-to-take-over-your-phone-how-to-stay-safe"><u>overlay attacks</u></a> by using fake notifications. Finally, to make matters worse, a smartphone infected with BingoMod can use text messages to spread onto other vulnerable phones.</p><h2 id="bypassing-antivirus-apps-and-wiping-phones-clean">Bypassing antivirus apps and wiping phones clean</h2><p>If all that wasn’t scary enough, BingoMod can also remove the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> from an infected smartphone as well as block the activity of any apps the hackers behind this malware specify in a command.</p><p>To help it evade detection, BingoMod’s creators have added code-flattening and string obfuscation layers. Even the popular malware analyzation service <a href="https://www.tomsguide.com/news/these-popular-apps-are-being-mimicked-to-spread-malware-heres-how-to-protect-yourself"><u>VirusTotal</u></a> couldn’t detect this new Android malware.</p><p>As for wiping an infected phone clean, if the malware is registered on the device as a device admin app, a hacker can send a remote command to wipe its system. However, Cleafy’s researchers point out in their report that this is only done after a successful transfer and only impacts a phone’s external storage. </p><p>Still though, a complete wipe is possible if a hacker uses this ability to erase all of a device’s data and then resets the phone via system settings.</p><h2 id="how-to-stay-safe-from-android-malware-6">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Even with all of these advanced capabilities, BingoMod actually still appears to be in an early development stage which means it could become even more dangerous later on. At the moment though, it is only being used to target Android phones owned by English, Romanian and Italian-speaking users.</p><p>Since BingoMod can bypass Android antivirus apps and evade detection, the only way to stay safe is by avoiding the <a href="https://www.tomsguide.com/computing/malware-adware/malicious-messaging-apps-used-to-spread-malware-on-google-play-delete-these-right-now">malicious text messages</a> used in this campaign altogether. If you do get an unsolicited message from someone you don’t know, you need to be very careful. Don’t click on any links it may contain and likewise, you shouldn’t respond to it either.</p><p>In a statement to Tom&apos;s Guide, a Google spokesperson explained that the search giant&apos;s built-in antivirus app <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> can help protect Android smartphones from this new malware threat, saying:</p><p>"Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services. Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play."</p><p>As BingoMod is still in active development, this likely isn&apos;t the last we&apos;ve heard of this new Android malware. However, if you&apos;re extra careful online and avoid interacting with text messages from unknown senders, you can avoid having your bank accounts drained and your smartphone wiped by hackers.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/intel-laying-off-15000-employees-and-slashing-randd-in-biggest-cuts-ever-heres-why">Intel laying off 15,000 employees and slashing R&D in biggest cuts ever</a></li><li><a href="https://www.tomsguide.com/computing/online-security/43-million-people-hit-in-massive-healthcare-data-breach-full-names-addresses-and-ssns-exposed-online">4.3 million people hit in massive healthcare data breach </a></li><li><a href="https://www.tomsguide.com/computing/online-security/google-is-giving-chrome-a-major-upgrade-to-keep-you-safe-from-dangerous-downloads-here-how-it-works">Chrome is getting a major upgrade to keep you safe from dangerous downloads</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This dangerous Android spyware has returned via malicious Play Store apps — delete them right now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-spyware-has-returned-via-malicious-play-store-apps-delete-them-right-now</link>
                                                                            <description>
                            <![CDATA[ Hackers used malware droppers to spread the Mandrake Android spyware via the Google Play Store for years. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">X3YMDPb5FofXr7FHukywqM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gwfFXM6EmU37ZTAj75i5hQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jul 2024 18:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gwfFXM6EmU37ZTAj75i5hQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Marcos_Silva/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[One phone with skull and crossbones on screen among several other clean-looking phones.]]></media:description>                                                            <media:text><![CDATA[One phone with skull and crossbones on screen among several other clean-looking phones.]]></media:text>
                                <media:title type="plain"><![CDATA[One phone with skull and crossbones on screen among several other clean-looking phones.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gwfFXM6EmU37ZTAj75i5hQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybersecurity researchers have discovered a new version of the Mandrake Android spyware hiding in apps on the Google Play Store.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/android-spyware-mandrake-hidden-in-apps-on-google-play-since-2022/" target="_blank">BleepingComputer</a>, <a href="https://www.tomsguide.com/news/mandrake-android-spyware"><u>Mandrake</u></a> was first discovered by <a href="https://www.tomsguide.com/reviews/bitdefender"><u>Bitdefender</u></a> in 2020, but before then, it had been operating in the wild since at least 2016. Since then, Kaspersky has discovered a new variant of the Android spyware that’s better at remaining undetected.</p><p>In a <a href="https://www.bleepingcomputer.com/news/security/android-spyware-mandrake-hidden-in-apps-on-google-play-since-2022/" target="_blank"><u>new report</u></a>, the cybersecurity firm’s researchers explain that this new version of Mandrake managed to sneak onto the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know"><u>Play Store</u></a> in five apps submitted back in 2022. Surprisingly, most apps remained available for at least a year, while one held out for two years before it was eventually discovered.</p><p>If you own one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a> and are worried about this resurfaced threat, here’s everything you need to know about the Mandrake spyware and how to stay safe from malware.</p><h2 id="delete-these-apps-right-now">Delete these apps right now</h2><p>At the time of writing, all <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now"><u>malicious apps</u></a> found to contain this new version of the Mandrake spyware have been removed from the Google Play Store. However, if you have any of them installed on your smartphone or one of the <a href="https://www.tomsguide.com/best-picks/best-android-tablets"><u>best Android tablets</u></a>, you must manually delete them. </p><p>Here are the apps in question, along with how many times unsuspecting Android users have downloaded them:</p><ul><li><strong>AirFS</strong> - 30,305 downloads</li><li><strong>Astro Explorer</strong> - 718 downloads</li><li><strong>Amber</strong> - 19 downloads</li><li><strong>CryptoPulsing</strong> - 790 downloads</li><li><strong>Brain Matrix</strong> - 259 downloads</li></ul><p>Of these malicious apps, AirFS is the one that managed to evade detection the longest, and it was up on the Play Store for two years before eventually being taken down back in March of this year. According to Kaspersky, Android users mainly downloaded these apps in the U.K., Canada, Germany, Italy, Mexico, Spain and Peru.</p><h2 id="hiding-in-plain-sight-2">Hiding in plain sight</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4865px;"><p class="vanilla-image-block" style="padding-top:57.06%;"><img id="b6kHN5w33oqtSXyNEacmve" name="Android malware on phone.jpg" alt="Android malware on phone" src="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve.jpg" mos="" align="middle" fullscreen="" width="4865" height="2776" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The malicious apps spreading the Mandrake spyware do things a bit differently than your typical Android malware. Instead of putting malicious logic in an app’s DEX file, Mandrake hides its first stage in a native library called “libopencv_dnn.so” which is obfuscated using OOLVM.</p><p>Once installed on a potential victim’s Android phone, this library then exports functions that are used to decrypt the second-stage loader DEx from its assets folder and load it into memory. </p><p>This second stage also requests to draw overlays often used in <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts"><u>overlay attacks</u></a>. However, it also loads a second native library (called “libopencv_java3.so”), which decrypts a certificate that is used for secure communications with a hacker-controlled command and control (<a href="https://www.tomsguide.com/computing/online-security/hackers-have-found-a-clever-way-to-use-emojis-in-their-attacks-but-its-not-what-you-think"><u>C2</u></a>) server.</p><p>Once the malicious app is connected to the hacker’s C2 server, it sends a device profile and receives its third stage, which is actually the Mandrake spyware. The spyware can perform a wide range of malicious actions such as collecting data, screen recording and monitoring, command execution, simulating swipes and taps, managing files, and even installing additional malicious apps.</p><p>The hackers behind this spyware have also devised a way to display notifications that impersonate real ones from the Play Store to trick users into side-loading additional malware through APK files. </p><p>Just like with other dangerous <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-wpeeper-android-malware-adds-a-backdoor-to-your-phone-to-steal-your-data-how-to-stay-safe">Android malware strains</a>, Mandrake abuses Android permissions to run in the background and to hide app icons so that it can sneakily operate in the background unnoticed.</p><h2 id="how-to-stay-safe-from-android-malware-7">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>While all five malicious apps in question have since been removed from the Play Store, cybercriminals could use new, harder-to-detect apps to continue spreading the spyware from Google’s official app store going forward.</p><p>For this reason, you always need to be careful when downloading and installing new apps on your Android devices. You want to look at reviews and ratings carefully before downloading anything. Still, as these can be faked, you should also look for external third-party reviews and video reviews that show a particular app in action before you download it.</p><p>At the same time, you also want to ensure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled on your smartphone or tablet since it can scan all your existing apps and any new ones you download for malware. For additional protection, though, you should also consider using one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside it.</p><p>Malicious apps have been very successful for hackers and other cybercriminals in the past, which is why this threat likely won’t be going away anytime soon despite Google’s best efforts to prevent them from ending up on the Play Store. This is why you need to be careful and do your research first before installing any new apps on your Android smartphone or tablet.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/rite-aid-hit-in-major-data-breach-with-22-million-customers-affected-names-drivers-license-numbers-and-more-stolen-by-hackers">Rite Aid hit in major data breach with 2.2 million customers affected</a></li><li><a href="https://www.tomsguide.com/computing/online-security/google-is-giving-chrome-a-major-upgrade-to-keep-you-safe-from-dangerous-downloads-here-how-it-works">Google is giving Chrome a major upgrade to keep you safe from dangerous downloads</a></li><li><a href="https://www.tomsguide.com/computing/online-security/43-million-people-hit-in-massive-healthcare-data-breach-full-names-addresses-and-ssns-exposed-online">4.3 million people hit in massive healthcare data breach with full names, addresses and SSNs exposed online</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Macs under threat from info-stealing malware — don’t fall for this Microsoft Teams scam ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/macs-under-threat-from-info-stealing-malware-dont-fall-for-this-microsoft-teams-scam</link>
                                                                            <description>
                            <![CDATA[ Mac users trying to download Microsoft Teams could end up with a nasty malware infection thanks to fake ads. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aeoDKvYGrFokE3jPkkZGn6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/76BX7qw85vqQucCvUnTHHQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Jul 2024 04:55:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/76BX7qw85vqQucCvUnTHHQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MacBook Pro 2021 (16-inch) on a patio table]]></media:description>                                                            <media:text><![CDATA[MacBook Pro 2021 (16-inch) on a patio table]]></media:text>
                                <media:title type="plain"><![CDATA[MacBook Pro 2021 (16-inch) on a patio table]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/76BX7qw85vqQucCvUnTHHQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When looking for new software online, you never want to click on the first search result as you could be dealing with <a href="https://www.tomsguide.com/news/you-should-think-twice-before-clicking-on-ads-even-on-google-search"><u>fake ads</u></a> spreading dangerous malware.</p><p>As we saw with the Arc browser in a recent <a href="https://www.tomsguide.com/computing/malware-adware/downloading-this-new-mac-browser-could-leave-you-with-a-nasty-malware-infection-dont-fall-for-this"><u>Poseidon campaign</u></a>, hackers are once again using fake ads to direct unsuspecting Mac users to <a href="https://www.tomsguide.com/news/these-misspelled-websites-are-spreading-nasty-malware-how-to-stay-safe"><u>malicious sites</u></a> hosting malware. This time though, they’re spreading the <a href="https://www.tomsguide.com/news/hackers-now-spreading-mac-malware-via-fake-browser-updates-dont-fall-for-this"><u>Atomic Stealer</u></a> malware which can steal passwords from web browsers and even Apple Keychain as well as cryptocurrency through fake Microsoft Teams downloads.</p><p>Here’s everything you need to know about this new campaign along with some tips on how you can keep your Mac virus free.</p><h2 id="hiding-in-plain-sight-3">Hiding in plain sight</h2><p>While cybercriminals and other hackers have traditionally used communication tools like Zoom, Webex or Slack as a lure, this time around, they’re using <a href="https://www.tomsguide.com/news/new-microsoft-teams-is-live-heres-the-3-biggest-upgrades"><u>Microsoft Teams</u></a> as the software giant’s workplace chat app has become quite popular.</p><p>In a <a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/07/fake-microsoft-teams-for-mac-delivers-atomic-stealer" target="_blank"><u>new report</u></a>, security researchers at <a href="https://www.tomsguide.com/reviews/malwarebytes-for-mac-premium"><u>Malwarebytes</u></a> explain how a search for “Microsoft Teams for Mac” led to a fake ad being displayed at the top of Google Search. They believe this ad was paid for by a compromised Google ad account.</p><p>Even though the ad itself shows microsoft[.]com as the URL at the top, clicking on it doesn’t take you to Microsoft’s official site. Instead, doing so takes you to a <a href="https://www.tomsguide.com/computing/malware-adware/hackers-target-job-hunters-with-dangerous-new-windows-backdoor-how-to-stay-safe"><u>fake landing page</u></a> with the URL teambusiness[.]org that impersonates the actual Microsoft Teams site.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1127px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="wt4pmWcBHDXEuKp49sJXQR" name="fake teams site.jpg" alt="Fake Microsoft Teams site spreading malware" src="https://cdn.mos.cms.futurecdn.net/wt4pmWcBHDXEuKp49sJXQR.jpg" mos="" align="middle" fullscreen="" width="1127" height="634" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Malwarebytes)</span></figcaption></figure><p>This incredibly simple site has Apple’s logo at the top with a brief description of the app and what it does. Underneath is a “Download Teams” button that when clicked, downloads a <a href="https://www.tomsguide.com/news/these-mac-apps-are-secretly-spreading-malware-delete-them-now"><u>malicious Mac app</u></a>.</p><p>If you frequently use one of the <a href="https://www.tomsguide.com/best-picks/best-macbook"><u>best MacBooks</u></a>, you might immediately be able to tell that something is off as the downloaded file (MicrosoftTeams_v.(xx).dmg) instructs potential victims to open it with a right click. This is a big red flag as any app that asks you to install it in this manner is actually trying to bypass Apple’s built-in protection mechanism for unsigned installers.</p><p>From here, the malicious app requests that the user enters their password and grants access to the file system. However, doing so allows the Atomic Stealer malware to grab <a href="https://www.tomsguide.com/news/new-macstealer-malware-steals-icloud-keychain-data-and-passwords-how-to-stay-safe"><u>Apple Keychain</u></a> passwords and other important files on the now compromised Mac. If you let things get this far, the malware then proceeds to extract sensitive data from your Apple computer and then send it back to the hackers behind this campaign.</p><h2 id="how-to-stay-safe-from-mac-malware-3">How to stay safe from Mac malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="F9ybS7WNwSK95hqxotZgYM" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/F9ybS7WNwSK95hqxotZgYM.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>As I mentioned before, the first and most important thing you can do to stay safe from fake ads spreading malware is actually to scroll further down the page when searching for new software online. Just like you or I, hackers too can easily buy ad space but for much more nefarious purposes.</p><p>Taking the extra second or so to scroll down to a company’s actual website could save you from falling victim to a nasty malware infection and perhaps even <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html"><u>having your identity stolen</u></a> by hackers.</p><p>Although your Mac does come with built-in antivirus software in the form of <a href="https://www.tomsguide.com/news/macos-is-getting-even-better-at-scanning-for-malware-heres-how"><u>XProtect</u></a>, you might also want to consider using one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus"><u>best Mac antivirus software</u></a> solutions alongside it. Paid antivirus software is updated more regularly plus, you often get extras like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a> to help you stay safe online.</p><p>Over the past few years, we’ve seen hackers routinely use fake ads in their malware campaigns due to how successful this tactic can be. Fortunately, if you scroll down past the ads, you can avoid falling victim to this and other similar campaigns designed to infect your Mac with password-stealing malware.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/apple-issues-new-spyware-warning-for-iphone-users-in-98-countries-how-to-stay-safe">Apple issues urgent spyware warning for iPhone users in 98 countries</a></li><li><a href="https://www.tomsguide.com/news/the-fbi-now-recommends-using-an-ad-blocker-heres-why">The FBI now recommends using an ad blocker — here’s why</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-facebook-ads-to-infect-windows-pcs-with-password-stealing-malware-how-to-stay-safe">Hackers are using Facebook ads to infect Windows PCs with malware</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using Facebook ads to infect Windows PCs with password-stealing malware — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-using-facebook-ads-to-infect-windows-pcs-with-password-stealing-malware-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Cybercriminals often abuse ads as a means to spread dangerous malware online. A new campaign is targeting Facebook users with Windows PCs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kd4GebZC3WWm6QW9XsZERo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ACBCnmVuQsWLA9CTBod6KW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 15 Jul 2024 16:07:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ACBCnmVuQsWLA9CTBod6KW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facebook app on phone]]></media:description>                                                            <media:text><![CDATA[Facebook app on phone]]></media:text>
