<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.tomsguide.com/feeds/tag/malware-and-adware" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from Tom's Guide in Malware-and-adware ]]></title>
                <link>https://www.tomsguide.com</link>
        <description><![CDATA[ All the latest malware-and-adware content from the Tom's Guide team ]]></description>
                                    <lastBuildDate>Thu, 18 Dec 2025 18:05:21 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Nearly 2 million Android devices hijacked by massive new botnet — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/nearly-2-million-android-devices-hijacked-by-massive-new-botnet-how-to-see-if-yours-are-infected</link>
                                                                            <description>
                            <![CDATA[ A large-scale botnet has taken over millions of Android devices in order to use them for nefarious purposes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mWvDXugoxmbag8s8sXKipQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 18 Dec 2025 18:05:21 +0000</pubDate>                                                                                                                                <updated>Fri, 19 Dec 2025 16:54:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Anthony Spadafora ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware on phone]]></media:description>                                                            <media:text><![CDATA[Android malware on phone]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>On October 30th, <a href="https://radar.cloudflare.com/domains?dateStart=2025-10-30&dateEnd=2025-10-31" target="_blank" rel="nofollow">Cloudfare data</a> identified a strange website that briefly surpassed Google as the most popular website globally. However, it wasn’t a website at all – It was a massive <a href="https://www.tomsguide.com/computing/malware-adware/over-one-million-android-devices-infected-with-password-stealing-pre-installed-botnet-malware-how-to-stay-safe">command-and-control server</a> that was controlling at least 1.8 million Android devices in order to use them for nefarious purposes.</p><p>Known as Kimwolf, the botnet is now considered to be the largest of its kind (so far) and shares codebase with the previous recordbreaker, Aisuru. Though both botnets use malware to infect vulnerable devices and rely on an APK file to load and start during runtime, the threat actors learned from Aisuru and included additional features in Kimwolf to better evade detection. Capable of various malicious activities including typical <a href="https://www.tomsguide.com/news/live/x-down-twitter-outage-march-2025">DDoS attacks</a>, it also uses proxy forwarding which allows the attackers to conceal their location and lets them bypass IP-based geo-restrictions and blacklists. </p><p>There’s also a reverse shell in the malware which gives the attackers command line access to the infected devices. This means they can run arbitrary commands or deploy additional malware on compromised devices. Likewise, they can also upload, download or modify files between devices.</p><p><a href="https://blog.xlab.qianxin.com/kimwolf-botnet/" target="_blank" rel="nofollow">Researchers at Xlab</a> infiltrated the Kimwolf botnet in order to learn more about how it works and its scale. According to their findings, it appears to target Android devices, specifically those that are not certified by Google – which lack the search giant's extra protections like dirt cheap set top boxes and tablets.</p><p>Xlab says the Kimwolf botnet seems to consist of <a href="https://www.tomsguide.com/news/thousands-of-android-tv-boxes-infected-with-dangerous-malware-linked-to-fraud">infected Android tv boxes</a> on residential networks distributed across 222 countries. Their <a href="https://www.tomsguide.com/computing/vpns/2-8-million-ip-addresses-being-used-in-brute-force-attack-on-vpns">IP addresses</a> are located in Brazil (14%), India (12.7%), and the United States (9.5%) with the remainder in (respectively) Argentina, South Africa, the Philippines, Mexico and China.</p><h2 id="how-to-avoid-becoming-mixed-up-in-a-botnet">How to avoid becoming mixed up in a botnet</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="X2e6hr6bWx89b7Nf87EKxX" name="botnet-structure-shst.jpg" alt="Stylized computer-aided illustration of interlinked blue robots illustrating the structure of a network botnet." src="https://cdn.mos.cms.futurecdn.net/X2e6hr6bWx89b7Nf87EKxX.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The recommendations here are simple: Users should avoid purchasing uncertified, off-brand Android devices, set strong passwords, update their firmware as soon as possible, and only download apps from known and trusted developers. </p><p>If you wants to stay safe, don't buy AOSP-based Android devices like off-brand TV boxes that lack official Google Play Services support. Additionally, always keep your firmware updated and install the latest security patches as soon as they become available on whichever of the <a href="https://www.tomsguide.com/us/best-streaming-players,review-2140.html" target="_blank" rel="nofollow">best streaming devices</a> you're currently using.</p><p>Google spokespeople have frequently advised us that "If a device isn't Play Protect certified, Google doesn't have a record of security and compatibility test results. Play Protect certified Android devices undergo extensive testing to ensure quality and user safety. Users should ensure Google Play Protect, Android’s malware protection that is one by default on devices with Google Play Services, is enabled.”</p><p>At the same time, you also want to avoid <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps">sideloading apps</a> and stick to only using ones from the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a> and other official app stores. Likewise, Android TV devices can have their remote access features disabled when not in use, which takes them offline. This can provide an extra layer of security to help protect your devices and the data on them if they've unknowingly become part of a botnet</p><p>It might also be worth investing in one of the <a href="https://www.tomsguide.com/us/best-wifi-routers,review-2498.html" target="_blank" rel="nofollow">best Wi-Fi routers</a> or the <a href="https://www.tomsguide.com/us/best-mesh-router,review-5191.html" target="_blank" rel="nofollow">best mesh Wi-Fi systems</a> with security software built-in. While the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html" target="_blank" rel="nofollow">best antivirus software</a> can keep your PC safe from malware, network-wide security solutions like Netgear's Armor or TP-Link's HomeShield protect all of the devices connected to your home network from viruses and other threats. If you want our recommendation for the best official Android TV box out there, we still really like the <a href="https://www.tomsguide.com/reviews/nvidia-shield-tv-2019-review">Nvidia Shield</a> (even though it's an older model).</p><h2 id="what-if-you-do-own-a-cheap-android-set-top-box">What if you do own a cheap Android set top box?</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4908px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="mMmeQWqfUGeJS4qYwjMGgE" name="shutterstock_1543667891.jpg" alt="A generic looking Android TV box" src="https://cdn.mos.cms.futurecdn.net/mMmeQWqfUGeJS4qYwjMGgE.jpg" mos="" align="middle" fullscreen="" width="4908" height="2761" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>If you've picked up a cheap, unofficial Android set top box and are worried about it becoming infected with malware, you definitely should be. We've covered this several times in the past and I wouldn't recommend buying one of these devices over say, a <a href="https://www.tomsguide.com/entertainment/streaming-devices/google-tv-streamer-review">Google TV Streamer</a> or if you're on a budget, an Onn Google TV like the <a href="https://www.tomsguide.com/reviews/onn-4k-google-tv-streaming-box-review-the-new-best-cheap-streaming-device">Onn 4K Plus</a>. However, if you've paid good money for an unofficial Android set top box, you're not completely out of luck.<br><br>If you head to the Google Play Store on either the device itself or on your phone or computer, you can download the <a href="https://play.google.com/store/apps/details?id=com.eset.etvs.gp&hl=en_US" target="_blank" rel="nofollow">ESET Smart TV Security</a> app for free though there is a paid version as well. It lets you run manual scans for malware at any time and like <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> on one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a>, monitors any new apps you install for malware and other threats.<br><br>Now if you have some extra cash, the paid version takes things a step further with scheduled scans and anti-phishing protection at a very reasonable price of $1-3 per month or $15-20 for the year for a single device. Likewise, you can pick up one of the more advanced <a href="https://www.tomsguide.com/computing/antivirus/eset">ESET Home</a> plans which includes the premium version of Smart TV Security.<br><br>This should keep you safe and hold you over until your next upgrade. At which time, I highly recommend getting an official Android set top box instead.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/hackers-are-using-this-simple-trick-to-take-over-microsoft-accounts-dont-fall-for-this">Microsoft accounts are under attack by hackers - here's how to stay safe from this age-old tactic</a></li><li><a href="https://www.tomsguide.com/computing/online-security/multiple-firefox-add-ons-infected-with-ghostposter-malware-how-to-stay-safe">Multiple Firefox add-ons infected with 'GhostPoster' malware — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/200-million-records-exposed-in-massive-pornhub-data-breach-heres-what-we-know-so-far">200 million records exposed in massive Pornhub data breach — here’s what we know so far</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How to avoid the nightmare Android malware that can hold your device for ransom or erase it ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-ransomware-locks-android-devices-and-can-also-erase-data-how-to-avoid-this-malware</link>