                                <media:title type="plain"><![CDATA[Facebook app on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ACBCnmVuQsWLA9CTBod6KW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You wouldn’t expect to run into <a href="https://www.tomsguide.com/news/macs-under-attacks-from-password-stealing-malware-how-to-stay-safe"><u>password-stealing malware</u></a> while browsing Facebook but hackers are now using fake ads to target vulnerable Windows PCs on the popular social network.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/facebook-ads-for-windows-themes-push-sys01-info-stealing-malware/" target="_blank"><u>BleepingComputer</u></a>, security researchers at Trustwave have discovered several new campaigns that use fake Windows themes along with fake downloads for pirated games and software as a lure to trick unsuspecting Facebook users into clicking on their <a href="https://www.tomsguide.com/news/you-should-think-twice-before-clicking-on-ads-even-on-google-search"><u>malicious ads</u></a>. This is done by either creating new <a href="https://www.tomsguide.com/news/facebook-business-accounts-are-being-hijacked-by-malware-how-to-stay-safe"><u>Facebook business accounts</u></a> or by hijacking existing ones.</p><p>Here’s everything you need to know about this new campaign and how you can keep your own Windows PC safe from malware.</p><h2 id="stealing-passwords-and-facebook-account-info">Stealing passwords and Facebook account info</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YwKRVzwvLwup6hDGh5bVNM" name="RzdqY6hhVUXJjJYEgfCrVe.jpg" alt="A hacker typing quickly on a keyboard" src="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>According to <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/facebook-malvertising-epidemic-unraveling-a-persistent-threat-sys01/" target="_blank"><u>Trustwave’s report</u></a>, the hackers behind this latest round of attacks have taken out thousands of ads for each individual campaign. For instance, the top campaign called “blue-softs” had 8,100 ads while “xtaskbar-themes” had 4,300 ads.</p><p>Clicking on one of these fake ads takes potential victims to <a href="https://www.tomsguide.com/news/these-misspelled-websites-are-spreading-nasty-malware-how-to-stay-safe"><u>malicious sites</u></a> hosted on Google Sites or True Hosting which appear to be download pages for the themes or software advertised on Facebook. These sites have a download button that when clicked, downloads a ZIP file with a name that matches the product advertised online.</p><p>As you’d expect, these ZIP files actually contain the SYS01 info-stealing malware which was first discovered by the cybersecurity firm <a href="https://www.tomsguide.com/news/jupyter-trojan-steals-passwords"><u>Morphisec</u></a> back in 2022. The malware itself uses a collection of executables, dynamic-link library (DLL) files, <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-chrome-word-and-onedrive-errors-to-trick-people-into-installing-malware-how-to-stay-safe"><u>PowerShell scripts</u></a> and PHP scripts to install itself and steal data from a targeted Windows PC.</p><p>SYS01 can steal cookies from your browser along with any passwords stored there and a victim’s browsing history. However, it also includes a task that leverages Facebook cookies on an infected device to extract data from a victim’s profile including their name, email, birthday and more on the social network. </p><p>Even if you’re not on Facebook, you still need to be careful as Trustwave has observed similar <a href="https://www.tomsguide.com/news/hackers-using-google-ads-to-steal-your-info-and-drain-your-accounts-what-you-need-to-know"><u>malvertising campaigns</u></a> on both YouTube and LinkedIn.</p><h2 id="how-to-stay-safe-from-malware-2">How to stay safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="Re2sDX92s3QG6dFsFnyrX6" name="6KXS4iqE4rw2D8SCHP62JF.jpg" alt="A woman looking at a smartphone while using a laptop" src="https://cdn.mos.cms.futurecdn.net/Re2sDX92s3QG6dFsFnyrX6.jpg" mos="" align="middle" fullscreen="" width="1000" height="562" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>To avoid falling victim to this campaign and others like it, the first and most important thing you can do is to avoid clicking on ads. </p><p>Hackers can buy ad space just as easily as legitimate businesses, so to stay safe, you’re better off not clicking on ads at all. In fact, even the <a href="https://www.tomsguide.com/news/the-fbi-now-recommends-using-an-ad-blocker-heres-why"><u>FBI recommends you now use an ad-blocker</u></a>. </p><p>If you do see an ad for something you like, though, you’re better off heading to a search engine or — better yet — to the company’s site directly and shopping for the item you may be interested in. When you do need to interact with an ad online, you’re going to want to make sure that you’re using the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>best antivirus software</u></a> to protect yourself from any malware or other viruses that ad could be spreading.</p><p>We’ve now seen fake ads on both Google and Facebook, and both companies are trying to crack down on this practice. In the meantime, you just need to be careful where you click and avoid downloading anything from unknown sites and sources online.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/apple-issues-new-spyware-warning-for-iphone-users-in-98-countries-how-to-stay-safe">Apple issues urgent spyware warning for iPhone users in 98 countries</a></li><li><a href="https://www.tomsguide.com/news/hackers-using-google-ads-to-steal-your-info-and-drain-your-accounts-what-you-need-to-know">Hackers using Google Ads to steal your info and drain your accounts </a></li><li><a href="https://www.tomsguide.com/news/nsfw-facebook-ads-being-used-to-spread-dangerous-malware-dont-click-on-these">NSFW Facebook ads used to spread dangerous malware — don’t click on these</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple issues urgent spyware warning for iPhone users in 98 countries — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/apple-issues-new-spyware-warning-for-iphone-users-in-98-countries-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Apple is warning users in 98 countries that they are being targeted by mercenary spyware designed to compromise their iPhones. Here's how to avoid it. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">udfxx6W9wtdHKsPNY2oH6S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9Ln5e3J6wmezqwU7c9pZXY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jul 2024 15:59:08 +0000</pubDate>                                                                                                                                <updated>Thu, 11 Jul 2024 18:25:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9Ln5e3J6wmezqwU7c9pZXY-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[iPhone 14 Plus shown held in hand]]></media:description>                                                            <media:text><![CDATA[iPhone 14 Plus shown held in hand]]></media:text>
                                <media:title type="plain"><![CDATA[iPhone 14 Plus shown held in hand]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9Ln5e3J6wmezqwU7c9pZXY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Although iPhones have a reputation for being more secure than their Android counterparts, the popularity of Apple’s smartphones makes them a bigger target for hackers, especially when it comes to more sophisticated <a href="https://www.tomsguide.com/computing/online-security/lightspy-spyware-can-now-snoop-on-your-mac-and-your-iphone-how-to-protect-yourself"><u>spyware attacks</u></a>.</p><p>Earlier this year, the iPhone maker sent out a <a href="https://www.tomsguide.com/phones/iphones/apple-sends-out-iphone-mercenary-spyware-warnings-to-92-countries-what-you-need-to-know"><u>spyware warning</u></a> to its customers in 92 countries around the world. Now Apple is back with another similar warning but this time, it’s gone out to iPhone users in even more countries.</p><p>Here’s everything you need to know about this new spyware warning along with how you can keep your own iPhone safe from hackers. </p><h2 id="same-threat-new-warning">Same threat, new warning</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:57.90%;"><img id="JD2iZVZUGEpBV4Awf4YyZP" name="smartphone-spyware-shst.jpg" alt="A spyware alert displaying on a smartphone." src="https://cdn.mos.cms.futurecdn.net/JD2iZVZUGEpBV4Awf4YyZP.jpg" mos="" align="middle" fullscreen="" width="1000" height="579" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: David MG/Shutterstock)</span></figcaption></figure><p>As reported by <a href="https://techcrunch.com/2024/07/10/apple-alerts-iphone-users-in-98-countries-to-mercenary-spyware-attacks/?" target="_blank"><u>TechCrunch</u></a>, Apple has sent out a new warning about mercenary spyware to iPhone users in 98 countries. Indian users were among them as many of the country’s journalists have been targeted by the infamous <a href="https://www.tomsguide.com/phones/nsa-issues-warning-to-iphone-and-android-users-do-this-to-stop-hackers"><u>NSO Group</u></a> and its <a href="https://www.tomsguide.com/news/ios-1661-update-your-iphone-now-to-prevent-pegasus-from-spying-on-you"><u>Pegasus spyware</u></a> in the past.</p><p>The warning says that “Apple detected that you are being targeted by a mercenary spyware attack” which is designed to remotely compromise the iPhone associated with your <a href="https://www.tomsguide.com/computing/online-security/apple-ids-under-threat-from-new-phishing-attack-spread-through-texts-dont-fall-for-this"><u>Apple ID</u></a>. It goes on to explain that the reason a particular user is being targeted is due to “who you are or what you do.”</p><p>Unlike with <a href="https://www.tomsguide.com/computing/malware-adware/first-ever-ios-trojan-discovered-and-its-stealing-face-id-data-to-break-into-bank-accounts"><u>malware</u></a> or <a href="https://www.tomsguide.com/computing/online-security/new-darcula-phishing-service-using-imessage-to-target-iphone-users-how-to-stay-safe"><u>phishing attacks</u></a>, spyware is more expensive for hackers to deploy, which is why it’s normally reserved for high-value targets like journalists, politicians and activists.</p><p>It’s worth noting that in the past, Apple has referred to these incidents as “state-sponsored” attacks while this time, the company is calling them “mercenary spyware attacks.” While the language may have changed, the threat remains the same.</p><h2 id="how-to-stay-safe-from-spyware-2">How to stay safe from spyware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="F9ybS7WNwSK95hqxotZgYM" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/F9ybS7WNwSK95hqxotZgYM.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>When it comes to protecting the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html"><u>best iPhones</u></a> from spyware, the first and most important thing you can do is to keep your smartphone updated and running the latest software. Apple often includes security patches in both major and minor iOS releases that can help keep you, your devices and the data stored on them safe.</p><p>If you are a high-value target or think that you could be, you should also consider enabling Apple’s <a href="https://www.tomsguide.com/news/ios-16-getting-extreme-lockdown-mode-what-it-means-for-your-iphone"><u>Lockdown Mode</u></a> on your iPhone. However, doing so does limit certain functions (like link previews in messages and just-in-time [JIT] JavaScript compilation in your browser) to minimize vulnerabilities which can be exploited by spyware. For those who are at serious risk though, this can be worth it as the alternative is much worse.</p><p>In addition to enabling Lockdown Mode, you should also consider signing up for Google’s <a href="https://www.tomsguide.com/news/nest-users-can-now-sign-up-for-googles-most-secure-protection"><u>Advanced Protection Program</u></a> which is designed to help keep you safe from phishing attempts and harmful downloads. It also comes with some limitations and extra requirements that change how you use your Google account.</p><p>For most people though, a warning like this is more of a wake-up call than a serious threat. Just because iPhones are known for being very secure, it doesn’t mean that you should take unnecessary risks online. One other way that you can keep your iPhone and your Mac safe is by installing the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus"><u>best Mac antivirus software</u></a>. While not every Mac antivirus can scan your iPhone for malware, <a href="https://www.tomsguide.com/reviews/intego-mac-internet-security-x9"><u>Intego Mac Internet Security X9</u></a> and <a href="https://www.tomsguide.com/reviews/intego-premium-bundle-x9"><u>Intego Mac Premium Bundle X9</u></a> can.</p><p>Spyware is highly profitable and can extract all sorts of sensitive data from a targeted device, so don’t expect this threat to disappear anytime soon.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/phones/iphones/dangerous-lightspy-iphone-spyware-can-steal-your-files-location-data-and-messages-how-to-stay-safe">Dangerous LightSpy iPhone spyware can steal your files, location data and messages</a></li><li><a href="https://www.tomsguide.com/news/hackers-have-found-a-sneaky-way-to-spy-on-iphone-users-heres-how">Hackers have found a sneaky new way to spy on your iPhone — here’s how</a></li><li><a href="https://www.tomsguide.com/news/worried-about-spyware-on-your-iphone-ishutdown-can-reveal-if-youve-been-infected">Worried about spyware on your iPhone? iShutdown can reveal if you’ve been infected</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Downloading this popular new browser could leave your Mac with a nasty malware infection — don’t fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/downloading-this-new-mac-browser-could-leave-you-with-a-nasty-malware-infection-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ Hackers have launched a new malvertising campaign that infects Mac users trying to download the Arc browser with info-stealing malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hYKdhTZpdYSe79bRnzb4WM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Jul 2024 18:21:54 +0000</pubDate>                                                                                                                                <updated>Tue, 02 Jul 2024 20:21:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:description>                                                            <media:text><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:text>
                                <media:title type="plain"><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you’re tired of Safari or Chrome and are thinking of switching browsers, you need to be extra careful as hackers are using fake ads to infect the <a href="https://www.tomsguide.com/best-picks/best-macbook"><u>best MacBooks</u></a> with info-stealing malware.</p><p>As reported by <a href="https://cybernews.com/security/poseidon-malware-infostealer-macos-users-arc-browser/" target="_blank"><u>Cybernews</u></a>, a rebranded <a href="https://www.tomsguide.com/news/hackers-have-found-an-insidious-way-to-attack-you-with-malware-dont-fall-for-this"><u>malvertising</u></a> campaign dubbed “Poseidon” has been discovered online hiding in <a href="https://www.tomsguide.com/news/macs-under-threat-from-malicious-ads-spreading-malware-dont-fall-for-this"><u>fake ads on Google Search</u></a>. Apparently, this Mac infostealer was developed as an alternative to the popular <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-by-malicious-info-stealing-malware-spread-through-ads-and-fake-software-dont-fall-for-this"><u>Atomic Stealer</u></a> used to target Windows PCs.</p><p>Here’s everything you need to know about this new malvertising campaign along with how to stay safe from malware when downloading new software for your Mac.</p><h2 id="hijacking-search-results-with-fake-ads">Hijacking search results with fake ads</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1037px;"><p class="vanilla-image-block" style="padding-top:56.32%;"><img id="hHmtjqausSajUJnuRc4u7a" name="arc-browser-fake-ad.jpg" alt="Fake ad for the Arc browser spotted on Google Search" src="https://cdn.mos.cms.futurecdn.net/hHmtjqausSajUJnuRc4u7a.jpg" mos="" align="middle" fullscreen="" width="1037" height="584" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Malwarebytes)</span></figcaption></figure><p>In a new <a href="https://www.malwarebytes.com/blog/news/2024/06/poseidon-mac-stealer-distributed-via-google-ads" target="_blank"><u>report</u></a>, the antivirus firm <a href="https://www.tomsguide.com/reviews/malwarebytes-premium-privacy-for-mac"><u>Malwarebytes</u></a> revealed that once again, hackers are using the popular new <a href="https://www.tomsguide.com/opinion/i-almost-ditched-chrome-for-the-arc-web-browser-heres-why"><u>Arc browser</u></a> as a lure in their attacks. </p><p>If a Mac user searches for Arc online, they could be tricked into clicking on a fake ad  that leads to the site “arc-download[.]com" which isn&apos;t the browser&apos;s real address. Instead of the Arc browser, this site hosts a <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-apps-to-distribute-this-dangerous-mac-malware-dont-fall-for-this"><u>malicious DMG file</u></a> that looks like a legitimate installer.</p><p>Seasoned Mac users will notice that something is amiss right away as this fake installer asks them to right-click on the DMG file to open it. Doing things this way allows the hackers to bypass macOS’ built-in security protections.</p><p>When installed on a vulnerable Mac, this fake version of the Arc browser can steal a victim’s files, passwords and browser data and even extract cryptocurrency from any crypto wallets found on their computer.</p><p>If you are looking for a change and want to try out Arc on your Mac, you can <a href="https://arc.net/" target="_blank"><u>download it here</u></a> at The Browser Company’s official website.</p><h2 id="how-to-stay-safe-from-mac-malware-4">How to stay safe from Mac malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="F9ybS7WNwSK95hqxotZgYM" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/F9ybS7WNwSK95hqxotZgYM.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>Since this info-stealing malware is spread through fake ads after all, you may want to consider <a href="https://www.tomsguide.com/news/the-fbi-now-recommends-using-an-ad-blocker-heres-why"><u>using an ad blocker</u></a> on your Mac to avoid this and other similar threats online.</p><p>From there though, you should also be using the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus"><u>best Mac antivirus software</u></a> to help detect and stop malware from infecting your computer. Apple does include its own built-in antivirus software with macOS but unlike with <a href="https://www.tomsguide.com/news/macos-is-getting-even-better-at-scanning-for-malware-heres-how"><u>XProtect</u></a>, you often get a number of extras like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a> with paid antivirus software.</p><p>Even with an ad blocker installed though, you want to get in the habit of scrolling down to the actual search results when looking for new software online. Hackers often use fake ads to lead potential victims to <a href="https://www.tomsguide.com/news/these-misspelled-websites-are-spreading-nasty-malware-how-to-stay-safe"><u>malicious sites</u></a> distributing malware in their attacks, so you want to avoid clicking on ads when possible. Instead, you’re much better off navigating to a site directly just to be safe.</p><p>Malvertising is quite effective and while Google is taking steps to crack down on the practice, hackers will likely continue to use this tactic in their attacks.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/apple-airpods-can-be-hacked-to-eavesdrop-on-your-conversations-how-to-stay-safe">Apple AirPods can be hacked to eavesdrop on your conversations</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-now-using-malware-cluster-bombs-in-their-attacks-how-to-stay-safe">Hackers are now using 'malware cluster bombs' in their attacks</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/medusa-banking-trojan-returns-and-can-now-hide-its-malicious-activities-in-plain-sight-how-to-stay-safe">Medusa banking trojan returns to steal your passwords and cash</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are now using 'malware cluster bombs' in their attacks — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-now-using-malware-cluster-bombs-in-their-attacks-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Hackers have begun using a new infection method in their attacks that allows them to use one malware strain to spread several viruses at the same time. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TTNzqg4zhDVEpP7AkJvXzY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 29 Jun 2024 06:45:51 +0000</pubDate>                                                                                                                                <updated>Sat, 29 Jun 2024 06:55:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Having your computer <a href="https://www.tomsguide.com/features/your-pc-could-be-under-attack-by-malware-heres-how-to-tell"><u>infected with malware</u></a> is bad enough but imagine if hackers were able to drop ten different malware strains onto your PC at the same time? Well, a new hacker group is now doing just that.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/new-unfurling-hemlock-threat-actor-floods-systems-with-malware/" target="_blank"><u>BleepingComputer</u></a>, a threat actor known as Unfurling Hemlock has begun infecting vulnerable systems with what security researchers at KrakenLabs are calling “malware cluster bombs”. </p><p>According to a new <a href="https://outpost24.com/blog/unfurling-hemlock-cluster-bomb-campaign/" target="_blank"><u>blog post</u></a>, Unfurling Hemlock has already launched these so-called malware cluster bomb attacks in 10 countries around the world, though the majority of them appear to be aimed at targets in the U.S. The attacks themselves began back in February of last year and are easy to trace back to the hacker group due to their distinct distribution method.</p><p>Here’s everything you need to know about these malware cluster bomb attacks along with some steps you can take to avoid falling victim to one.</p><h2 id="dropping-a-malware-bomb">Dropping a malware bomb</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YwKRVzwvLwup6hDGh5bVNM" name="RzdqY6hhVUXJjJYEgfCrVe.jpg" alt="A hacker typing quickly on a keyboard" src="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The initial malware used in these attacks is distributed through <a href="https://www.tomsguide.com/news/this-is-the-one-thing-to-look-out-for-in-scam-emails"><u>malicious emails</u></a> or <a href="https://www.tomsguide.com/news/hackers-have-found-an-insidious-way-to-attack-you-with-malware-dont-fall-for-this"><u>malware loaders</u></a> that Unfurling Hemlock paid other hackers to use. Either way, there’s a malicious executable named “WEXTRACT.EXE” that ends up on a potential victim’s computer.</p><p>This malicious executable serves as the malware cluster bomb since it contains nested compressed cabinet files with each level containing a different malware sample or another compressed file. Once unpacked on a victim’s computer, each one drops a different malware variant.</p><p>When the final stage in the attack is reached, all of these extracted files are then executed in reverse order with the most recently extracted malware hitting the targeted device first. According to KrakenLabs’ researchers, each of these malware cluster bombs has between four and seven stages, so the amount of malware contained within them varies.</p><p>In regard to the types of malware dropped on a computer in one of Unfurling Hemlock’s attacks, there could be <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-by-malicious-info-stealing-malware-spread-through-ads-and-fake-software-dont-fall-for-this"><u>info-stealers</u></a>, <a href="https://www.tomsguide.com/news/this-popular-mac-utility-is-now-malware-delete-it-right-now"><u>botnets</u></a> and <a href="https://www.tomsguide.com/news/this-new-macos-backdoor-lets-hackers-take-over-your-mac-remotely-how-to-stay-safe"><u>backdoors</u></a>. KrakenLabs has observed the <a href="https://www.tomsguide.com/news/hackers-just-hijacked-2ks-support-site-to-spread-malware-to-gamers"><u>Redline stealer</u></a> and many other popular malware strains in these cluster bomb-style attacks.</p><p>While KrakenLabs didn’t cover how Unfurling Hemlock is making money from these attacks, BleepingComputer believes that the group could be harvesting sensitive data using info-stealing malware and then selling this information off to other hacker groups.</p><h2 id="how-to-stay-safe-from-malware-3">How to stay safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wbnnjnFdxfHUZGiSFXky2S" name="computer smartphone security.jpg" alt="Best antivirus software" src="https://cdn.mos.cms.futurecdn.net/wbnnjnFdxfHUZGiSFXky2S.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>When it comes to staying safe from malware in general and with these cluster bomb-style attacks, the most important thing you can do is to be extra careful when downloading files online. Whether it&apos;s an attachment in a <a href="https://www.tomsguide.com/news/this-new-phishing-scam-can-steal-your-social-security-number-how-to-stay-safe"><u>phishing email</u></a> or an executable from a dodgy site, you shouldn’t be downloading or opening any file from a non-trusted source.</p><p>However, hackers use all kinds of different tactics from <a href="https://www.tomsguide.com/news/this-social-engineering-trick-can-infect-your-pc-with-malware-what-you-need-to-know"><u>social engineering</u></a> to creating a fake <a href="https://www.tomsguide.com/news/unpaid-invoices-are-one-of-the-easiest-ways-scammers-try-and-trick-you-what-to-look-out-for"><u>sense of urgency</u></a> to get you to respond to their messages or to download and open suspicious files. This is where the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>best antivirus software</u></a> can help. </p><p>When you do download something suspicious, your antivirus will flag the file to warn you that it’s dangerous. Paid antivirus software often comes with useful extras like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or a <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a> but Microsoft’s built-in antivirus software should be able to stop most threats. You just need to make sure that <a href="https://www.tomsguide.com/news/windows-defender-good-enough-for-new-laptop"><u>Windows Defender</u></a> is enabled on your PC which it should be as it’s turned on by default.</p><p>Hackers are always coming up with new attack methods and these malware cluster bombs are one of the most interesting ones I’ve seen in quite some time. However, if you’re careful online, avoid downloading files from unknown sources and keep your PC and the software on it up to date, you should be able to avoid ending up with a nasty malware infection.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/medusa-banking-trojan-returns-and-can-now-hide-its-malicious-activities-in-plain-sight-how-to-stay-safe">Dangerous Medusa banking trojan returns to steal your passwords and cash</a></li><li><a href="https://www.tomsguide.com/computing/online-security/apple-airpods-can-be-hacked-to-eavesdrop-on-your-conversations-how-to-stay-safe">Apple AirPods can be hacked to eavesdrop on your conversations</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/malware-filled-extensions-are-a-chrome-threat-you-cant-ignore-reportedly-installed-by-280-million-over-the-last-three-years">280 million at risk from malware-filled Chrome extensions — how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Medusa banking trojan returns to steal your passwords and cash — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/medusa-banking-trojan-returns-and-can-now-hide-its-malicious-activities-in-plain-sight-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ The Medusa banking trojan is back with all-new capabilities that make it even easier for this malware to steal your passwords and cash. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Nwgrf8yiqkXMmeKU2f7ydh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hymSLCyZabSxT4kiY4sXhP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Jun 2024 20:26:59 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jun 2024 20:44:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hymSLCyZabSxT4kiY4sXhP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware botnet attack]]></media:description>                                                            <media:text><![CDATA[Android malware botnet attack]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware botnet attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hymSLCyZabSxT4kiY4sXhP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When a popular <a href="https://www.tomsguide.com/computing/malware-adware/this-nasty-android-banking-trojan-lets-hackers-completely-hijack-your-phone-how-to-stay-safe"><u>Android banking trojan</u></a> goes dark, it’s usually good news—but not in this case. </p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/new-medusa-malware-variants-target-android-users-in-seven-countries/" target="_blank"><u>BleepingComputer</u></a>, after almost a year of lying low, the Medusa banking trojan has returned in several campaigns targeting users of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a> in the U.S., the U.K., Canada, France, Italy, Spain and Turkey.</p><p>While Medusa was already dangerous before, these new variants require <a href="https://www.tomsguide.com/phones/android-phones/google-blocked-over-2-million-dangerous-android-apps-from-the-play-store-last-year">fewer permissions</a> and include new features that make it easier for the malware to commit fraud directly on a compromised smartphone.</p><p>Here’s everything you need to know about these new Medusa variants along with how you can keep yourself and your Android devices protected from banking trojans.</p><h2 id="using-botnets-to-deliver-malicious-apps">Using botnets to deliver malicious apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="X2e6hr6bWx89b7Nf87EKxX" name="botnet-structure-shst.jpg" alt="Stylized computer-aided illustration of interlinked blue robots illustrating the structure of a network botnet." src="https://cdn.mos.cms.futurecdn.net/X2e6hr6bWx89b7Nf87EKxX.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>According to a <a href="https://www.cleafy.com/cleafy-labs/medusa-reborn-a-new-compact-variant-discovered" target="_blank"><u>new report</u></a> from the online fraud management firm <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts"><u>Cleafy</u></a>, these new Medusa variants were first spotted back in July of last year in several campaigns that used SMS phishing or <a href="https://www.tomsguide.com/news/this-fake-text-message-from-amazon-can-steal-your-account-dont-fall-for-this-nasty-phishing-scam"><u>smishing</u></a> to side-load the malware with the help of dropper apps.</p><p>In total, the researchers have identified 24 separate campaigns with five of them attributed to botnets that were used to deliver malicious apps to unsuspecting users. Some of the <a href="https://www.tomsguide.com/news/these-shady-android-apps-are-stealing-banking-info-delete-them-now"><u>dropper apps</u></a> used in these campaigns include a <a href="https://www.tomsguide.com/news/hackers-are-using-fake-chrome-updates-to-spread-malware-dont-fall-for-this"><u>fake Chrome browser</u></a>, a 5G connectivity app and a fake streaming app called 4K Sports.</p><p>As Medusa is a <a href="https://www.tomsguide.com/news/password-stealing-erbium-malware-is-spreading-fast-and-loved-by-cybercriminals"><u>malware-as-a-service</u></a> offering where hackers pay a subscription fee to deploy the banking trojan, all of these campaigns and botnets are handled by its central infrastructure, which fetches links for its command and control (<a href="https://www.tomsguide.com/news/google-calendar-now-being-targeted-by-hackers-what-you-need-to-know"><u>C2</u></a>) server.</p><h2 id="smaller-footprint-but-even-more-dangerous">Smaller footprint but even more dangerous</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4865px;"><p class="vanilla-image-block" style="padding-top:57.06%;"><img id="b6kHN5w33oqtSXyNEacmve" name="Android malware on phone.jpg" alt="Android malware on phone" src="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve.jpg" mos="" align="middle" fullscreen="" width="4865" height="2776" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>To make it easier to install their banking trojan, Medusa’s creators have made it even smaller, and it now requests fewer permissions after installation. However, it still relies on Android’s <a href="https://www.tomsguide.com/news/android-13-security-feature-designed-to-stop-malware-has-already-been-bypassed"><u>Accessibility Services</u></a> to function.</p><p>While 17 commands were removed from the previous version of this banking trojan, it retains its ability to access a victim’s contacts and send text messages to spread even further. There are some new commands, though, which give these Medusa variants the ability to uninstall apps, draw over apps, set a black screen overlay and take screenshots.</p><p>Of these, the <a href="https://www.tomsguide.com/news/these-android-apps-can-steal-your-banking-info-by-recording-your-screen-delete-them-now"><u>screen overlay</u></a> one is particularly dangerous since it can be used by a remote attacker to make an infected smartphone appear as if it has been turned off while malicious activities are performed in the background. Likewise, Medusa’s screenshot capability provides hackers with an easy way to steal sensitive information like passwords from an infected device.</p><p>We’ll be keeping a close eye on this improved banking trojan as its smaller size means that the hackers using it will be able to expand the scope of their attacks while targeting even more Android users.</p><h2 id="how-to-stay-safe-from-android-malware-8">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>As the Medusa banking trojan is often spread through dropper apps, you need to be extra careful when installing new apps on your smartphone. </p><p>While <a href="https://www.tomsguide.com/news/over-60000-compromised-android-apps-found-spreading-adware-how-to-stay-safe"><u>sideloading apps</u></a> may be convenient, it’s an easy way to come down with a nasty malware infection, especially if you’re downloading their APK files from less-than-trustworthy sources. For this reason, you should stick to official Android app stores like the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know"><u>Google Play Store</u></a>, Amazon Appstore and the Samsung Galaxy Store.</p><p>At the same time, you also want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled on your Android phone as it scans all of your existing apps and any new ones you download for malware. For extra protection, you may also want to consider using one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside it.</p><p>Banking trojans can be quite lucrative for the hackers that use them in their attacks, so don’t expect this particular threat to disappear anytime soon.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/urgent-windows-security-flaw-lets-hackers-infect-your-pc-over-wi-fi-update-right-now">Urgent Windows security flaw lets hackers infect your PC over Wi-Fi</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/malware-filled-extensions-are-a-chrome-threat-you-cant-ignore-reportedly-installed-by-280-million-over-the-last-three-years">Over 280 million at risk from malware-filled Chrome extensions </a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-chrome-word-and-onedrive-errors-to-trick-people-into-installing-malware-how-to-stay-safe">Chrome security alert — this error will open the malware floodgates on your PC</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware gang claims cyber attack on Federal Reserve ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/ransomware-gang-claims-cyber-attack-on-federal-reserve</link>