                                                                            <description>
                            <![CDATA[ A new Android ransomware can lock your device to demand malware, or erase all your data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">abaA3CNtSWqDCALGrGUUWe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Dec 2025 16:45:03 +0000</pubDate>                                                                                                                                <updated>Fri, 12 Dec 2025 14:43:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware on phone]]></media:description>                                                            <media:text><![CDATA[Android malware on phone]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Newly discovered <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-malicious-code-to-take-over-legitimate-banking-apps-and-your-phone-dont-fall-for-this">malware</a> DroidLock can wreak havoc on your Android phone, taking over your lock screen — even changing your login info — to prevent victims from being able to get into their devices. </p><p>According to <a href="https://zimperium.com/blog/total-takeover-droidlock-hijacks-your-device" target="_blank" rel="nofollow">researchers at Zimperium</a>, the malware can lock victims' screens in order to demand a ransom, change the PIN, password or biometric data to prevent the user from accessing their own device, access complete control over the device including text messages, call logs, contacts and audio recordings. The ransomware overlay will instruct the victim to contact the attacker at a Proton email address within 24 hours, otherwise it will permanently destroy the files on the device. </p><p>The researchers say the malware is being distributed through malicious websites with links to fake apps that mimic legitimate programs. The infection begins with a dropper that tricks the users into installing an app that contains the malware. These apps then request permissions for Device Administrator and Accessibility Services via an update, which allow it to perform additional malicious actions. </p><p>Currently, the targets are largely Spanish-speaking users, but as with most malware, there’s no reason it couldn’t be scaled up. </p><p>The DroidLock malware supports 15 commands that let it send notifications, place an overlay on the screen, mute the device, reset it to factory settings, start the camera or uninstall apps. It can use the same malicious APK to place a different overlay onto the phone to steal the lock pattern; when the user draws the lock pattern on their handset, it gets sent to the attacker. </p><h2 id="how-to-stay-safe-from-ransomware">How to stay safe from ransomware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="HbBDgAW7nB6VZN9b6sLyyD" name="Android malware ransomware Unlock your system pay now.jpg" alt="An Android smartphone infected with ransomware" src="https://cdn.mos.cms.futurecdn.net/HbBDgAW7nB6VZN9b6sLyyD.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The good news is that because Zimperium shares its malware findings with the Android security team, Play Protect detects and blocks this threat from devices that are up to date. </p><p>That means if your Android device is keep current with updates, you’re in the clear – and this is precisely why we stress again and again that users need to keep their devices up to date. </p><p>The bad news is Android users are additionally recommended to avoid sideloading APKs from outside the Google Play store –  unless the publisher is a trusted source.  So, if you like sideloading apps, make sure to check out the publisher and the URL extensively before you download. </p><p>Also, always check to see if the permissions required by an app serve its purposes, and doesn't overstep. Be particularly wary of anything that is asking for accessibility permissions, as this is often a way that malware will try to sneak in access to your handset. And periodically scan your device with Play Protect. Keep in mind, that the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> can also be of assistance here in scanning and protecting your phone. </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/nordvpns-new-email-protection-feature-can-stop-phishing-in-real-time">NordVPN's new email protection feature can stop phishing in real time</a></li><li><a href="https://www.tomsguide.com/computing/online-security/new-spiderman-phishing-kit-lets-hackers-instantly-spoof-banking-sites-to-steal-passwords-and-take-over-accounts-how-to-stay-safe">New Spiderman phishing kit lets hackers instantly spoof banking sites to steal passwords and take over accounts — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/4-3-billion-job-documents-left-unsecured-online-names-emails-phone-numbers-and-linkedin-data-exposed">4.3 billion job documents left unsecured online — names, emails, phone numbers and LinkedIn data exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New malware turns trusted banking apps into phone hijacking tools — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-using-malicious-code-to-take-over-legitimate-banking-apps-and-your-phone-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ Hackers are taking over legitimate apps with malicious code in order to commit financial fraud and take over your device. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">x3sfTrpAryGbuQWt93TTgE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hymSLCyZabSxT4kiY4sXhP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Dec 2025 18:52:10 +0000</pubDate>                                                                                                                                <updated>Tue, 09 Dec 2025 17:12:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hymSLCyZabSxT4kiY4sXhP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware botnet attack]]></media:description>                                                            <media:text><![CDATA[Android malware botnet attack]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware botnet attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hymSLCyZabSxT4kiY4sXhP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are taking legitimate banking apps and decompiling them in order to add <a href="https://www.tomsguide.com/computing/malware-adware/this-spyware-campaign-can-turn-your-browser-extensions-into-malware-how-to-stay-safe">malicious code</a>, then spreading them through common threat schemes like <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing lures</a> and <a href="https://www.tomsguide.com/computing/malware-adware/booking-com-phishing-scam-is-infecting-users-with-malware-by-using-lookalike-urls-dont-fall-for-this">fake look-a-like websites</a>. According to <a href="https://www.group-ib.com/blog/turning-apps-into-gold/" target="_blank">researchers at Group-IB</a>, these poisoned apps may be linked to the GoldFactory group which is also known for <a href="https://www.tomsguide.com/computing/malware-adware/first-ever-ios-trojan-discovered-and-its-stealing-face-id-data-to-break-into-bank-accounts">stealing facial recognition data</a>. </p><p>This malware campaign has enabled them to not only expose thousands of people to banking fraud, but also to get full control over an infected device. The attackers also add <a href="https://www.tomsguide.com/computing/malware-adware/new-android-banking-trojan-lets-hackers-stream-a-live-feed-from-your-phone-and-control-it-in-real-time-how-to-stay-safe">trojans</a> or backdoors to the apps and in total, Group-IB found 27 original banking applications that had been tampered with so far. After injecting malicious code into an app, the hackers behind this campaign will then impersonate a government agency or service through smishing, phishing or <a href="https://www.tomsguide.com/news/this-social-engineering-trick-can-infect-your-pc-with-malware-what-you-need-to-know">social engineering</a> tactics so that potential victims are fooled into visiting a website that mimics an actual government website. </p><p>For example, the initial lure might be a text from an electricity provider or the Department of Health and the attacker would direct the target to a fake website  impersonating either where they would be prompted to download an infected app in order to make a payment. Some of the scams may initially establish contact with the victims over text or messaging app and then move to phone calls to provide additional instructions. </p><p>The victim may be instructed to borrow an Android device to complete the process or given a link to a website that resembles the actual <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a>  but is used to deliver an APK file. Unfortunately, because the fake app behaves in the same way as the legitimate app would, the victim doesn’t realize that they aren't interacting with a regular government agency or business.