                                                                            <description>
                            <![CDATA[ Ransomware gang Lockbit 3.0 has claimed responsibility for a cyber attack on the US Federal Reserve ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FHodv6DhxmyL5VzxTSgyCA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9JmTabf9SdZjLaW9muABUj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Jun 2024 13:00:44 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jun 2024 13:01:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ olivia.powell@futurenet.com (Olivia Powell) ]]></author>                    <dc:creator><![CDATA[ Olivia Powell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/FKbUaUWbWreYpT9SbyC7qd.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Olivia joined Tom&#039;s Guide in October 2023 as part of the core Future Tech Software team, and is the Commissioning Editor at Tom&#039;s Guide. With a background in cybersecurity, Olivia is interested in how VPNs protect users&#039; privacy, and how they improve online safety. She also regularly uses VPNs to make sure they deliver what they promise, and specializes in testing VPNs with streaming sites.&lt;/p&gt;&lt;p&gt;After graduating with a degree in English Literature from the University of Exeter, Olivia got her official start in journalism writing magazines for the events industry, writing for Exhibition News, Conference News, All Access, Exhibition World and Conference and Meeting World both in print and online. After this, she delved into the world of customer experience at CX Network, then the cybersecurity sector when she became Editor in Chief for Cyber Security Hub. This saw her create content from webinars to blogs to research reports on all things cybersecurity before finally ending up at Tom&#039;s Guide.&lt;/p&gt;&lt;p&gt;Olivia was also shortlisted for Security Serious&#039; Unsung Heroes award in the Cyber Writer category in 2023.&lt;/p&gt;&lt;p&gt;When not writing about the latest in tech software, Olivia can be found reading mystery novels, watching the X-Files or doing valuable research in her quest to find the best Italian restaurant in London.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9JmTabf9SdZjLaW9muABUj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stock image of a hacker using a computer to infect a server with a virus]]></media:description>                                                            <media:text><![CDATA[A stock image of a hacker using a computer to infect a server with a virus]]></media:text>
                                <media:title type="plain"><![CDATA[A stock image of a hacker using a computer to infect a server with a virus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9JmTabf9SdZjLaW9muABUj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Notorious Russia-based ransomware gang Lockbit 3.0 have claimed responsibility for a cyber attack on the US Federal Reserve.</p><p>The attack, which was announced on June 23 via a post on a site associated with the ransomware gang, allegedly saw the gang infiltrate the systems of the US Federal Reserve and exfiltrate 33 TB of sensitive banking information.</p><p>In the post, which was entitled &apos;federalreserve.gov&apos;, the gang explained how the Federal Reserve is structured, and its role in distributing money across the 12 US banking districts. It also gave the Reserve a 48-hour deadline to fire their "clinical idiot" of a negotiator (Lockbit&apos;s words, not mine) who had apparently valued the worth of America&apos;s banking secrecy at $50,000. The gang demanded the Federal Reserve hire a new one.</p><a href="https://www.redhotcyber.com/en/post/lockbit-3-0-claims-attack-on-federal-reserve-33-terabytes-of-sensitive-data-allegedly-compromised/" rel="nofollow" target="_blank"><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1004px;"><p class="vanilla-image-block" style="padding-top:57.07%;"><img id="fGZ42xs6EMooLYvV84qnTA" name="lockbot federal reserve announcement.jpg" alt="An announcement of the cyber attack on the US Federal Reserve by Lockbit 3.0" src="https://cdn.mos.cms.futurecdn.net/fGZ42xs6EMooLYvV84qnTA.jpg" mos="" align="middle" fullscreen="" width="1004" height="573" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Red Hot Cyber)</span></figcaption></figure></a><p>Lockbit 3.0 is notorious for its aggressive negotiation tactics and its targeting of high-profile organizations. Other recent victims of the ransomware gang include Canadian pharmacy chain London Drugs, the City of Wichita and the Hôpital de Cannes - Simone Veil.</p><p>The attack on the Federal Reserve follows the unmasking by the US Justice System of Russian national Dmitry Khoroshev as the developer, creator and administrator of the ransomware gang.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 280 million at risk from malware-filled Chrome extensions — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/malware-filled-extensions-are-a-chrome-threat-you-cant-ignore-reportedly-installed-by-280-million-over-the-last-three-years</link>
                                                                            <description>
                            <![CDATA[ Malicious browser extensions are a serious threat that can put you, your data and your devices at risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eMPdRJ9DbbWyij8gBNxGC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/62aHxnvmKJvfMzFqKzR96H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Jun 2024 19:57:48 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jun 2024 15:46:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/62aHxnvmKJvfMzFqKzR96H-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[and image of the Google Chrome logo on a laptop]]></media:description>                                                            <media:text><![CDATA[and image of the Google Chrome logo on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[and image of the Google Chrome logo on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/62aHxnvmKJvfMzFqKzR96H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In the same way that you need to be careful when installing new apps on your smartphone, you also have to be cautious when adding <a href="https://www.tomsguide.com/news/millions-under-threat-from-malicious-browser-extensions-what-to-do"><u>new extensions to your browser</u></a>, especially with Google Chrome.</p><p>With a 65% market share worldwide according to <a href="https://gs.statcounter.com/" target="_blank"><u>Statcounter</u></a>, Chrome is the most popular browser by far which makes it the perfect target for hackers and other cybercriminals. While cyberattacks often exploit <a href="https://www.tomsguide.com/computing/online-security/update-chrome-right-now-four-zero-day-flaws-used-by-hackers-have-already-been-patched-this-month"><u>zero-day flaws</u></a> in Google’s browser, there’s an easier way to target Chrome users: <a href="https://www.tomsguide.com/news/hackers-are-stealing-gmail-messages-delete-this-extension-right-now"><u>malicious extensions</u></a>.</p><p>Just like with <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now"><u>malicious apps</u></a>, these bad extensions can contain malware and other threats designed to steal your data as well as your cash. Of the 250,00 extensions on the Chrome Web Store, less than 1% were found to include malware according to a recent <a href="https://security.googleblog.com/2024/06/staying-safe-with-chrome-extensions.html" target="_blank"><u>blog post</u></a> from Google. However, a new research paper is claiming differently. </p><p>Published by researchers from Stanford University and the CISPA Helmholtz Center for Information Security, the <a href="https://arxiv.org/pdf/2406.12710" target="_blank"><u>research paper</u></a> (PDF) claims that 280 million people installed a malware-infected Chrome extension between July 2020 and February 2023.</p><p>Here’s everything you need to know about malicious Chrome extensions and how you can stay safe when adding new extensions to your browser.</p><h2 id="lasting-threats">Lasting threats</h2><p>As reported by <a href="https://www.techspot.com/community/topics/researchers-say-280-million-people-installed-malware-infected-chrome-extensions-over-three-years.286548/" target="_blank"><u>TechSpot</u></a>, the researchers found that over a three year period, 346 million users installed Security-Noteworthy Extensions (SNE). While 63 million of these extensions were policy violations and 3 million were vulnerable, 280 million of these installs actually contained malware. </p><p>Surprisingly, many of these malicious extensions were available to download on the <a href="https://www.tomsguide.com/news/chrome-could-soon-zap-some-of-your-extensions-heres-why"><u>Chrome Web Store</u></a> for quite some time. The malware-filled ones remained on the store for 380 days on average while the ones with vulnerable code stayed up for 1,248 days on average.</p><p>Of these malicious extensions, one called TeleApp was available to download and install for 8.5 years. The extension itself was updated in 2013 before it was finally removed after it was found to contain malware in 2022.</p><p>Normally with apps on the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know"><u>Google Play Store</u></a>, I recommend checking user ratings and reviews to see if they are malicious. However, the researchers found that this doesn’t help when it comes to bad extensions as many of them don’t have any reviews at all. This could indicate that their users don’t know they’re dangerous or that they just didn’t take the time to rate and review them.</p><h2 id="how-to-stay-safe-from-malicious-extensions">How to stay safe from malicious extensions</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1280px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TW6SCjSNtNrvZWTMiZRQmb" name="Google Chrome.png" alt="How to update Google Chrome" src="https://cdn.mos.cms.futurecdn.net/TW6SCjSNtNrvZWTMiZRQmb.png" mos="" align="middle" fullscreen="" width="1280" height="720" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Firmbee.com via Unsplash)</span></figcaption></figure><p>Since checking ratings and reviews on the Chrome Web Store doesn’t seem to work in this case, you’re going to have to look for external reviews to help judge whether or not a browser extension is safe to install. However, as browser extensions rarely get full reviews, there are some other things to keep in mind to stay safe.</p><p>Just like with bad apps, the researchers found that malicious extensions often ask for <a href="https://www.tomsguide.com/news/google-just-reversed-this-major-play-store-change-after-backlash"><u>more permissions</u></a> than they should. If you go to install a new extension and it’s asking for quite a lot of permissions, this can be a major red flag and could be a good indication that it might be malicious.</p><p>Since many malicious extensions contain malware, you’re going to want to use the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>best antivirus software</u></a> on your PC and one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus"><u>best Mac antivirus software</u></a> solutions on your Apple computer. This way, if an extension does contain malware, your antivirus software will be able to catch it before any damage can be done.</p><p>Likewise, before you install any new software or browser extensions, you first need to ask yourself if you really need to. A lot of times, you’ll be able to accomplish the same thing using built-in software or your browser’s own capabilities. If you do need to install an extension for your browser, make sure that it’s from a trusted source or a well-known software provider.</p><p>Since Chrome is the biggest browser after all, hackers will likely keep trying to have their malicious extensions slip past Google’s defenses. The search giant does have a dedicated security team that reviews every Chrome extension to make sure it isn’t malicious though. However, if you want to be extra careful, the fewer browser extensions you have installed the better.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-chrome-word-and-onedrive-errors-to-trick-people-into-installing-malware-how-to-stay-safe">Chrome security alert — this error will open the malware floodgates on your PC</a></li><li><a href="https://www.tomsguide.com/computing/online-security/hackers-have-found-a-clever-way-to-use-emojis-in-their-attacks-but-its-not-what-you-think">Hackers are now using emoji to speed up their cyberattacks</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/urgent-windows-security-flaw-lets-hackers-infect-your-pc-over-wi-fi-update-right-now">Urgent Windows security flaw lets hackers infect your PC over Wi-Fi</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Chrome security alert — clicking this error will open the malware floodgates on your PC ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-chrome-word-and-onedrive-errors-to-trick-people-into-installing-malware-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Hackers are now using fake error messages to trick unsuspecting users into running malicious PowerShell scripts that install malware on their PCs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MCKkstYQ9UbcA7eG26DN2V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/62aHxnvmKJvfMzFqKzR96H-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Jun 2024 15:36:40 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Jun 2024 19:41:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/62aHxnvmKJvfMzFqKzR96H-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[and image of the Google Chrome logo on a laptop]]></media:description>                                                            <media:text><![CDATA[and image of the Google Chrome logo on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[and image of the Google Chrome logo on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/62aHxnvmKJvfMzFqKzR96H-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers love to trick their victims into doing things they wouldn’t do otherwise, and a new <a href="https://www.tomsguide.com/computing/malware-adware/scammers-are-tricking-android-users-into-installing-a-fake-antivirus-app-thats-actually-malware-how-to-stay-safe"><u>malware campaign</u></a> currently making the rounds online is the perfect example of this.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/fake-google-chrome-errors-trick-you-into-running-malicious-powershell-scripts/" target="_blank"><u>BleepingComputer</u></a>, hackers are using fake Google Chrome and Microsoft Word errors to trick potential victims into running malicious PowerShell “fixes” that actually install malware.</p><p>This particular campaign is so effective that multiple hacker groups (including the ones behind <a href="https://www.tomsguide.com/news/fake-chrome-updates-infecting-pcs-with-malware-what-you-need-to-know"><u>ClearFake</u></a>, a new group called ClickFix and the group TA571) are using it in their attacks. </p><p>Here’s everything you need to know about this new malware campaign, and how you can avoid falling victim to the <a href="https://www.tomsguide.com/news/this-social-engineering-trick-can-infect-your-pc-with-malware-what-you-need-to-know"><u>social engineering</u></a> it uses to get you to infect your own Windows PC with malware.</p><h2 id="from-fix-to-fail">From fix to fail</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:986px;"><p class="vanilla-image-block" style="padding-top:56.29%;"><img id="g3B7ekmAX3rWZZHNDD2wuA" name="fake-chrome-error.jpg" alt="Fake Chrome error message" src="https://cdn.mos.cms.futurecdn.net/g3B7ekmAX3rWZZHNDD2wuA.jpg" mos="" align="middle" fullscreen="" width="986" height="555" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Proofpoint)</span></figcaption></figure><p>Just like with previous ClearFake campaigns, this new one uses <a href="https://www.tomsguide.com/news/godfather-malware-is-draining-banking-and-crypto-accounts-what-you-need-to-know"><u>overlays</u></a> to display fake Chrome and Word errors. Potential victims are then prompted to click a copy button which contains a "fix" for these fake errors. This copied code then needs to be pasted into either a Windows Run dialog or a Powershell prompt.</p><p>In a <a href="https://www.proofpoint.com/us/blog/threat-insight/clipboard-compromise-powershell-self-pwn" target="_blank"><u>new report</u></a> highlighting all of the different attack chains used in this campaign, <a href="https://www.tomsguide.com/features/7-easy-ways-to-improve-your-online-security-for-free">Proofpoint</a> explains that <a href="https://www.tomsguide.com/news/hackers-now-spreading-mac-malware-via-fake-browser-updates-dont-fall-for-this"><u>compromised websites</u></a> which load a malicious script hosted on the blockchain using Binance’s Smart Chain contracts are also used to infect vulnerable Windows PCs with malware.</p><p>This script performs several checks before displaying a fake Google Chrome warning that says there’s a problem displaying the webpage in question. From here, a dialog prompts visitors to install a "root certificate" by copying a PowerShell script and then running it in a Windows PowerShell (Admin) console.</p><p>When executed, this PowerShell script performs more checks to make sure that the device in question is a valid target before it downloads additional payloads, including an <a href="https://www.tomsguide.com/news/this-info-stealing-malware-is-hiding-in-downloads-for-popular-apps-how-to-stay-safe"><u>info-stealing malware</u></a>.</p><p>Finally, there’s also an email-based infection chain that uses HTML attachments which resemble Word documents. They prompt potential victims to install a “Word Online” extension to view a document but like the other attack chains used in this campaign, a “fix” involving a PowerShell command also has to be copied and then pasted into PowerShell.</p><p>In this attack chain, the PowerShell command downloads and executes either an MSI file or a VBS script which infects the target PC with either the Matanbuchus or DarkGate malware.</p><h2 id="how-to-stay-safe-from-windows-malware">How to stay safe from Windows malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ynU5BuH6Taj5rNfWw8mmpV" name="LG Gram 17 Pro-5.jpg" alt="LG Gram 17 Pro (2023) review unit on table outdoors running Windows 11" src="https://cdn.mos.cms.futurecdn.net/ynU5BuH6Taj5rNfWw8mmpV.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tom's Guide)</span></figcaption></figure><p>All three of the different attack chains used in this campaign rely on the fact that most Windows users aren’t aware of the dangers associated with running unknown PowerShell commands on their PCs. This is why you should never copy and execute code unless you <em>absolutely</em> know what you’re doing.</p><p>Likewise, you also want to ensure that <a href="https://www.tomsguide.com/news/windows-defender-good-enough-for-new-laptop"><u>Windows Defender</u></a> is enabled and running on your PC as it can catch the malware dropped by these malicious PowerShell scripts. If you want even more protection though, you should also consider using one of the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>best antivirus software</u></a> suites alongside Microsoft’s built-in security tools, especially as they often come with extras like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a>.</p><p>As for campaigns like this one that use overlays to trick potential victims, you want to stop and take a minute to think things over before doing anything online. Hackers often try to <a href="https://www.tomsguide.com/news/unpaid-invoices-are-one-of-the-easiest-ways-scammers-try-and-trick-you-what-to-look-out-for"><u>instill a sense of urgency</u></a> in their attacks to get you to act without thinking. Instead, you should read over any messages carefully and try to look them up online to see whether or not they’re genuine. Even if you don’t find any info online, the best course of action is to do nothing in most cases.</p><p>Overlay attacks are very effective as they often appear as if they’re coming from the software you’re currently using. However, by learning how they work and knowing what to look out for, you can keep your devices and your data safe.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/urgent-windows-security-flaw-lets-hackers-infect-your-pc-over-wi-fi-update-right-now">Urgent Windows security flaw lets hackers infect your PC over Wi-Fi</a></li><li><a href="https://www.tomsguide.com/computing/online-security/hackers-have-found-a-clever-way-to-use-emojis-in-their-attacks-but-its-not-what-you-think">Hackers are now using emoji to speed up their cyberattacks</a></li><li><a href="https://www.tomsguide.com/computing/online-security/scammers-are-impersonating-this-government-agency-to-steal-your-cash-dont-answer-this-call">Scammers are impersonating this government agency to steal your cash</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Urgent Windows security flaw lets hackers infect your PC over Wi-Fi — update right now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/urgent-windows-security-flaw-lets-hackers-infect-your-pc-over-wi-fi-update-right-now</link>