</p><p>Once the download is complete, the victim is prompted to enable a number of <a href="https://www.tomsguide.com/news/these-predatory-loan-apps-have-been-installed-over-15-million-times-delete-them-now">unnecessary permissions</a> on their device. This allows the threat actors to steal a victim's login credentials, as well as monitor their activity, commit financial fraud and even take over their device. The group can remove traces of their activity once they’ve completed these malicious behaviors too.</p><p>Group-IB points out that GoldFactory uses “advanced hooking malware families” – called SkyHook, FriHook, PineHook or Gigabug which can bypass many built-in app integrity checks to hid their malicious behaviors. These malware families can also allow the attackers to capture sensitive data, automate on screen actions and even remotely view and operate the victims phone.</p><p>While the victims so far have been concentrated in the areas that GoldFactory usually operates in – Vietnam, Thailand and Indonesia – the approach could easily be deployed to other countries like the U.S. or the U.K. </p><h2 id="how-to-stay-safe-from-malware">How to stay safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Fortunately, this campaign isn't very widespread – yet. However, as with most phishing, vishing and smishing campaigns, the best way to protect yourself is to stay calm and think critically about the messages you receive. Be extremely suspicious of  any messages from a government agency or service that arrive through non-official channels. Does your power company typically send you text messages? Is it normal for the Department of Health to contact you through your mobile device?</p><p>With any unexpected message, the rules always remain the same: Never, ever click on any link or code in a message if you don't know who's sending it. Don't download anything if you don't know who is sending it and haven't verified it. If someone is contacting you requesting that you download something, hang up or don't respond to the text and contact that office independently and verify that the request is legitimate. </p><p>Likewise, you always want to check the URLs of the websites you visit or manually enter them in yourself to make sure that you're going to the correct website. Always make sure that you have the <a href="https://www.tomsguide.com/computing/antivirus/best-antivirus-software">best antivirus software</a> up and running on your devices as most of them have features that will alert you if you visit a suspicious website, or attempt to download a program that isn't legitimate. They also have additional features like a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a>, ransomware rollback and more that can help you stay safe when you go online. </p><p>This campaign may be limited to several countries in Southeast Asia now but given how successful it's been so far, I could easily see it spreading. For this reason, you want to make sure that you always practice good cyber hygiene and that you're especially wary of unsolicited messages that claim to be from a government agency or business. That way, you can avoid falling victim to this new malware campaign if it does end up spreading to other countries.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/new-android-banking-trojan-lets-hackers-stream-a-live-feed-from-your-phone-and-control-it-in-real-time-how-to-stay-safe">New Android banking trojan lets hackers stream a live feed from your phone and control it in real time — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/billions-of-chrome-users-at-risk-from-13-security-flaws-including-four-high-severity-ones-update-your-browser-right-now">Billions of Chrome users at risk from 13 security flaws including four high-severity ones — update your browser right now</a></li><li><a href="https://www.tomsguide.com/computing/online-security/fbi-says-scammers-are-stealing-instagram-photos-to-fake-kidnappings-for-ransom-money-heres-how-to-spot-it">FBI says scammers are stealing Instagram photos to fake kidnappings for ransom money — here's how to spot it</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Android banking trojan lets hackers stream a live feed from your phone and control it in real time — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-android-banking-trojan-lets-hackers-stream-a-live-feed-from-your-phone-and-control-it-in-real-time-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ The new Albiriox banking malware can already impersonate over 400 financial apps while giving hackers remote control over infected smartphones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3NbDHAMJgeUEm9tYRtXPYB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 04 Dec 2025 08:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 04 Dec 2025 09:27:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Imagine if a hacker could gain full control of your smartphone and stream everything on its screen to their own device? Well, a new <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-raton-android-trojan-can-automatically-transfer-money-right-off-your-phone-to-hackers">Android banking trojan</a> allows them to do just that, but they can also tap, swipe, type and navigate through hijacked smartphones in real time.</p><p>According to a new <a href="https://www.malwarebytes.com/blog/news/2025/12/new-android-malware-lets-criminals-control-your-phone-and-drain-your-bank-account" target="_blank">blog post</a> from the cybersecurity site Malwarebytes, security researchers at the online fraud management firm <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts">Cleafy</a> have discovered a new Android malware family called Albiriox. Despite being fairly new, it already offers advanced capabilities to cybercriminals looking to deploy this banking trojan in their attacks.</p><p>First observed during September of this year, Albiriox is currently being promoted as a <a href="https://www.tomsguide.com/news/password-stealing-erbium-malware-is-spreading-fast-and-loved-by-cybercriminals">Malware-as-a-Service</a> offering on dark web cybercrime forums. This means that other hackers and cybercriminals pay its creators a small fee to use it in their own malware campaigns.</p><p>What makes Albiriox a serious threat to the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> is the fact that it’s explicitly designed to perform On-Device Fraud. Unlike other malware that <a href="https://www.tomsguide.com/computing/malware-adware/this-android-banking-trojan-steals-passwords-to-take-over-your-accounts-and-all-it-takes-is-a-single-text-message">steals banking credentials</a>, allowing hackers to log in to a victim’s financial accounts from another device, this one enables them to do so and drain accounts directly on an infected smartphone. </p><p>Here’s everything you need to know about this new malware strain, along with some tips and tricks to help keep your Android phone safe from hackers.</p><h2 id="hiding-behind-a-blank-screen">Hiding behind a blank screen</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iJKvacosvMoCwbKjwcVGbP" name="hacker computer.jpg" alt="A hand typing at a computer in a dark room, lit up by the laptop's keyboard LEDs and red LED light" src="https://cdn.mos.cms.futurecdn.net/iJKvacosvMoCwbKjwcVGbP.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>Like other Android malware strains, Albiriox is often spread through <a href="https://www.tomsguide.com/computing/malware-adware/these-12-malicious-android-apps-are-recording-your-conversations-delete-them-right-now">malicious apps</a> that unsuspecting users install on their devices by sideloading them. However, in one of the first Albiriox campaigns observed by Cleafy’s security researchers, they found that the hackers behind it were using fake <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a> pages to trick users into installing their malicious apps by making it appear legitimate.</p><p>In the example shared in a separate <a href="https://www.cleafy.com/cleafy-labs/albiriox-rat-mobile-malware-targeting-global-finance-and-crypto-wallets" target="_blank">blog post</a>, Cleafy points out that this fake page is almost an identical copy of the listing pages used by real Android apps on the Play Store. In fact, it even had screenshots of the fake app in question, along with ratings and installation prompts. However, once a potential victim went to install it, a malware dropper hidden inside an APK was downloaded instead, completely bypassing the Google Play Store. While some Android users would immediately see this as a major red flag, others wouldn’t due to how much effort was put into perfectly copying an actual Play Store listing page.</p><p>From there, Cleafy’s researchers noticed that the cybercriminals behind Albiriox shifted their tactics and began using <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing</a> instead of fake websites to spread the malware. Now, instead of a direct APK download from a fake site, visitors were prompted to enter their mobile phone numbers, with the site telling them that a download link would be delivered via WhatsApp.</p><p>Once potential victims downloaded this APK file, they’re met with a <a href="https://www.tomsguide.com/computing/online-security/macs-under-threat-from-new-info-stealing-malware-spread-through-fake-browser-updates-how-to-stay-safe">fake system update</a> interface instead of the normal one you see when installing new Android apps. This is done to trick them into granting unnecessary permissions that the Albiriox malware needs access to in order to take over their smartphone. After this is done, the final payload is loaded and installed on their phones.</p><p>Although Albiriox is a new banking trojan, it can already target over 400 banking and financial apps. Like other malware strains, it uses <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-banking-trojan-now-shows-a-fake-lock-screen-to-steal-your-pin-and-your-cash-dont-fall-for-this">overlay attacks</a> to mimic a banking app’s login page in order to steal a victim’s credentials. </p><p>Another interesting feature baked into this malware is that it can hide an attacker’s actions on a device in plain sight. For instance, if a hacker is using that stolen password to log into a user’s bank account in order to drain their funds, Albiriox can display a black screen while they operate in the background. You often see black or blank screens when an app is loading, so for most people, this behavior wouldn’t be out of the ordinary.</p><p>Likewise, since the fraud happens on the device itself, hackers using this malware can bypass <a href="https://www.tomsguide.com/computing/online-security/gen-z-and-millenials-are-more-concerned-about-cyber-attacks-tips-to-keep-you-safe">multi-factor authentication</a> and other security checks by intercepting one-time, 2FA codes and inputting them directly when prompted to do so.</p><h2 id="how-to-stay-safe-from-banking-trojans">How to stay safe from banking trojans</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Even though Albiriox is a rapidly evolving Android banking trojan, Cleafy has only observed attacks in Austria and other European countries so far. However, since this malware is distributed online to other cybercriminals to use in their own attacks, it could easily be repackaged and used to target Android users in the U.S., Canada and other countries around the world. For that reason, it’s definitely something you want to keep on your radar and prepare for. </p><p>One of the easiest ways to prevent your Android phone from coming down with a <a href="https://www.tomsguide.com/computing/malware-adware/downloading-this-new-mac-browser-could-leave-you-with-a-nasty-malware-infection-dont-fall-for-this">nasty malware infection</a> is to avoid <a href="https://www.tomsguide.com/news/over-60000-compromised-android-apps-found-spreading-adware-how-to-stay-safe">sideloading apps</a> altogether. I know it may seem convenient at times — like when a particular app is no longer available or can’t be downloaded in your region — but the high risk isn’t worth the reward. Fortunately, pretty much every Android smartphone has the option to install apps from unknown sources disabled by default. If you have enabled this feature, though, you might want to consider disabling it unless it’s absolutely necessary for your work, which it most likely won’t be.</p><p>From there, you want to ensure that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> is enabled on your Android phone. This free, built-in security app automatically scans all of the new apps you download and install for malware, as well as the existing ones on your phone. To add an extra layer of security, you might want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it. Many of them include useful extras like a <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a>, <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a> and more to help keep you safe online.</p><p>Albiriox has definitely made a splash in the world of cybercriminals, thanks to its advanced capabilities and rapid development, which is why I don’t see this particular Android malware strain going anywhere anytime soon. As such, it’s up to you to practice good cyber hygiene, avoid installing apps from shady websites or ones sent to you on social media, and to keep your device updated with the latest security patches. </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/new-android-banking-trojan-is-draining-accounts-and-snooping-on-encrypted-chats-how-to-stay-safe">New Android banking trojan is draining accounts and snooping on encrypted chats — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/parental-controls/you-can-control-what-your-kids-see-in-chatgpt-heres-how-to-enable-it">You can control what your kids see in ChatGPT — here's how to enable it</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/this-spyware-campaign-can-turn-your-browser-extensions-into-malware-how-to-stay-safe">Over 4 million users hit with spyware that can turn your browser extensions into malware — how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 4 million users hit with spyware that can turn your browser extensions into malware — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-spyware-campaign-can-turn-your-browser-extensions-into-malware-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ ShadyPanda is a dangerous new malware campaign that spent years turning browser extensions into spyware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hS4kyXowpPQHopc5y4ahZE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/W6JjyA6fWc7yvSauu4zdzT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Dec 2025 18:08:29 +0000</pubDate>                                                                                                                                <updated>Wed, 03 Dec 2025 18:13:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Browsers]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/W6JjyA6fWc7yvSauu4zdzT-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Chrome browser on laptop]]></media:description>                                                            <media:text><![CDATA[Chrome browser on laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Chrome browser on laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/W6JjyA6fWc7yvSauu4zdzT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>Editor's note: Microsoft has reached out to us regarding the story below and has issued the following update: "We have removed all the extensions identified as malicious on Edge Add-on store. When we become aware of instances that violate our policies, we take appropriate action that includes, but is not limited to, the removal of prohibited content or termination of our publishing agreement"</em></p><p>A long running malware operation that has evolved over several years has been turning <a href="https://www.tomsguide.com/computing/malware-adware/chrome-and-edge-users-infected-with-malicious-browser-extensions-that-steal-your-personal-data-what-to-do-now">browser extensions</a> in Chrome and Edge into spyware through updates that added malicious functionalities. According to a report from <a href="https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign">Koi Security</a>, the ShadyPanda campaign affects 4.3 million users who downloaded these now compromised browser extensions. </p><p>The ShadyPanda campaign consists of 20 malicious extensions on the <a href="https://www.tomsguide.com/news/chrome-could-soon-zap-some-of-your-extensions-heres-why">Chrome Web Store</a> and 125 in Edge; initial submissions of the extensions appeared in 2018, and the first signs of malicious behavior didn’t show up until five years later when a set of them posing as wallpaper and productivity tools began to show signs that something was amiss. </p><p>According to Koi Security, the malware campaign rolled out slowly, in phases, through the auto updated mechanism that is designed to keep users safe:</p><p>“Chrome and Edge’s trusted update pipeline silently delivered malware to users. No phishing. No social engineering. Just trusted extensions with quiet version bumps that turn productivity tools into surveillance platforms.” </p><p>Here's everything you need to know about this massive malicious extension campaign along with what steps you can take to secure your browser and your data right now.</p><h2 id="from-fraud-to-full-browser-access">From fraud to full browser access</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YwKRVzwvLwup6hDGh5bVNM" name="RzdqY6hhVUXJjJYEgfCrVe.jpg" alt="A hacker typing quickly on a keyboard" src="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The extensions begin their malicious activity by injecting tracking codes into legitimate links, which allowed them to earn revenue off of users' purchases. <a href="https://www.tomsguide.com/news/malicious-chrome-extensions-with-1-million-downloads-can-hijack-your-browser-delete-these-now">Search hijacking</a>, where search queries are redirected, was also one of the behaviors the researchers saw. Search queries were logged, monetized, sold, manipulated and exfiltrated. </p><p>ShadyPanda can collect a range of personal information from users including browsing history, search queries, keystrokes, cookies, local and session storage, fingerprint data, and mouse clicks with coordinates. The extensions that had gained a “good” reputation were modified throughout the years to include a backdoor update that permitted an hourly remote code execution; downloading and executing arbitrary JavaScript with full browser access. This means they were capable of monitoring every website a user visited and exfiltrating browsing URLs, fingerprinting information and persistent identifiers. </p><p>Most concerningly, the extensions were able to stage adversary in the middle (AitM) attacks which means they were capable of facilitating credential theft, session hijacking and injecting code into any website. Additionally, any attempt to access the browser’s developer tools will cause it to switch to benign behavior. </p><p>While Google has since removed the extensions from the web store, Koi Security noticed the active campaign in the Microsoft Edge Add-ons platform with one extension listed as having 3 million installs.