                                                                            <description>
                            <![CDATA[ Microsoft has fixed a bug in the Windows Wi-Fi driver that can be exploited to infect vulnerable PCs with malware over Wi-Fi. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SgLTG2TYx7GcPyZkdBpgPj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ynU5BuH6Taj5rNfWw8mmpV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Jun 2024 17:07:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ynU5BuH6Taj5rNfWw8mmpV-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LG Gram 17 Pro (2023) review unit on table outdoors running Windows 11]]></media:description>                                                            <media:text><![CDATA[LG Gram 17 Pro (2023) review unit on table outdoors running Windows 11]]></media:text>
                                <media:title type="plain"><![CDATA[LG Gram 17 Pro (2023) review unit on table outdoors running Windows 11]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ynU5BuH6Taj5rNfWw8mmpV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers often use <a href="https://www.tomsguide.com/news/hackers-are-now-hiding-malicious-word-documents-in-pdfs-how-to-stay-safe"><u>malicious documents</u></a> or <a href="https://www.tomsguide.com/news/heres-another-big-reason-to-avoid-pirating-content-online"><u>pirated software</u></a> as a means of getting their malware onto vulnerable devices, but a new Windows flaw could let them do so over Wi-Fi.</p><p>As reported by <a href="https://www.forbes.com/sites/daveywinder/2024/06/14/new-wi-fi-takeover-attack-all-windows-users-warned-to-update-now/" target="_blank"><u>Forbes</u></a>, this new Wi-Fi vulnerability (tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30078" target="_blank"><u>CVE-2024-30078</u></a>) affects all versions of Windows, and if exploited, it can be used by an attacker to infect vulnerable PCs with malware.</p><p>The flaw itself has a CVSS score of 8.8 out of 10, and what makes it particularly dangerous is the fact that an attacker doesn’t need physical access to a target system. They do however have to be on the same Wi-Fi network to exploit it.</p><p>Here’s everything you need to know about this new critical flaw along with some tips on how to keep your own Windows PC or laptop safe from hackers.</p><h2 id="making-public-wi-fi-an-even-greater-threat">Making public Wi-Fi an even greater threat</h2><p>In an <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30078" target="_blank"><u>update guide</u></a> on its site, Microsoft confirmed that no special obligations need to be met to exploit this flaw except for the hacker being close to a target and on the same Wi-Fi network. They also don’t have to be authenticated nor do they need access to any settings or files on a victim’s PC.</p><p>To make matters worse, an exploit for this new Wi-Fi flaw doesn’t require any interaction from a potential victim at all. This means that users don’t need to click on a link in a <a href="https://www.tomsguide.com/news/millions-of-duolingo-users-at-risk-from-targeted-phishing-attacks-what-you-need-to-know"><u>phishing email</u></a> or to <a href="https://www.tomsguide.com/news/microsoft-onenote-files-are-once-again-being-used-to-spread-malware-how-to-stay-safe"><u>download a malicious attachment</u></a> for this to work.</p><p>For those working from home or at the office, this type of vulnerability is far less concerning. However, if you often use one of the <a href="https://www.tomsguide.com/best-picks/the-best-windows-laptops"><u>best Windows laptops</u></a> out in public — say at a coffee shop or in the airport — then you’d be more likely to fall victim to an attack exploiting this flaw.</p><p>Though often free, <a href="https://www.tomsguide.com/news/why-you-need-to-use-a-vpn-on-public-wi-fi"><u>public Wi-Fi</u></a> presents its own dangers, even without a flaw like this potentially being used in cyberattacks. This is why I highly recommend using one of the <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>best VPNs</u></a> when connected to public Wi-Fi networks. If you haven’t signed up for one yet or didn’t download its client before your big trip, then you’re going to want to avoid logging into sensitive sites on your laptop like your online banking account when connected to public Wi-Fi. Instead, you should use your phone and your own mobile data plan.</p><p>The good news here is that exploitation of this vulnerability is considered “less likely” by Microsoft. However, now that news about this flaw is out in the open, enterprising hackers could try to develop an exploit for it. The second bit of good news is that Microsoft has already patched this flaw along with 48 other vulnerabilities as part of its <a href="https://msrc.microsoft.com/update-guide/releaseNote/2024-Jun" target="_blank"><u>June 2024 Patch Tuesday</u></a> updates.</p><h2 id="how-to-keep-your-windows-pc-safe-from-malware">How to keep your Windows PC safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:951px;"><p class="vanilla-image-block" style="padding-top:55.84%;"><img id="q2ugp6wXAFJWA74KdKx6hc" name="msoft-defender-lptp-shst.jpg" alt="The Microsoft Defender Antivirus, aka Windows Defender, logo on the display of a laptop sitting on a table or desk." src="https://cdn.mos.cms.futurecdn.net/q2ugp6wXAFJWA74KdKx6hc.jpg" mos="" align="middle" fullscreen="" width="951" height="531" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: monticello/Shutterstock)</span></figcaption></figure><p>Just like with your smartphone, the easiest and simplest way to avoid falling victim to malware on your Windows PC is to keep your machine updated and running the latest software. Microsoft releases new security updates on the second Tuesday of every month and you can use this timeline for when to update your desktop or laptop.</p><p>From here, you should ensure that <a href="https://www.tomsguide.com/news/windows-defender-good-enough-for-new-laptop"><u>Windows Defender</u></a> is enabled on your computer. This <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html#the-best-free-antivirus-software"><u>free antivirus software</u></a> from Microsoft has really improved over the years and it now does a great job of catching the latest threats before they can do damage to your PC. For even more protection though, you should consider signing up for one of the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>best antivirus software</u></a> solutions. Paid antivirus software is usually updated more regularly, plus you often get access to a VPN, <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a> and other extras to help you stay safe online.</p><p>New vulnerabilities like the one described above crop up fairly often, but if you stay on top of things and update your PC regularly, your devices and your data should be safe from any attacks exploiting them.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/hackers-have-found-a-clever-way-to-use-emojis-in-their-attacks-but-its-not-what-you-think">Hackers are now using emoji to speed up their cyberattacks</a></li><li><a href="https://www.tomsguide.com/features/how-to-use-a-vpn-to-stay-safe-on-public-wi-fi">How to use a VPN to stay safe on public Wi-Fi</a></li><li><a href="https://www.tomsguide.com/computing/online-security/scammers-are-impersonating-this-government-agency-to-steal-your-cash-dont-answer-this-call">Scammers are impersonating this government agency to steal your cash</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers target job hunters with dangerous new Windows backdoor — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-target-job-hunters-with-dangerous-new-windows-backdoor-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Looking for a new job now requires an antivirus ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LL75hzuMa2Ch5rVAWtGYDe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Jun 2024 16:27:18 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Jun 2024 16:27:22 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Looking for a new job is hard enough as it is but now hackers are using a <a href="https://www.tomsguide.com/news/new-paypal-phishing-campaign-is-stealing-credit-card-info-what-you-need-to-know"><u>phishing campaign</u></a> to infect job seekers with a new Windows-based backdoor.</p><p>As reported by <a href="https://thehackernews.com/2024/06/new-phishing-campaign-deploys.html" target="_blank"><u>The Hacker News</u></a>, the backdoor in question has been dubbed WARMCOOKIE by researchers at the cybersecurity firm Elastic Security Labs. According to a <a href="https://www.elastic.co/security-labs/dipping-into-danger" target="_blank"><u>new report</u></a>, it’s used to “scout out victim networks and deploy additional payloads.”</p><p>Once installed on a victim’s PC, the backdoor can fingerprint infected machines, capture screenshots and drop other <a href="https://www.tomsguide.com/news/this-windows-malware-is-stealing-passwords-and-other-data-how-to-stay-safe"><u>Windows malware</u></a> onto their system. </p><p>Here’s everything you need to know about this new Windows backdoor and how you can stay safe when looking for a new job online.</p><h2 id="warmcookie-backdoor">WARMCOOKIE backdoor</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YwKRVzwvLwup6hDGh5bVNM" name="RzdqY6hhVUXJjJYEgfCrVe.jpg" alt="A hacker typing quickly on a keyboard" src="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>This campaign began at the end of April and uses emails that claim to come from recruitment firms such as Hays, Michael Page and PageGroup in its attack chain. These emails try to entice recipients into clicking on an embedded link to view additional details about a job opportunity.</p><p>If a potential victim does click on the link contained in these emails, they are then told to download a document by solving a CAPTCHA challenge. Doing so drops a malicious JavaScript file on their PC. It’s worth noting that this campaign uses compromised websites to host its initial phishing URLs which are then used to redirect potential victims to <a href="https://www.tomsguide.com/computing/malware-adware/12-million-people-fooled-by-fake-midjourney-facebook-page-used-to-spread-malware-dont-fall-for-this"><u>malicious landing pages</u></a>.</p><p>According to Elastic, this obfuscated script runs PowerShell and loads the WARMCOOKIE backdoor onto their PC. The backdoor follows a two-step process which allows for it to <a href="https://www.tomsguide.com/news/hackers-are-using-fake-chrome-updates-to-spread-malware-dont-fall-for-this"><u>establish persistence</u></a> on the now compromised PC but before doing so, it performs anti-analysis checks to avoid being detected.</p><p>Besides capturing information from the infected PC, WARMCOOKIE can also read and write to files, execute commands using cmd.exe, compile a list of installed applications and capture screenshots. </p><p>This backdoor doesn’t use automation to install malware onto a Windows PC. Instead, it walks victims through a number of different prompts that hide the intentions of the hackers behind this campaign that ultimately results in their computer being compromised and infected with malware.</p><h2 id="how-to-stay-safe-from-windows-malware-xa0">How to stay safe from Windows malware </h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:59.20%;"><img id="zM65k9LRHzNjagpMSF4e5j" name="Bitdefender-Spying-IoT.jpg" alt="Laptop showing security lock on screen" src="https://cdn.mos.cms.futurecdn.net/zM65k9LRHzNjagpMSF4e5j.jpg" mos="" align="middle" fullscreen="" width="1000" height="592" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Windows malware comes in many different forms but fortunately, the steps you can take to keep you and your PC safe remain the same across different malware strains.</p><p>For starters, you want to ensure that <a href="https://www.tomsguide.com/news/windows-defender-good-enough-for-new-laptop"><u>Windows Defender</u></a> is enabled and up to date. This <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html#the-best-free-antivirus-software"><u>free antivirus software</u></a> comes pre-installed on all Windows 10 and Windows 11 PCs in the same way that Apple includes its own <a href="https://www.tomsguide.com/news/macos-is-getting-even-better-at-scanning-for-malware-heres-how"><u>X-Protect</u></a> antivirus software with macOS. For additional protection though and some useful extras like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a>, you should also consider installing one of the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>best antivirus software</u></a> suites to run alongside it.</p><p>From here, you want to be extra careful when checking your inbox. This involves carefully scrutinizing senders’ email addresses to make sure they are legitimate and avoiding downloading any attachments or clicking on links from unknown senders. Hackers use malicious documents and other <a href="https://www.tomsguide.com/news/hackers-are-using-this-new-gmail-scam-to-steal-your-personal-data-how-to-stay-safe"><u>bogus attachments</u></a> as an entryway into your PC, so if you don’t know the sender, you should avoid downloading anything that’s sent to you.</p><p>As for staying safe during a job hunt, you want to stick to established and trusted sites and services like Indeed, LinkedIn, ZipRecruiter, Monster and GlassDoor. Likewise, if possible, you should try to use your existing connections to see if there are any new positions or opportunities available before heading to a job site to look for work.</p><p>WARMCOOKIE may be a newly discovered backdoor but it is quickly gaining popularity among hackers and other cybercriminals as it provides an easy way to infect vulnerable PCs with other types of malware. As such, this likely isn’t the last time that we’ll hear about this particular backdoor being used in cyberattacks.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/huge-frontier-hack-exposed-personal-info-of-750000-customers-including-social-security-numbers">Frontier hack exposed personal info of 750,000 customers including SSNs</a></li><li><a href="https://www.tomsguide.com/computing/online-security/lightspy-spyware-can-now-snoop-on-your-mac-and-your-iphone-how-to-protect-yourself">LightSpy spyware can now snoop on your Mac and your iPhone</a></li><li><a href="https://www.tomsguide.com/computing/online-security/massive-ticketmaster-data-breach-reportedly-hits-over-500-million-customers-what-to-do-now">Over 500 million hit in massive Ticketmaster data breach — what to do now</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 90+ malicious Android apps with 5.5m installs found spreading malware on the Play Store — protect yourself now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now</link>
                                                                            <description>