* There is no way of telling if those are inflated numbers, intended to create a sense of legitimacy though. </p><p>*<em>Microsoft has said that this extension has since been removed.</em></p><h2 id="how-to-stay-safe-from-malicious-browser-extensions">How to stay safe from malicious browser extensions</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1280px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZSBEjNnwg2PvoZMCgSydm3" name="DataPrivacy_InBody" alt="Image of man on computer with data security ecosystem" src="https://cdn.mos.cms.futurecdn.net/ZSBEjNnwg2PvoZMCgSydm3.jpg" mos="" align="middle" fullscreen="" width="1280" height="720" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>Most of these extensions are wallpaper or productivity apps and if you've downloaded any of them, you should remove them immediately. While <a href="https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign" target="_blank" rel="nofollow">Koi Security </a>lists all the extensions at the end of their report, three of the most frequently mentioned ones are <strong>Clean Master</strong>, <strong>WeTab</strong> and <strong>Infinity V+</strong>. </p><p>After removing the extensions, you should reset your account passwords –  the recommendation is for all accounts across your entire online presence. Since this could be quite a serious undertaking, you may want to use one of the <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">best password managers</a> to make things easier. Not only can a password manager help keep your passwords organized and safe but they can also automatically create <a href="https://www.tomsguide.com/opinion/im-a-security-editor-and-this-is-how-i-create-strong-passwords-that-are-also-easy-to-remember">strong and unique passwords</a> for each of your online accounts.</p><p>As always, I recommend using the <a href="https://www.tomsguide.com/computing/antivirus/best-antivirus-software">best antivirus software</a> on your computer as well. While an antivirus may not have caught these malicious extensions due to how this campaign operated, they can scan for malware, spyware and viruses even when you slip up and download something that shouldn't be on your machine. Antivirus programs also have browser extensions that can help advise you against visiting suspicious websites, help protect your data with cloud backups and can provide you with a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a> and other extras to add an extra layer of security to protect you when you're online. </p><p>Given how successful and long-running this campaign was, I doubt this is the last we've heard of ShadyPanda. However, by limiting the number of extensions you have installed and carefully vetting each one before you add it to your browser, you can keep your data and your devices safe.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/parental-controls/you-can-control-what-your-kids-see-in-chatgpt-heres-how-to-enable-it">You can control what your kids see in ChatGPT — here's how to enable it</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/new-android-banking-trojan-is-draining-accounts-and-snooping-on-encrypted-chats-how-to-stay-safe">New Android banking trojan is draining accounts and snooping on encrypted chats — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/scammers-are-now-using-your-data-to-craft-personalized-attacks-heres-how-you-can-fight-back">Scammers are now using your data to craft personalized attacks — here's how you can fight back</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Android banking trojan is draining accounts and snooping on encrypted chats — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-android-banking-trojan-is-draining-accounts-and-snooping-on-encrypted-chats-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ A new malware is spoofing banking app logins to help hackers capture your logins and drain your accounts. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DZt7jmPWXEqjSmAkKNwsQo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Nov 2025 19:57:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ scott.younker@futurenet.com (Scott Younker) ]]></author>                    <dc:creator><![CDATA[ Scott Younker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RZsUpqcJ6Uj2q83oCUwNhQ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the latest tech news, including phones, computing and more. He’s been involved in tech since 2011 covering everything from cameras and swimming pool equipment to the latest gaming consoles and smart TVs. He is on a seemingly never ending hunt to build the easiest to use home media system. &lt;/p&gt;&lt;p&gt;Before Tom’s Guide, Scott worked for publications like &lt;em&gt;Digital Trends, Outdoor Photographer, Dead Beats Panel&lt;/em&gt;, and in a brief detour, &lt;em&gt;America’s Funniest Home Videos&lt;/em&gt;. Yes, he has seen more pratfalls, silly pets and ridiculous home movie fails than is reasonably healthy. &lt;/p&gt;&lt;p&gt;When not writing about the latest devices or advances in chipsets, be sure to ask about Scott about disc golf and sustainability, or just if you’re being cheeky, ask about his noodle arm. If you truly want to get nerdy, bring up board games and his ongoing losing streak. &lt;/p&gt;&lt;p&gt;Scott joined Tom&#039;s Guide in 2024 as the West Coast Reporter. He graduated from the School of Journalism at the University of Oregon with a degree in magazine journalism and a minor in communications. While there he blogged or wrote for several magazines including the Fluxx, Ethos and the Oregon Commentator. He briefly wrote and managed a moderately successful blog focused on web comics. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:description>                                                            <media:text><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Earlier this year, Google announced plans to <a href="https://www.tomsguide.com/computing/malware-adware/google-wants-to-fight-android-malware-by-making-sideloading-more-difficult-heres-how">make sideloading apps significantly harder </a>to do on the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a>. However, many Android owners <a href="https://www.tomsguide.com/phones/android-phones/googles-about-to-ruin-one-of-the-best-things-about-android-and-make-it-more-like-ios">did not welcome this controversial move</a>.</p><p>Now though, fans of sideloading apps might want to reconsider thanks to a new malware strain that can bypass encrypted chats in apps like WhatsApp and Signal and targets financial apps. This new <a href="https://www.tomsguide.com/computing/malware-adware/this-android-banking-trojan-steals-passwords-to-take-over-your-accounts-and-all-it-takes-is-a-single-text-message">banking trojan</a>, dubbed Sturnus, originates in malicious APKs. </p><p>Researchers from MTI Security first discovered Sturnus (via <a href="https://www.threatfabric.com/blogs/sturnus-banking-trojan-bypassing-whatsapp-telegram-and-signal" target="_blank">ThreatFabric</a>) and noted it can bypass some security measures by gaining high-level access to the contents of your screen which allows it to view those encrypted chats you thought were safe from prying eyes.</p><p>The malware can also recreate banking screens using <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-banking-trojan-now-shows-a-fake-lock-screen-to-steal-your-pin-and-your-cash-dont-fall-for-this">overlay attacks</a> to phish your login credentials and launch device-level attacks. This means that cybercriminals could remotely control take over your device. Likewise, it can also create <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-banking-trojan-uses-fake-google-play-updates-to-take-over-your-phone-how-to-stay-safe">fake Android updates</a> to hide its activity.</p><h2 id="how-sturnus-works">How Sturnus works</h2><p>According to ThreatFabric, Sturnus has been used in attacks in both Southern and Central Europe, which the cybersecurity firm claim suggests preparations for a "broader campaign."</p><p>The malware apparently uses a "chaotic mix" of plaintext, RSA and AES communications that it switches unpredictably between while sending out simple and complex messages. </p><p>According to the researchers, they suspect the malware may be transmitted via rogue attachments in messaging apps. It propagates by disguising itself as fake versions of <a href="https://www.tomsguide.com/computing/online-security/critical-chrome-zero-day-flaw-fixed-by-google-update-your-browser-right-now">Google Chrome</a> and other popular apps. From there, it then gains Admin rights on the phone which enables the malware to prevent itself from being uninstalled and locking the device.