                            <![CDATA[ Malicious apps have been found distributing the Anatsa banking trojan on the Play Store to drain Android users’ bank accounts. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CsNMhARjQxtXc5efsQ6ZH7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 May 2024 22:17:18 +0000</pubDate>                                                                                                                                <updated>Thu, 30 May 2024 03:30:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:description>                                                            <media:text><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Bad apps can wreak havoc on the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a><u>,</u> which is why you always need to be careful when installing new ones. However, even when you download new software via the <a href="https://www.tomsguide.com/news/hackers-are-sneaking-malware-on-to-the-google-play-store-how-to-stay-safe"><u>Google Play Store</u></a> there’s still a chance that you could end up with a malicious app on your phone.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/over-90-malicious-android-apps-with-55m-installs-found-on-google-play/" target="_blank"><u>BleepingComputer</u></a>, the cybersecurity firm <a href="https://www.tomsguide.com/news/this-insidious-malware-is-hijacking-facebook-accounts-protect-yourself-now">Zscaler</a> has revealed that it has discovered more than 90 <a href="https://www.tomsguide.com/computing/malware-adware/these-malicious-android-malware-apps-were-downloaded-150000-times-from-the-play-store-delete-them-right-now"><u>malicious apps</u></a> on Google Play which were collectively installed 5.5 million times.</p><p>While the firm hasn’t provided the names of most of these malicious apps, we do know that many of them impersonated productivity, personalization and health & fitness apps along with other utilities.</p><p>Here’s everything you need to know about this latest batch of bad apps including the names of two of them that you need to remove immediately if they’re installed on your Android devices.</p><h2 id="delete-these-apps-right-now-2">Delete these apps right now</h2><p>As I mentioned before, Zscaler has yet to release the full list of the 90+ malicious apps it discovered over the past few months. However, it did provide info on two particularly dangerous apps in a <a href="https://www.zscaler.com/blogs/security-research/technical-analysis-anatsa-campaigns-android-banking-malware-active-google" target="_blank"><u>new report</u></a> that you should delete immediately if you have them installed:</p><ul><li><strong>PDF Reader & File Manager</strong> by TSARKA Watchfaces</li><li><strong>QR Reader & File Manager</strong> by risovanul</li></ul><p>Fortunately, both of these apps have been removed from the Google Play Store and are no longer available for download. However, if you have them installed on your Android phone or tablet, you’re going to need to manually uninstall them.</p><h2 id="dropper-apps-hiding-in-plain-sight">Dropper apps hiding in plain sight</h2><p>As we’ve seen in the past, bad apps can slip through the cracks and end up on the Google Play Store. Both of the apps listed above are what’s known as malware droppers and according to Zscaler, together they’ve been installed 70,000 times combined.</p><p>These dropper apps are able to bypass Google’s rigorous security checks as they don’t contain malware when uploaded to the Play Store. Instead, the apps communicate with a hacker-controlled command and control (<a href="https://www.tomsguide.com/news/move-over-joker-harly-malware-infects-millions-of-android-phones">C&C</a>) server after installation to download malware.</p><p>In this case, both of these utility apps are being used to infect vulnerable Android phones with the <a href="https://www.tomsguide.com/news/dangerous-android-trojan-can-drain-your-bank-accounts-how-to-stay-safe"><u>Anatsa banking trojan</u></a>. This Android malware targets over 650 banking apps in the US, the UK, Europe and Asia in order to steal their financial credentials. In fact, during a malware campaign late last year, Anatsa was able to infect 150,000 Android phones through Google Play using bad apps.</p><p>Just like with other banking trojans, Anatsa uses <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts">overlay attacks</a> to steal your banking credentials. These overlays are actually fake websites designed to mimic the look and feel of the login pages of popular banking apps. However, instead of logging into your account, you’re also giving hackers your username and password.</p><p>Anatsa can also commit on-device fraud by launching banking apps on its own and performing transactions on behalf of victims. Not only does this save the hackers time but it also improves their chances of success since someone logging into their account on their own device doesn’t raise nearly as much suspicion as it would on a different Android phone.</p><h2 id="how-to-stay-safe-from-malicious-apps">How to stay safe from malicious apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>In order to stay safe from this and other Android malware strains, you’re going to want to <a href="https://www.tomsguide.com/news/60-android-apps-with-100-million-installs-actually-contain-malware-delete-them-right-now"><u>limit the number of apps</u></a> on your phone. Even seemingly innocent apps can be used to drop malware onto your device which is why you really want to ask yourself whether or not you need a particular app before downloading and installing it.</p><p>For this reason, you want to stick to bigger, more widely known app developers that have a history of putting out good software. Likewise, you’re much less likely to come across malware when going with paid apps as opposed to free ones. Before installing any app, you also want to check its rating and reviews but as these can be faked, it’s a good idea to look for video reviews online so that you can see the app in question in action before you download it.</p><p>To protect yourself and your devices from malware, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled on your phone as it can scan all of your existing apps and any new ones you download for malware. For additional protection and some useful extras like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or even a <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a>, you might also want to look into running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside it.</p><p>In an email to Tom&apos;s Guide, a Google spokesperson provided further insight on these malicious apps, saying:<br><br> “All of the identified malicious apps have been removed from Google Play. Google Play Protect also protects users by automatically removing or disabling apps known to contain this malware on Android devices with Google Play Services.”</p><p>Hopefully Zscaler releases the full list of the 90+ malicious apps it has discovered over the past few months. Even if it doesn’t though, this new Anatsa campaign serves as the perfect reminder that you always need to be careful when downloading and installing new software even when it’s from official app stores.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-banking-trojan-uses-fake-google-play-updates-to-take-over-your-phone-how-to-stay-safe">Android banking trojan uses fake Google Play updates to take over your phone</a></li><li><a href="https://www.tomsguide.com/computing/online-security/massive-ticketmaster-data-breach-reportedly-hits-over-500-million-customers-what-to-do-now">Massive Ticketmaster data breach reportedly hits over 500 million customers</a></li><li><a href="https://www.tomsguide.com/computing/online-security/hackers-have-leaked-the-criminal-records-of-millions-of-americans-online-how-to-stay-safe">Hackers have leaked the criminal records of millions of Americans online</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new Android banking trojan uses fake Google Play updates to take over your phone — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-banking-trojan-uses-fake-google-play-updates-to-take-over-your-phone-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Hackers are using the new Antidot banking trojan to steal text messages, passwords and more from vulnerable Android phones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dAd7G4Vh7Le4fop9tXS3uL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 May 2024 20:30:19 +0000</pubDate>                                                                                                                                <updated>Wed, 29 May 2024 19:38:50 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware on phone]]></media:description>                                                            <media:text><![CDATA[Android malware on phone]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Keeping your mobile devices and their apps updated is one of the most important things you can do to stay safe from the latest cyber threats. However, as hackers are aware of this too, they often use fake updates as a means to infect your devices with malware, as is the case with a new <a href="https://www.tomsguide.com/news/dangerous-android-trojan-can-drain-your-bank-accounts-how-to-stay-safe"><u>Android banking trojan</u></a> currently making the rounds online.</p><p>According to a <a href="https://cyble.com/blog/new-antidot-android-banking-trojan-masquerading-as-google-play-updates/" target="_blank"><u>blog post</u></a> from the cybersecurity firm <a href="https://www.tomsguide.com/news/godfather-malware-is-draining-banking-and-crypto-accounts-what-you-need-to-know"><u>Cyble</u></a>, its researchers have discovered a new Android banking Trojan called Antidot, not to be confused with the <a href="https://www.tomsguide.com/computing/malware-adware/new-brokewell-malware-targets-android-users-with-fake-google-chrome-updates"><u>Brokewell malware</u></a> the team discovered last month.</p><p>Once installed on one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a>, the Antidot malware can collect contacts and text messages, harvest credentials, lock and unlock the device, forward calls and more which is why this new banking trojan is so dangerous.</p><p>Here’s everything you need to know about the Antidot banking trojan along with some steps you can take to keep your own Android phone safe from this and other malware strains.</p><h2 id="impersonating-google-play">Impersonating Google Play</h2><p><a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know"><u>Google Play</u></a> is one of the most important apps on your Android phone, as it’s where you download new apps from as well as updates for your existing apps. It’s the kind of app you definitely want to keep up to date, which is why the hackers behind this campaign have decided to impersonate it.</p><p>Like with other malware campaigns, this one uses <a href="https://www.tomsguide.com/news/this-fake-text-message-from-amazon-can-steal-your-account-dont-fall-for-this-nasty-phishing-scam"><u>phishing messages</u></a> to trick users into installing it. Unsuspecting users may receive an email — or more likely a text message — that appears to come from Google telling them they need to update Google Play. The message also contains a <a href="https://www.tomsguide.com/computing/malware-adware/this-android-malware-can-steal-all-your-photos-and-texts-without-being-opened-how-to-stay-safe"><u>malicious link</u></a> that leads them to the malware itself which needs to be sideloaded as an APK file.</p><p>What’s particularly interesting about this campaign is that the fake Google Play update pages it uses have been crafted in several different languages including English, German, French, Spanish, Russian, Portuguese and Romanian. This lets the hackers behind the Antidot banking trojan target a wide range of Android users from multiple countries at the same time without having to tweak the campaign itself for each country.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1507px;"><p class="vanilla-image-block" style="padding-top:56.27%;"><img id="mQHrh4jw9nwgDWuCeL7Voe" name="antidot.jpg" alt="Screenshots showing how the Antidot malware impersonates Google Play" src="https://cdn.mos.cms.futurecdn.net/mQHrh4jw9nwgDWuCeL7Voe.jpg" mos="" align="middle" fullscreen="" width="1507" height="848" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Cyble)</span></figcaption></figure><p>Once installed, the malware displays another fake update page that’s used to trick victims into giving it access to Android’s <a href="https://www.tomsguide.com/news/android-13-security-feature-designed-to-stop-malware-has-already-been-bypassed">Accessibility Settings</a>. Getting access to these services is what allows Antidot to gain complete control over a vulnerable Android smartphone as they can be abused to see what’s on a victim’s screen as well as to interact with their apps and other data.</p><h2 id="from-overlay-attacks-to-keylogging">From overlay attacks to keylogging</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="RR5n2TRGVvqndr24zaEoCn" name="shutterstock_2149145387 .jpg" alt="A picture depicting how banking trojans steal credit card data" src="https://cdn.mos.cms.futurecdn.net/RR5n2TRGVvqndr24zaEoCn.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The Antidot malware and other banking trojans make use of a hacker-controlled Command and Control (<a href="https://www.tomsguide.com/news/move-over-joker-harly-malware-infects-millions-of-android-phones"><u>C&C</u></a>) server to carry out their malicious actions. This server lets the hackers communicate directly with an infected device and tell the malware what to do.</p><p>From here, the Antidot malware has a total of 35 different commands it can perform from unlocking an infected device to making calls, collecting and sending text messages, sending out push notifications, locking the device and more. This banking trojan can also copy text from an infected phone’s clipboard.</p><p>In order to steal passwords and other credentials though, Antidot uses overlay attacks in a similar way to other popular banking trojans like <a href="https://www.tomsguide.com/news/look-out-this-android-malware-can-take-over-your-banking-and-crypto-accounts"><u>Ermac</u></a>, <a href="https://www.tomsguide.com/news/new-chameleon-banking-trojan-is-stealing-account-info-what-you-need-to-know"><u>Chameleon</u></a> and Brokewell. For those unfamiliar with <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts"><u>overlay attacks</u></a>, here’s how they work. When you open a banking app on your phone, the malware loads an HTML phishing page that’s designed to look just like that particular app and this page is overlaid on top. Then when you enter your credentials to log in, they are captured by hackers who can then drain your bank account, commit fraud or even steal your identity with enough info.</p><p>If there are banking or other financial apps that the malware doesn’t have an overlay ready for, keylogging is used to capture everything a victim types on an infected Android smartphone including their passwords.</p><h2 id="how-to-stay-safe-from-android-malware-9">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Android malware like Antidot can be very dangerous since so much personal and financial information is now stored on our phones. However, by taking the right steps and implementing certain safeguards, you can avoid falling victim to it.</p><p>For starters, you only want to install new apps from the Google Play Store or other official app stores like the Amazon Appstore or the Samsung Galaxy Store. While convenient and fast, <a href="https://www.tomsguide.com/news/over-60000-compromised-android-apps-found-spreading-adware-how-to-stay-safe"><u>sideloading apps</u></a> puts you and your devices at risk, so it’s best to avoid this altogether.</p><p>At the same time, you want to avoid clicking on any links in emails or text messages sent from unknown senders to your smartphone. Hackers will often send messages that try to instill a <a href="https://www.tomsguide.com/news/this-new-phishing-scam-can-steal-your-social-security-number-how-to-stay-safe"><u>sense of urgency</u></a> with a link for you to click at the bottom. If you read through the message and get worked up about what it says, like how you need to update Google Play immediately in this case, you’re more likely to click on the link and do exactly what the hackers want you to. Also keep in mind that hackers can pose as your friends and family to trick you as well, like we saw with the recent ‘<a href="https://www.tomsguide.com/news/look-who-died-scam-is-making-the-rounds-on-facebook-dont-fall-for-this"><u>Look who died</u></a>’ scam on social media.</p><p>To stay safe from Android malware, you should make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled on your smartphone. This free antivirus app from Google scans all of your existing apps and any new ones you download for malware. However, for additional protection and access to some useful extras like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a>, you should also consider downloading one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a>.</p><p>Due to how much data and money they can bring in for hackers, banking trojans aren’t going anywhere anytime soon. This is why it’s up to you to carefully examine the messages you receive and practice good cyber hygiene.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/massive-ticketmaster-data-breach-reportedly-hits-over-500-million-customers-what-to-do-now">Massive Ticketmaster data breach reportedly hits over 500 million customers — what to do now</a></li><li><a href="https://www.tomsguide.com/computing/online-security/update-chrome-right-now-four-zero-day-flaws-used-by-hackers-have-already-been-patched-this-month">Update Chrome right now — four zero-day flaws have already been patched this month</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/scammers-are-tricking-android-users-into-installing-a-fake-antivirus-app-thats-actually-malware-how-to-stay-safe">Scammers are tricking Android users into installing a fake antivirus app to drain their accounts</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Android malware is stealing passwords by impersonating popular apps like Instagram and Snapchat — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-android-malware-is-stealing-passwords-by-impersonating-popular-apps-like-instagram-and-snapchat-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ The malicious app used in this new malware campaign hides in plain sight by using the logos, names and icons of other popular apps and services. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8D4aQnZ8kde4bcMePv4Ry6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 11 May 2024 04:45:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:description>                                                            <media:text><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are now using a combination of <a href="https://www.tomsguide.com/news/these-35-malicious-android-apps-have-infected-millions-delete-them-now"><u>malicious apps</u></a> and <a href="https://www.tomsguide.com/news/6000-sites-used-to-impersonate-100-top-brands-and-steal-your-banking-info-how-to-stay-safe"><u>brand impersonation</u></a> to steal the passwords and other sensitive data of unsuspecting Android users.</p><p>As reported by <a href="https://thehackernews.com/2024/05/malicious-android-apps-pose-as-google.html" target="_blank"><u>The Hacker News</u></a>, a new malware campaign has been spotted online in which malicious Android apps pose as Google, Instagram, Snapchat, WhatsApp, X and other popular online services in a bid to harvest contacts, text messages, call logs and of course, passwords from vulnerable Android phones.</p><p>Although security researchers at SonicWall’s Capture Labs team know quite a bit about this new campaign so far, they aren’t quite sure how the malicious apps used in it end up on the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a>. However, these fake apps could be spread on <a href="https://www.tomsguide.com/news/hackers-often-use-this-clever-trick-to-take-you-to-phishing-sites-can-you-spot-it"><u>phishing sites</u></a>, through emails or text messages or they may even come bundled with <a href="https://www.tomsguide.com/news/nullmixer-malware-spies-on-you-and-steals-your-online-accounts-what-you-need-to-know"><u>pirated software</u></a>.