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:960px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XU3My3XF3XuXcvTz3c2QMN" name="Sturnus" alt="Sturnus android banking trojanware" src="https://cdn.mos.cms.futurecdn.net/XU3My3XF3XuXcvTz3c2QMN.jpg" mos="" align="middle" fullscreen="" width="960" height="540" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: ThreatFabric)</span></figcaption></figure><p>While Sturnus is designed to get around encrypted conversations, it sends stolen data back to hacker-controlled servers using an encrypted 256-bit AES key.</p><p>Sturnus appears to be in its "pre-development" stages, but the researches say it could be used as for advanced attacks right now. Unfortunately, given how dangerous it ism the only way to prevent it at the moment is to avoid downloading APK files online to sideload Android apps.</p><p>A Google spokesperson told Android Authority that according to their detection programs, there are no <a href="https://www.tomsguide.com/computing/malware-adware/these-12-malicious-android-apps-are-recording-your-conversations-delete-them-right-now">malicious apps</a> in the which Play Store contain Sturnus. </p><h2 id="how-to-stay-safe-from-android-malware">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.50%;"><img id="isJ69yLbLrdiB6eP7kvmXG" name="lock-holograph-shst.jpg" alt="Digitally created image of a ghostly digital lock being touched by a human hand." src="https://cdn.mos.cms.futurecdn.net/isJ69yLbLrdiB6eP7kvmXG.jpg" mos="" align="middle" fullscreen="" width="1000" height="565" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: sdecoret/Shutterstock)</span></figcaption></figure><p>First of all, to avoid falling victim to Sturnus and other Android malware strains, you shouldn't sideload apps on your devices.</p><p>Doing so puts you at serious risk of being plagued by malware, adware, <a href="https://www.tomsguide.com/computing/malware-adware/this-android-spyware-is-posing-as-an-antivirus-app-to-steal-your-photos-and-passwords-how-to-stay-safe">spyware</a> and other threats. Apps found in unofficial third-party app stores or downloaded as APK files don't go through the same rigorous security checks as they would on the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a> or other first-party stores like the Samsung Galaxy Store.</p><p>Beyond not sideloading apps, you also want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> is enabled on your Android smartphone or tablet. This pre-installed security app scans all of your existing apps and any new ones you download for malware and other threats. However, you should also consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it for extra protection.</p><p>Malicious apps are one the easiest ways for hackers and other cybercriminals to establish a foothold on your devices. So it's up to you to carefully vet every app you install.  Sticking to official, first-party app stores and limiting the number of apps installed on your phone should keep you relatively safe from  Sturnus and other malware strains too.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/these-12-malicious-android-apps-are-recording-your-conversations-delete-them-right-now">These 12 malicious Android apps are recording your conversations — delete them right now</a></li><li><a href="https://www.tomsguide.com/round-up/best-android-apps">Best Android apps — free and paid</a></li><li><a href="https://www.tomsguide.com/phones/google-pixel-phones/dogs-and-cats-living-together-google-announces-android-quick-share-now-works-with-airdrop">Dogs and cats living together! Google announces Android Quick Share now works with AirDrop</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ These older Asus routers are under attack from new malware — see if you're impacted now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-infecting-older-asus-routers-with-malware-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Several older Asus routers are being targeted by a new malware campaign, and users should follow these steps to stay protected. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jepdQcb56aSeVjVA6vcVph</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Nov 2025 19:03:52 +0000</pubDate>                                                                                                                                <updated>Thu, 20 Nov 2025 19:05:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over the past six months, researchers at <a href="https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/" target="_blank">SecurityScored’s STRIKE team</a> have identified a new WrtHug campaign that's been scanning for compromised devices. They’ve found 50,000 unique IPs globally that appear to have been affected by the <a href="https://www.tomsguide.com/computing/malware-adware/this-android-malware-has-your-debit-card-and-pin-and-its-making-withdrawals">malware campaign</a> which targets end-of-life and outdated Asus router models. It then uses six vulnerabilities to hijack them and leaves vulnerable routers open for other hackers to use them for a variety of malicious activities. </p><p>Most of the identified and affected models that have been located were found in Taiwan, followed by Southeast Asia, Russia, Central Europe and the United States. The following Asus models are the ones currently being targets in this campaign:</p><ul><li><strong>• ASUS Wireless Router 4G-AC55U</strong></li><li><strong>• ASUS Wireless Router 4G-AC860U</strong></li><li><strong>• ASUS Wireless Router DSL-AC68U</strong></li><li><strong>• ASUS Wireless Router GT-AC5300</strong></li><li><strong>• ASUS Wireless Router GT-AX11000</strong></li><li><strong>• ASUS Wireless Router RT-AC1200HP</strong></li><li><strong>• ASUS Wireless Router RT-AC1300GPLUS</strong></li><li><strong>• ASUS Wireless Router RT-AC1300UHP</strong></li></ul><p>The attacks begin with an exploitation of a command injection flaw as well as other known vulnerabilities. The STRIKE team believes that the compromised routers might be used as operational relay box (ORB) networks in relay nodes to hide <a href="https://www.tomsguide.com/news/move-over-joker-harly-malware-infects-millions-of-android-phones">command-and-control</a> (C2) operations but there are no further details in their report. </p><p>Asus issued security updates to address all six vulnerabilities used in the attacks, making it critical for router owners to update their firmware in a timely manner. Devices that are old enough to no longer be covered under support, should be replaced or have their remote access features disabled. Some of the flaws currently being exploited include: </p><ul><li><strong>CVE-2023-39780</strong> which is a major command injection flaw (also used in the AyySSHush campaign).</li><li><strong>CVE-2024-12912</strong> which is an arbitrary command execution flaw.</li><li><strong>CVE-2025-2492</strong> which is an improper authentication control flaw with a critical severity rating which can lead to unauthorized execution of functions. It can be triggered by a crafted request on routers that have Asus' AiCloud feature enabled.</li></ul><h2 id="how-to-keep-your-router-safe">How to keep your router safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4yMSsLX6mnBnQdtmWDpokE" name="shutterstock_1393698617-2.jpg" alt="A person trying to set up a new Wi-Fi router" src="https://cdn.mos.cms.futurecdn.net/4yMSsLX6mnBnQdtmWDpokE.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>If you own an outdated router and especially one that's reached its end-of-life and is no longer supported, it's probably best to replace it right away with one of the <a href="https://www.tomsguide.com/us/best-wifi-routers,review-2498.html">best Wi-Fi routers</a> instead. This way, your router will receive frequent software updates and security patches from their manufacturer.</p><p>However, regardless of your router model you should always apply all available security patches and firmware updates as soon as possible. Likewise, you also want to use a <a href="https://www.tomsguide.com/opinion/im-a-security-editor-and-this-is-how-i-create-strong-passwords-that-are-also-easy-to-remember">strong and unique password</a> with at least 16 characters to secure your home network. To make things easier, you can always use one of the <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">best password managers</a> to generate one for you and then securely store it. Additionally, you can disable remote administration and reboot the device as this feature is often leveraged by hackers in their attacks.</p><p>It’s also a good idea to make sure that you’re using the<a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"> best antivirus software</a> on all of your devices as many of them offer additional security features such as a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a> that can help protect your privacy when you’re online.</p><p>By using a new router with frequent security updates, you're essentially adding an extra layer of protection for all of the devices on your home network. If you want the latest and greatest Wi-Fi tech and have the budget for it, one of the <a href="https://www.tomsguide.com/best-picks/best-Wi-fi-7-routers">best Wi-Fi 7 routers</a> will provide you with the best overall experience. However, if you don't mind not having access to the faster <a href="https://www.tomsguide.com/face-off/wi-fi-6e-vs-wi-fi-7-whats-the-difference">6GHz band</a>, one of the <a href="https://www.tomsguide.com/best-picks/best-wi-fi-6-routers">best Wi-Fi 6 routers</a> will still be a major upgrade.