</p><p>While we’ll likely learn more regarding the intricacies of this campaign and the hackers behind it once SonicWall does, in the meantime, here’s everything you need to know to avoid getting a nasty malware infection on your own Android phone as the result of a malicious app. </p><h2 id="from-a-fake-app-to-fake-login-pages">From a fake app to fake login pages</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1796px;"><p class="vanilla-image-block" style="padding-top:56.24%;"><img id="GmaDFHSzhCytn2AsEvFTa6" name="fake instagram app.jpg" alt="A series of screenshots depicting a malicious app impersonating Instagram on Android" src="https://cdn.mos.cms.futurecdn.net/GmaDFHSzhCytn2AsEvFTa6.jpg" mos="" align="middle" fullscreen="" width="1796" height="1010" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: SonicWall)</span></figcaption></figure><p>According to a <a href="https://blog.sonicwall.com/en-us/2024/04/android-remote-access-trojan-equipped-to-harvest-credentials/" target="_blank"><u>blog post</u></a> from SonicWall, once the malicious app used to distribute this malware is installed on a victim’s phone, it then uses famous Android app icons from popular apps and online services to hide in plain sight.</p><p>When the malicious app is opened for the first time which could easily happen by mistake as it’s impersonating another app, it requests access to two permissions: <a href="https://www.tomsguide.com/news/this-new-android-malware-can-unlock-your-phone-and-drain-your-bank-accounts-how-to-stay-safe"><u>Android Accessibility Service</u></a> and Device Admin Permission. If a potential victim grants the app access to these sensitive permissions, it can then take control over their phone and steal sensitive data from it without their knowledge.</p><p>The malicious app in question then establishes a connection with a hacker-controlled command and control (<a href="https://www.tomsguide.com/news/move-over-joker-harly-malware-infects-millions-of-android-phones"><u>C&C</u></a>) server from which it receives additional instructions. For instance, the malicious app can be used to read messages, read call logs, access notification data, send messages and worst of all, open <a href="https://www.tomsguide.com/news/these-misspelled-websites-are-spreading-nasty-malware-how-to-stay-safe"><u>malicious websites</u></a> in a victim’s browser for the purpose of phishing.</p><p>Essentially, the way in which this malicious app and the malware it contains harvest credentials from victims is by taking them to <a href="https://www.tomsguide.com/news/dont-click-on-that-email-from-instagram-support-its-a-fake"><u>fake login pages</u></a> for sites such as Instagram, PayPal, Netflix, Microsoft, WordPress, LinkedIn, ProtonMail, Yahoo and more. They are then prompted to enter their username and password which is stored and then relayed back to the hackers behind this campaign. </p><p>From there, they can then take over their online accounts and commit fraud or possibly even <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html"><u>identity theft</u></a> if enough of their sensitive, personal information is contained in one of these services. For instance, if they got a victim’s Microsoft credentials and they use OneDrive to store copies of their driver’s license, passport or even their <a href="https://www.tomsguide.com/us/what-to-do-ssn-stolen,news-18742.html">Social Security number</a> (a terrible idea but some people still do), the hackers could cause some serious trouble.</p><h2 id="how-to-stay-safe-from-android-malware-10">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Since we aren’t entirely sure how this particular malware-filled app is being spread, the best I can do is to give you some overall guidance when it comes to protecting yourself from Android malware.</p><p>Google has taken a lot of precautions over the years to significantly decrease the chances of malicious apps ending up on <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know"><u>Play Store</u></a>. However, you still need to be careful when downloading any new app onto your Android phone. You want to check an app’s ratings, reviews and if possible, look for a video review online so that you can see the app in question.</p><p>Normally with malicious apps though, they are often <a href="https://www.tomsguide.com/news/this-android-malware-installs-backdoor-on-your-phone-delete-these-malicious-apps-now"><u>sideloaded onto a victim’s smartphone</u></a>. Surprisingly, this is often done by the victim themselves after being coerced into doing so by a hacker, scammer or some other type of cybercriminal. This is why you need to be extremely wary when someone tells you to install an app in either a text message, email or on social media. If the app isn’t available on a first party app store and needs to be downloaded as an APK file and then installed manually, this is a big red flag and you should avoid it at all costs.</p><p>To prevent malicious apps from being installed on your Android phone in the first place, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled as this pre-installed security app scans all of your existing apps and any new ones you download for malware. If you want to be extra careful though, you should also consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> alongside it.</p><p>We may not learn more about this particular campaign but at least now, you know that malicious apps can change their icons to hide in plain sight. Sometimes they do this by pretending to be system apps like contacts or settings or in this case, by impersonating popular apps using their logos and names. Since campaigns like this one can be so effective though, we likely won’t see hackers drop this tactic from their arsenal anytime soon.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-wpeeper-android-malware-adds-a-backdoor-to-your-phone-to-steal-your-data-how-to-stay-safe">Wpeeper Android malware adds a backdoor to your phone to steal your data</a></li><li><a href="https://www.tomsguide.com/news/heres-another-big-reason-to-avoid-pirating-content-online">Here’s another big reason to avoid pirating content and software online</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/scammers-are-tricking-android-users-into-installing-a-fake-antivirus-app-thats-actually-malware-how-to-stay-safe">Scammers are tricking Android users with a fake antivirus app that can drain bank accounts</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers are tricking Android users into installing a fake antivirus app that can drain bank accounts — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/scammers-are-tricking-android-users-into-installing-a-fake-antivirus-app-thats-actually-malware-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ New social engineering campaign uses text messages to trick victims into calling scammers who then have them install a malware-filled app on their phone. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x3UqZqdG8DCg5uuKXethCg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 May 2024 21:56:00 +0000</pubDate>                                                                                                                                <updated>Wed, 08 May 2024 14:26:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new <a href="https://www.tomsguide.com/news/this-android-malware-installs-backdoor-on-your-phone-delete-these-malicious-apps-now"><u>Android malware</u></a> campaign is using <a href="https://www.tomsguide.com/news/this-social-engineering-trick-can-infect-your-pc-with-malware-what-you-need-to-know"><u>social engineering</u></a> and several other tricks to dupe unsuspecting users into installing malware capable of draining their bank accounts.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/finland-warns-of-android-malware-attacks-breaching-bank-accounts/" target="_blank"><u>BleepingComputer</u></a>, this particular campaign currently only affects users of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html"><u>best Android phones</u></a> in Finland. However, it’s still a great example of the types of tactics and means hackers use to trick people into installing <a href="https://www.tomsguide.com/computing/malware-adware/these-malicious-android-malware-apps-were-downloaded-150000-times-from-the-play-store-delete-them-right-now"><u>malicious apps</u></a>.</p><p>According to Finland’s Transport and Communications Agency (<a href="https://www.kyberturvallisuuskeskus.fi/fi/ajankohtaista/kyberturvallisuuskeskuksen-viikkokatsaus-182024" target="_blank"><u>Traficom</u></a>), this attack begins with a text message that instructs the recipient to call a phone number. When they do, they are then instructed by a scammer on the other end to install a McAfee app for protection.</p><p>While you should never install any app someone coerces you to over the phone, the initial text messages in this campaign appeared to come from either banks or payment service providers using <a href="https://www.tomsguide.com/news/hackers-often-use-this-clever-trick-to-take-you-to-phishing-sites-can-you-spot-it"><u>spoofing technology</u></a> to make this request appear more legitimate.</p><p>Here’s everything you need to know about this new malware campaign and how you can avoid falling victim to it and others like it.</p><h2 id="sideloading-malware">Sideloading malware</h2><p>Instead of coming from the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know"><u>Google Play Store</u></a> or another official app store, this fake McAfee app arrives as an Android APK file which needs to be <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps"><u>sideloaded</u></a> onto a victim’s phone. This is a major red flag and a clear giveaway that this is a scam since no bank or financial service provider would ever ask its customers to sideload an app.</p><p>Still though, many Finish users have fallen to this scam with Traficom reporting that one victim lost over $100,000. In fact, this scam has gotten so bad that the financial service provider OP Financial Group published a separate alert on its website warning its customers about text messages impersonating banks or national authorities.</p><p>While the Finnish authorities didn’t name the malware strain being used in this campaign, BleepingComptuer noticed that it resembled a recent <a href="https://www.tomsguide.com/computing/malware-adware/this-nasty-android-banking-trojan-lets-hackers-completely-hijack-your-phone-how-to-stay-safe"><u>Vultur banking trojan</u></a> campaign from earlier this year.</p><p>This new Vultur variant uses a combination of <a href="https://www.tomsguide.com/news/this-fake-text-message-from-amazon-can-steal-your-account-dont-fall-for-this-nasty-phishing-scam"><u>smishing</u></a> (phishing over SMS) and <a href="https://www.tomsguide.com/news/that-emergency-phone-call-from-a-loved-one-could-actually-be-scammers-using-ai-how-to-stay-safe"><u>phone call attacks</u></a> to convince potential victims to download a fake McAFee Security app. Sound familiar? It should as this is almost the exact same attack scenario used in this new campaign.</p><p>For those who may have accidentally installed this malicious app posing as McAFee, you should call your bank immediately to enable protective measures and restore your compromised Android phone to its factory settings. You will lose all of your apps and other data but doing so will wipe the malware from your phone.</p><h2 id="how-to-stay-safe-from-android-malware-11">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Android malware has the potential to completely upend your life if you’re not careful. This is why you want to be extremely cautious when installing any new app onto your smartphone.</p><p>Besides not sideloading apps, you also want to check the ratings and reviews of any app you download from the Google Play Store or other official Android app stores like the Samsung Galaxy Store or Amazon Appstore for that matter. Since reviews and ratings can be faked, I always recommend that you also look for video reviews so that you can see the app in question in action before installing it.</p><p>When you do install a new app, pay careful attention to the permissions it requests. Malicious apps spreading malware often request access to <a href="https://www.tomsguide.com/news/these-predatory-loan-apps-have-been-installed-over-15-million-times-delete-them-now"><u>unnecessary permissions</u></a> as a means to gain access over your phone. For instance, a simple utility app like a calculator doesn’t need access to your photos or the ability to see your contacts. As for which permissions are an immediate red flag, <a href="https://www.tomsguide.com/news/look-out-this-android-malware-can-take-over-your-banking-and-crypto-accounts"><u>Accessibility Services</u></a> is a permission that’s often abused by malicious apps as it gives the hackers behind them near total control of your phone.</p><p>As it comes pre-installed on most Android phones, you also want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled as it scans all of your existing apps and any new ones you download for malware. For extra protection though, you might also want to consider installing one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a> as they often come with additional security features like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a>.</p><p>Scammers and hackers are going to keep coming up with clever new ways to infect users with malware as companies like Google and law enforcement agencies grow wise to their tricks. As such, it’s up to you to be careful online and not let your emotions get the best of you when dealing with text messages or other communications sent from unknown senders or even people posing as someone they’re not.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-wpeeper-android-malware-adds-a-backdoor-to-your-phone-to-steal-your-data-how-to-stay-safe">Wpeeper Android malware adds a backdoor to your phone to steal your data</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-apps-to-distribute-this-dangerous-mac-malware-dont-fall-for-this">Hackers are using fake apps to distribute this dangerous Mac malware</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/new-cuckoo-macos-malware-can-take-over-all-macs-and-steals-your-passwords-too-dont-fall-for-this">Cuckoo macOS malware can take over all Macs and steals your passwords too</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Cuckoo macOS malware can take over all Macs and steals your passwords too — don’t fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-cuckoo-macos-malware-can-take-over-all-macs-and-steals-your-passwords-too-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ The Cukcoo malware goes after both Intel-based Macs and newer Macs running Apple Silicon to spy on users and steal their passwords. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YB7htQvyVZ4FpPXvvBXreJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Mqn4Ck4BndEpuKXAY6ofyE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 May 2024 17:19:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Mqn4Ck4BndEpuKXAY6ofyE-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MacBook Air 15-inch M2 on a bench]]></media:description>                                                            <media:text><![CDATA[MacBook Air 15-inch M2 on a bench]]></media:text>
                                <media:title type="plain"><![CDATA[MacBook Air 15-inch M2 on a bench]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Mqn4Ck4BndEpuKXAY6ofyE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are using a new <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-by-malicious-info-stealing-malware-spread-through-ads-and-fake-software-dont-fall-for-this"><u>Mac malware</u></a> to launch attacks against both newer Macs running Apple Silicon as well as older Intel-based Macs.</p><p>As reported by <a href="https://thehackernews.com/2024/05/new-cuckoo-persistent-macos-spyware.html?m=1" target="_blank"><u>The Hacker News</u></a>, the malware in question has been dubbed Cuckoo by security researchers at the device management company Kandji. Besides targeting both newer and older Macs, what sets Cuckoo apart is that it behaves like a cross between <a href="https://www.tomsguide.com/news/this-new-mac-malware-is-stealing-passwords-credit-card-info-and-more-how-to-stay-safe"><u>infostealer malware</u></a> and <a href="https://www.tomsguide.com/news/macs-under-threat-from-cloudmensis-spyware-what-you-need-to-know"><u>spyware</u></a>.</p><p>In a <a href="https://blog.kandji.io/malware-cuckoo-infostealer-spyware" target="_blank"><u>blog post</u></a>, Kandji’s Adam Kohler and Christopher Lopez explain that they came across a previously undetected malicious <a href="https://www.tomsguide.com/news/macs-are-under-attack-from-this-windows-malware-what-you-need-to-know"><u>Mach-O</u></a> binary on the malware-tracking site <a href="https://www.tomsguide.com/news/these-popular-apps-are-being-mimicked-to-spread-malware-heres-how-to-protect-yourself"><u>VirusTotal</u></a> with the name “DumpMedia Spotify Music Converter.” They then looked up the program’s name online and found that it was being distributed from a site called dumpmedia[.]com which offers multiple apps to help users pirate music from streaming services by converting them into MP3 files.</p><p>While the Cuckoo malware is currently being spread on music piracy sites, this campaign could easily be changed to distribute it through other fake apps. Here’s everything you need to know about this new Mac malware threat including some tips on how you can keep your own Mac virus free.</p><h2 id="establishing-persistence-and-escalating-privileges">Establishing persistence and escalating privileges</h2><p>After downloading the DumpMedia Spotify Music Converter app, the researchers discovered it contained an application bundle. This is interesting as normally, macOS apps just need to be dragged into the Applications folder — in contrast, this one encourages users to right click on it and then click open.</p><p>The app found in the bundle was signed without a <a href="https://www.tomsguide.com/news/macs-under-attacks-from-password-stealing-malware-how-to-stay-safe"><u>developer ID</u></a> which means that Apple’s <a href="https://www.tomsguide.com/news/this-severe-macos-flaw-could-let-malware-run-on-your-mac-update-right-now"><u>Gatekeeper</u></a> will try to stop it from running. However, if a user allows it to run on their computer manually, the malware will then run its course.</p><p>Just like the <a href="https://www.tomsguide.com/news/new-macstealer-malware-steals-icloud-keychain-data-and-passwords-how-to-stay-safe"><u>MacStealer malware</u></a>, Cuckoo uses a script to display a fake password prompt to trick users into entering their system password. If the hackers behind this malware do get a victim’s system password, they can then escalate the malware’s privileges on the infected machine.</p><p>Cuckoo then takes note of the apps installed on the now compromised Mac, takes screenshots and harvests data from <a href="https://www.tomsguide.com/news/apple-brings-end-to-end-encryption-to-icloud-and-beta-users-can-try-it-now"><u>iCloud Keychain</u></a>, Apple Notes, web browsers, crypto wallets and apps like Discord, FileZilla, Steam and Telegram.