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/cybercriminals-are-preparing-for-black-friday-with-new-ai-powered-scams-and-attacks-how-to-shop-safely-this-year">Black Friday shoppers under attack from AI-powered scams — here's how to spot them before it's too late</a></li><li><a href="https://www.tomsguide.com/computing/online-security/1-3-billion-leaked-passwords-exposed-online-in-massive-new-collection-what-to-do-now-and-how-to-check-your-passwords">1.3 billion leaked passwords exposed online in massive new collection — what to do now and how to check your passwords</a></li><li><a href="https://www.tomsguide.com/computing/online-security/critical-chrome-zero-day-flaw-fixed-by-google-update-your-browser-right-now">Critical Chrome zero-day flaw fixed by Google — update your browser right now</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Samsung phones infected with 'Landfall' spyware through WhatsApp images — what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/samsung-phones-infected-with-landfall-spyware-through-whatsapp-images-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ This malware can infect Samsung devices through malicious WhatsApp images and it doesn't require any user interaction. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">J48YQBeGwwkoQssLZWhNmG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VJpN6Qi85YnjEaC7LbLk9D-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Nov 2025 18:33:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VJpN6Qi85YnjEaC7LbLk9D-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Samsung galaxy s24 and galaxy s24 plus]]></media:description>                                                            <media:text><![CDATA[Samsung galaxy s24 and galaxy s24 plus]]></media:text>
                                <media:title type="plain"><![CDATA[Samsung galaxy s24 and galaxy s24 plus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VJpN6Qi85YnjEaC7LbLk9D-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Last week, the cybersecurity team at <a href="https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/" target="_blank" rel="nofollow">Palo Alto Networks' Unit 42 </a> published a report that detailed their discovery of a vulnerability on the <a href="https://www.tomsguide.com/best-picks/best-samsung-phone">best Samsung phones</a>. The bug, tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21042" target="_blank" rel="nofollow">CVE-2025-21042</a>, exploits a flaw in the image processing library that left users vulnerable to a zero-day exploit for months. </p><p>Called “Landfall,” the exploit was patched by Samsung in April. However, it does appear that it had been left open since mid-2024, leaving select users vulnerable to malicious image files that could have been embedded in WhatsApp messages. These malicious DNG files may have been labeled as .jpeg files to make them appear more legitimate too. Landfall, as a <a href="https://www.tomsguide.com/news/chrome-zero-day-redux">zero-day flaw</a>, would not have required any interaction from the user in order to infect the device. </p><p>The impacted devices include the following:</p><ul><li><strong>Galaxy S22 series </strong></li><li><strong>Galaxy S23 series </strong></li><li><strong>Galaxy S24 series</strong></li><li><strong>Galaxy Z Fold 4</strong></li><li><strong>Galaxy Z Flip 4 </strong></li></ul><h2 id="what-the-spyware-records">What the spyware records</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="8EMYJM7c2XjG883ztUVnrS" name="shutterstock_582843328.jpg" alt="Spyware" src="https://cdn.mos.cms.futurecdn.net/8EMYJM7c2XjG883ztUVnrS.jpg" mos="" align="middle" fullscreen="" width="2000" height="1124" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Once installed, the spyware is capable of recording audio, accessing and and collecting data from photos, contacts, location and call logs among other capabilities. Landfall targeted specific Samsung devices throughout the Middle East, including Iraq, Iran, Turkey and Morocco. </p><p>Again, Samsung owners are now protected from the threat as the company was informed of the danger back in September 2024 and issued a fix in April. CISA (Cybersecurity and Infrastructure Security Agency), has ordered federal agencies to patch any affected Samsung devices and it also added the bug to the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-21042" target="_blank" rel="nofollow">Known Exploited Vulnerabilities</a> catalog, which lists security bugs that are flagged as actively exploited in attacks. The federal agencies have until December 1st to secure vulnerable devices. </p><h2 id="how-to-stay-safe-from-spyware">How to stay safe from spyware </h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="Jzwhquu4gv5ZQF336dDbZE" name="android malware.jpg" alt="Green skull on smartphone screen." src="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE.jpg" mos="" align="middle" fullscreen="" width="2000" height="1124" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Because Landfall has already been corrected through a patch, one of the best ways to ensure that you can avoid this malware – and other serious threats – is to always keep your phone's operating system up-to-date. This keeps your device protected against recent and newer threats as updates often include security patches as well as other new features that can help protect you online. </p><p>At the same time, you also want to be wary about who you connect with online and what you click on, download and install. The usual <a href="https://www.tomsguide.com/computing/online-security/what-is-social-engineering">social engineering</a> and <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing</a> rules apply here too – if you don't know who sent the link or download, you don't need to click on it or install it. </p><p>In order to stay protected, it's also advisable that you use one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> on your device alongside <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> as they often additional additional security features like a VPN, browser warnings about suspicious sites and both phishing and scam alerts. </p><p>Zero-day flaws are just something that phone makers have to deal with as hackers are always looking for a new, undiscovered way to gain access to our devices. However, by keeping your phone updated and practicing good cyber hygiene, you can avoid falling victim to a majority of the attacks that leverage them.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/this-android-malware-has-your-debit-card-and-pin-and-its-making-withdrawals">This Android malware has your debit card and PIN — and it’s making withdrawals</a></li><li><a href="https://www.tomsguide.com/computing/online-security/that-text-claiming-to-have-found-your-lost-iphone-could-actually-be-from-scammers-dont-fall-for-this-phishing-scam">Phishing scam alert: This "We found your lost iPhone" text is fake and wants to steal your Apple ID</a></li><li><a href="https://www.tomsguide.com/computing/online-security/your-personal-information-is-everywhere-online-5-ways-to-start-removing-it">Your personal information is everywhere online — 5 ways to start removing it from the internet</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Android malware has your debit card and PIN — and it’s making withdrawals ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-android-malware-has-your-debit-card-and-pin-and-its-making-withdrawals</link>
                                                                            <description>
                            <![CDATA[ Dangerous new NGate Android malware uses NFC to steal debit card and PIN info so that hackers can make cash withdrawals from ATMs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">z9YYhfWRB785o5iXosjPf9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PoEqQyXuATwMvtLV5s5VYL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Nov 2025 19:01:08 +0000</pubDate>                                                                                                                                <updated>Tue, 11 Nov 2025 20:04:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PoEqQyXuATwMvtLV5s5VYL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shuterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware]]></media:description>                                                            <media:text><![CDATA[Android malware]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PoEqQyXuATwMvtLV5s5VYL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Besides digitally draining your bank account, hackers  can now steal your card details to make cash withdrawals right from an ATM.