</p><p>It’s also worth noting that Cuckoo uses a technique called LaunchAgent to establish persistence on an infected Mac. This way, even if you reboot your computer, the malware will still run the next time you turn your Mac on. Likewise, the malware checks to make sure that the targeted Mac isn’t located in Armenia, Belarus, Kazakhstan, Russia or Ukraine before it begins stealing sensitive data.</p><h2 id="how-to-stay-safe-from-mac-malware-5">How to stay safe from Mac malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="F9ybS7WNwSK95hqxotZgYM" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/F9ybS7WNwSK95hqxotZgYM.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>As is often the case with other malware strains, Cuckoo is currently <a href="https://www.tomsguide.com/news/heres-another-big-reason-to-avoid-pirating-content-online">being spread on piracy sites</a>. Besides being illegal and harmful to creators, pirating content online is usually a surefire way to end up with a nasty malware infection.</p><p>While your Mac comes with built-in <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"><u>antivirus software</u></a> in the form of Apple’s <a href="https://www.tomsguide.com/news/macos-is-getting-even-better-at-scanning-for-malware-heres-how"><u>XProtect</u></a>, you might also want to consider using one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus"><u>best Mac antivirus software</u></a> solutions as well. These paid antivirus programs tend to receive updates more regularly, come with more features and often give you access to extras like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a>.</p><p>We could see the hackers behind this campaign come up with another way to distribute the new Cuckoo malware like through <a href="https://www.tomsguide.com/reference/what-are-phishing-scams"><u>phishing emails</u></a> or <a href="https://www.tomsguide.com/news/200-malicious-android-and-ios-apps-caught-draining-bank-accounts-check-your-phone-now"><u>malicious apps</u></a>. For right now though, if you avoid sites that offer a way to download music from streaming services, you should be safe.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-apps-to-distribute-this-dangerous-mac-malware-dont-fall-for-this">Hackers are using fake apps to distribute this dangerous Mac malware </a></li><li><a href="https://www.tomsguide.com/computing/macbooks/unpatchable-vulnerability-discovered-in-apple-m1-m2-and-m3-chips-what-you-need-to-know">Unpatchable vulnerability discovered in Apple M1, M2 and M3 chips</a></li><li><a href="https://www.tomsguide.com/news/this-macos-flaw-lets-hackers-install-undeletable-malware-on-your-mac-how-to-stay-safe">This macOS flaw lets hackers install 'undeletable' malware on your Mac</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Android security flaw lets hackers seize control of apps — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-android-security-flaw-lets-hackers-seize-control-of-apps-uninstall-these-immediately</link>
                                                                            <description>
                            <![CDATA[ Microsoft has uncovered a new security flaw called ‘Dirty Stream’ which impacts many popular Android apps and could let hackers sneak malicious code into them. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gcnAdqKvV4ZecMoP2qd86U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/v6Ro3B6LfmJmFroAuNUBf8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 05 May 2024 15:29:23 +0000</pubDate>                                                                                                                                <updated>Mon, 06 May 2024 15:03:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Alyse Stanley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/BxNnQuBWRHqkv5xWZsjrjc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alyse Stanley is a news editor at Tom’s Guide, overseeing weekend coverage and writing about the latest in tech, gaming, and entertainment. Before Tom’s Guide, Alyse worked as an editor for the Washington Post’s sunsetted video game section, Launcher, where she also wrote about indie games you shouldn’t miss, how to tackle your gaming backlog, and all things Nintendo. She previously led Gizmodo’s weekend news desk covering breaking tech news and has written game reviews and features for outlets like Polygon, Unwinnable, and Rock, Paper, Shotgun. A recent Chicago-area transplant born and raised in Virginia, Alyse is a big fan of horror movies, cartoons, and roller skating. She&#039;s also a puzzle fan and can often be found contributing to the NYT Connections coverage on Tom&#039;s Guide &lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Anthony Spadafora ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/v6Ro3B6LfmJmFroAuNUBf8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android logo on phone next to Malware sign]]></media:description>                                                            <media:text><![CDATA[Android logo on phone next to Malware sign]]></media:text>
                                <media:title type="plain"><![CDATA[Android logo on phone next to Malware sign]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/v6Ro3B6LfmJmFroAuNUBf8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em><strong>Editor’s Note: </strong></em><em>We have updated this article to highlight the fact that the vulnerable apps in question have since been patched by their respective developers. Also, we’ve changed the headline to address that the apps themselves are not malicious and don’t need to be deleted. We’ll update this story as we learn more.</em></p><p>Microsoft is sounding the alarm about a recently discovered <a href="https://www.microsoft.com/en-us/security/blog/2024/05/01/dirty-stream-attack-discovering-and-mitigating-a-common-vulnerability-pattern-in-android-apps/" target="_blank">critical security vulnerability on Android</a> named "Dirty Stream" that can let <a href="https://www.tomsguide.com/computing/malware-adware/these-malicious-android-malware-apps-were-downloaded-150000-times-from-the-play-store-delete-them-right-now">malicious apps</a> easily hijack legitimate apps. Worse still, this flaw impacts multiple apps with hundreds of millions of installs. If you have one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a>, here&apos;s what you need to know to protect your data. </p><p>The vulnerability relates to the ContentProvider system prevalent across many popular Android apps, which manages access to structured data sets meant to be shared between different applications. It&apos;s basically what lets your Android apps talk to one another and share files. To protect users and ward off unauthorized access, the system includes safeguards such as strict isolation of data, unique permissions attached to specific URIs (Uniform Resource Identifiers), and path validation security. </p><p>According to Microsoft&apos;s alert, two vulnerable apps that have since been patched  include <a href="https://play.google.com/store/apps/details?id=com.mi.android.globalFileexplorer" target="_blank">Xiaomi Inc.’s File Manager</a> (1B+ installs) and <a href="https://play.google.com/store/apps/details?id=cn.wps.moffice_eng" target="_blank">WPS Office</a> (500M+ installs). </p><p>What makes the Dirty Stream vulnerability so devious is how it manipulates this system. Microsoft has found that hackers can create "custom intents," messaging objects that facilitate communication between components across Android apps, to bypass these security measures. By exploiting this loophole, malicious apps can send a file with a manipulated filename or path to another app using a custom intent, sneaking in harmful code disguised as legitimate files. </p><p>From there, a hacker could trick a vulnerable app into overwriting critical files within its private storage space — and the results can be devastating. As <a href="https://www.bleepingcomputer.com/news/security/microsoft-warns-of-dirty-stream-attack-impacting-android-apps/" target="_blank">BleepingComputer</a> put it, Dirty Stream essentially turns a common OS-level function into a weaponized tool to execute unauthorized code, steal data, and even hijack an app while the user is none the wiser. </p><p>"Arbitrary code execution can provide a threat actor with full control over an application’s behavior," <a href="https://www.microsoft.com/en-us/security/blog/2024/05/01/dirty-stream-attack-discovering-and-mitigating-a-common-vulnerability-pattern-in-android-apps/" target="_blank">Microsoft said in a security bulletin this week</a>. "Meanwhile, token theft can provide a threat actor with access to the user’s accounts and sensitive data."</p><h2 id="how-widespread-is-this-threat">How widespread is this threat?</h2><p>Microsoft’s investigation found that this vulnerability is not an isolated issue. The company uncovered incorrect implementations of the content provider system across many popular Android apps. </p><p>"We identified several vulnerable applications in the Google Play Store that represented over four billion installations," Microsoft explained. "We anticipate that the vulnerability pattern could be found in other applications."</p><p>Given the nature of how this vulnerability works, it&apos;s hard to know exactly how many other legitimate apps may have been impacted. But it&apos;s safe to assume this potential risk is on an industrial scale until all apps are patched. </p><h2 id="how-to-stay-safe-from-android-malware-12">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>When it comes to staying safe from Android malware, one of the easiest and simplest things you can do is to <a href="https://www.tomsguide.com/news/xenomorph-android-malware-can-steal-passwords-from-400-banking-apps-protect-yourself-now"><u>limit the number of apps</u></a> on your phone. I know this may sound silly but think of it this way, the fewer apps you have, the less likely that one of them may turn out to be malicious. Before installing any new app, first ask yourself whether or not you actually need it.</p><p>From here, you want to make sure that you’re installing new security updates and patches as soon as they become available. These often fix vulnerabilities and zero-day flaws which can be used to launch attacks by hackers. While you can <a href="https://www.tomsguide.com/us/old-phones-unsafe,news-24846.html"><u>use an old phone</u></a> for longer than you’d expect, it’s worth upgrading to a new device once your current phone isn’t receiving security updates any more, especially if you want to be on the safe side.</p><p>You also want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect"><u>Google Play Protect</u></a> is enabled on your device. This pre-installed app scans both your existing apps and any new ones you download for malware. Likewise, if you want extra protection and potentially even some extra features like a <a href="https://www.tomsguide.com/best-picks/best-vpn"><u>VPN</u></a> or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html"><u>password manager</u></a>, you also want to check out the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus"><u>best Android antivirus apps</u></a>.</p><p>As ‘Dirty Stream’ is a very serious flaw, it’s likely that Google is already working on a fix as Microsoft would have shared any of the info it uncovered with the search giant before publishing its alert.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-wpeeper-android-malware-adds-a-backdoor-to-your-phone-to-steal-your-data-how-to-stay-safe">New Wpeeper Android malware adds a backdoor to your phone to steal your data</a></li><li><a href="https://www.tomsguide.com/phones/android-phones/google-blocked-over-2-million-dangerous-android-apps-from-the-play-store-last-year">Google blocked over 2 million dangerous Android apps from the Play Store last year</a></li><li><a href="https://www.tomsguide.com/computing/online-security/fbi-warns-scammers-are-using-free-verification-services-to-dupe-dating-app-users-how-to-stay-safe">FBI warns scammers are using ‘free’ verification services to dupe dating app users</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using fake apps to distribute this dangerous Mac malware — don’t fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-apps-to-distribute-this-dangerous-mac-malware-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ Hackers are now using lookalike pages for popular apps to infect vulnerable Macs with the Atomic Stealer malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bK5U3meBETmmRm9rugQrw6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 May 2024 16:46:40 +0000</pubDate>                                                                                                                                <updated>Fri, 03 May 2024 20:24:34 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:description>                                                            <media:text><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:text>
                                <media:title type="plain"><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you thought the <a href="https://www.tomsguide.com/best-picks/best-macbook"><u>best MacBooks</u></a> were safe from malware, think again, as hackers now have Apple’s computers fixed firmly in their sights.</p><p>While there are a number of different <a href="https://www.tomsguide.com/computing/malware-adware/that-innocent-looking-calendar-invite-could-infect-your-mac-with-malware-dont-fall-for-this"><u>Mac malware strains</u></a>, one in particular keeps reappearing. <a href="https://www.tomsguide.com/news/hackers-now-spreading-mac-malware-via-fake-browser-updates-dont-fall-for-this"><u>Atomic Stealer</u></a> is an info-stealing malware which is often distributed through pirated apps. This time, however, this malware is impersonating popular apps in <a href="https://www.tomsguide.com/news/you-should-think-twice-before-clicking-on-ads-even-on-google-search"><u>Google Ads</u></a> to dupe unsuspecting users into infecting their Apple computers.</p><p>According to a <a href="https://www.intego.com/mac-security-blog/intego-discovers-new-atomic-stealer-amos-mac-malware-variants/" target="_blank"><u>blog post</u></a> from <a href="https://www.tomsguide.com/news/mac-malware-shlayer2"><u>Intego</u></a>, the cybersecurity firm’s researchers have been tracking two new Atomic Stealer variants. What makes this malware particularly dangerous is that it’s designed to steal sensitive data including saved passwords, cookies, autofill text and even crypto from infected Macs.</p><p>Here’s everything you need to know about this new Atomic Stealer campaign along with some tips and tricks to help keep your Mac malware free.</p><h2 id="impersonating-popular-mac-apps">Impersonating popular Mac apps</h2><p>In the same way that businesses can buy ad space to have their products show up higher in search results, so too can hackers. They’ve been using this technique for the past year or so, which is why I highly recommend that you now scroll down past the ads and don’t just click on the first result in Google (or any other search engine for that matter).</p><p>In this particular campaign, the hackers behind it are impersonating a popular Mac utility, a personal finance app, a digital trading card game and a productivity app using this technique. </p><p>With the utility File Juicer, which extracts embedded files from different types of documents, and the personal finance app Debit & Credit, the hackers behind this campaign are using a fake installer called “AppleApp.” When opened on a vulnerable Mac, instead of installing the actual programs, this installer infects the system with the Atomic Stealer malware.</p><p>As for the digital trading card game Parallel and the productivity software Notion, both fake apps have installers that impersonate their legitimate counterparts, complete with their names and logos. </p><p>During its investigation into the matter, Intego also observed that many of these fake apps are actually <a href="https://www.tomsguide.com/news/new-android-malware-dropper-sneaks-past-google-protect-yourself-now"><u>malware droppers</u></a> which are “designed to obtain and install additional malware.” These droppers try to hide in plain sight before connecting to a malicious website to download additional payloads onto an infected computer.</p><h2 id="how-to-keep-your-mac-safe-from-malware">How to keep your Mac safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="F9ybS7WNwSK95hqxotZgYM" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/F9ybS7WNwSK95hqxotZgYM.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>To avoid accidentally downloading fake apps spreading malware onto your Mac, there are a few steps you can take to stay safe.</p><p>For starters, it’s better to stick to official app stores like the <a href="https://www.tomsguide.com/news/apple-allows-unlisted-apps-in-the-app-store-heres-how-to-see-them"><u>Mac App Store</u></a> when downloading new software. If you do need to look for a particular program on a search engine, you want to scroll down past any ads as they could be malicious and instead install the app or program directly from a company’s website. When you know a company’s web address, you’re better off just typing that out into your browser’s address bar, too.</p><p>Although your Mac comes with built-in malware protection in the form of XProtect, you might also want to consider investing in the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus"><u>best Mac antivirus software</u></a> for your Apple computer. These paid antivirus programs have more features, and it’s worth noting that Intego’s Mac antivirus products also have a clever trick up their sleeves. Both <a href="https://www.tomsguide.com/reviews/intego-mac-internet-security-x9"><u>Intego Mac Internet Security X9</u></a> and <a href="https://www.tomsguide.com/reviews/intego-premium-bundle-x9"><u>Intego Mac Premium Bundle X9</u></a> can scan the best iPhones and iPads for malware but only when they are connected to a Mac via a USB cable.</p><p>Since Mac users are such a profitable target for hackers, it’s highly likely that we will continue to see even more malware targeting Apple’s computers. This is why you need to be extra careful online and this is especially true when downloading new apps or software.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/fbi-warns-scammers-are-using-free-verification-services-to-dupe-dating-app-users-how-to-stay-safe">FBI warns scammers are using ‘free’ verification services to dupe dating app users</a></li><li><a href="https://www.tomsguide.com/computing/macbooks/unpatchable-vulnerability-discovered-in-apple-m1-m2-and-m3-chips-what-you-need-to-know">Unpatchable vulnerability discovered in Apple M1, M2 and M3 chips</a></li><li><a href="https://www.tomsguide.com/phones/iphones/dangerous-lightspy-iphone-spyware-can-steal-your-files-location-data-and-messages-how-to-stay-safe">Dangerous LightSpy iPhone spyware can steal your files, location data and messages</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>