</p><p>The Polish Computer Emergency Response Team (CERT Polska) has discovered a new <a href="https://www.tomsguide.com/computing/malware-adware/google-warns-of-ai-infused-malware-thats-harder-to-detect-than-normal-viruses">malware strain </a>that targets Android devices in order to steal debit card details and PIN information which are then used by hackers  to make ATM withdrawals. </p><p>According to the <a href="https://www.malwarebytes.com/blog/news/2025/11/android-malware-steals-your-card-details-and-pin-to-make-instant-atm-withdrawals" target="_blank" rel="nofollow">Malwarebytes Blog</a>, the NGate malware uses both <a href="https://www.tomsguide.com/computing/online-security/what-is-social-engineering">social engineering</a> and NFC technology to exfiltrate banking data from a victim’s phone and then an accomplice drains their account. Surprisingly no one ever has to physically steal or touch a victim's bank card to access their account. </p><p>NFC (near field communication) is a wireless technology that lets devices communicate when nearby and it’s used in smartphones, payment cards and terminals. When a mobile device is infected with the NGate malware, attackers can capture the NFC activity, forward the transaction data to devices at nearby ATMs and the stolen data is then used by an accomplice on a phone or smartwatch to take out cash. However, this sophisticated attack takes planning and requires multiple steps. </p><p>First the malware needs to be installed on the targeted device. For this, it's usually planted via social engineering tricks like <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing emails</a> or SMS messages with warnings about fake security or technical issues with a bank account. Sometimes these fake messages are followed up with a phone call to make them appear more legitimate; the caller will then ask potential victims to download a “banking app” to help fix the issue. The app is usually from a non-official source (not the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store)</a>, and will ask for <a href="https://www.tomsguide.com/computing/malware-adware/scammers-are-tricking-android-users-into-installing-a-fake-antivirus-app-thats-actually-malware-how-to-stay-safe">unnecessary permissions</a> and financial information.</p><p>Once it has led the target though fake card verification, the accomplice has been fed the appropriate information to start using the debit card and PIN data at a nearby ATM. The victim often has no idea that they have been tricked. This is a sophisticated attack method not only due to the various steps involved but also because the one-time dynamic codes that are generated for the NFC technology are temporary which means they have to be used quickly. </p><h2 id="how-to-stay-safe-from-ngate-malware">How to stay safe from NGate malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:61.80%;"><img id="9YfNYu2ZNUUMFt9838R46Y" name="shutterstock_1452139694.jpg" alt="Security padlock icon on a smartphone" src="https://cdn.mos.cms.futurecdn.net/9YfNYu2ZNUUMFt9838R46Y.jpg" mos="" align="middle" fullscreen="" width="1000" height="618" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tero Vesalainen / Shutterstock)</span></figcaption></figure><p>This malware is specific in that it requires multiple steps, so it can be easy to avoid if you can make sure to protect yourself from the layers of attack. First off, make sure to look out for social engineering tactics when dealing with strangers or those who claim to represent a bank or other business. Likewise, only  download apps from the Google Play Store or trusted developers. Whatever you do, absolutely don't download banking and financial apps  from links sent to you through social media, texts or unknown sources. </p><p>You also want to make sure you don't give out financial information to people you don't know. Never click on links, download anything, or use <a href="https://www.tomsguide.com/computing/online-security/new-qr-code-threat-can-infect-your-phone-as-soon-as-you-scan">QR codes</a> from strangers too. If someone calls, emails or texts claiming to be from your financial institution and says there is a problem with your account, delete the email, hang up, or block the text sender and reach out to your provider through an independent manner – a phone number you find on your debit card or account statement is always a good idea. </p><p>At the same time, you can also protect your mobile devices just like your laptop or computer with antivirus software. We highly recommend the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> as they can scan for malware, provide phishing protection and even turn off apps that might pose a security risk. However,  if you already have a subscription to the<a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"> best antivirus software </a>for your computer, you may already have the option to secure your mobile devices through it, so check with your antivirus provider to see what kind of mobile protection it offers.</p><p>Hackers and cybercriminals keep coming up with new ways to con you out of your hard-earned cash which is why its pays (literally) to stay on top of the latest attack methods and threats. And once you do, make sure you share that knowledge with your family and friends too, so they can avoid falling victim to a dangerous attack like this one.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/clickfix-attacks-just-got-a-major-upgrade-to-trick-you-into-infecting-your-computer-with-malware-dont-fall-for-this">Don’t fall for this – ClickFix attacks now include video instructions and can recognize your operating system</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/google-warns-of-ai-infused-malware-thats-harder-to-detect-than-normal-viruses">Google issues security warning for millions — AI-powered malware is here</a></li><li><a href="https://www.tomsguide.com/computing/online-security/hundreds-of-malicious-apps-have-been-downloaded-42-million-times-from-the-google-play-store-how-to-stay-safe">Over 200 malicious apps were downloaded more than 40 million times from the Google Play Store this year</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Don’t fall for this – ClickFix attacks now include video instructions and can recognize your operating system ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/clickfix-attacks-just-got-a-major-upgrade-to-trick-you-into-infecting-your-computer-with-malware-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ ClickFix style attacks now includes video tutorials and OS recognition in order to fool victims into downloading malware onto their computers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yUNQgHkgaKP9aJcJ3fYQte</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LffG4UEQCjsU968KtChAC9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Nov 2025 19:15:17 +0000</pubDate>                                                                                                                                <updated>Fri, 07 Nov 2025 18:05:54 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LffG4UEQCjsU968KtChAC9-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LffG4UEQCjsU968KtChAC9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ClickFix style attacks, which have already become an increasingly popular <a href="https://www.tomsguide.com/computing/online-security/what-is-social-engineering">social engineering tool</a> to spread malware, have now evolved to include new steps to trick users into infecting their own computers. As reported by <a href="https://www.bleepingcomputer.com/news/security/clickfix-malware-attacks-evolve-with-video-instructions-and-os-detection/" target="_blank" rel="nofollow">BleepingComputer</a>, the malware now features video instructions that guide victims through the download process in order to help them unknowingly give their machines a <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-this-little-know-file-type-to-drop-a-nasty-windows-worm-on-vulnerable-pcs-how-to-stay-safe">nasty malware infection</a>. </p><p>In <a href="https://www.tomsguide.com/computing/malware-adware/new-filefix-attack-brings-clickfix-social-engineering-to-windows-file-explorer-how-to-stay-safe">previous ClickFix attacks</a>, targets have been fooled by social engineering style tricks – sometimes a false identity verification request or a software problem that requires a “fix” – which then leads them to a <a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-over-free-online-file-converters-that-infect-your-pc-with-malware">malicious webpage</a> that requires them to copy, paste and execute code or commands. Doing so launches a payload, typically an infostealer that harvests personal or sensitive data from the victim's computer which is then sent back to the attackers. </p><p>These new ClickFIx attacks operate in much the same way. However, in the past, they would provide text instructions to trick victims into downloading code. Now though, these upgraded attacks provide embedded video which is designed to make the attack feel less suspicious to the target. </p><p>A threat actor can hide commands using JavaScript and copy them onto a user's clipboard which reduces the chance of them making any mistakes. In the same window, a timer may appear that's designed to invoke a sense of pressure and may make potential victims feel as if they're required to take action quickly. This also removes their ability to take the necessary time to verify the authenticity of the website or go through a proper, multi-step verification process.</p><p>Sometimes there may also be a counter which reads “users verified in the last hour” to add a feeling of legitimacy while making the window appear as if it's a Cloudflare bot check tool. </p><p>ClickFix attacks have been observed on all major operating systems, <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-attack-from-malware-impersonating-popular-password-managers-how-to-stay-safe">including macOS</a> and Linux, however the automatic detection of the operating system and adjustment of the instructions is another new development much like these new video tutorials. </p><p>In a <a href="https://pushsecurity.com/blog/the-most-advanced-clickfix-yet/">blog post</a>, Push Security reveals that these advanced-style attack pages are being promoted through <a href="https://www.tomsguide.com/news/hackers-have-found-an-insidious-way-to-attack-you-with-malware-dont-fall-for-this">malvertising</a> or malicious advertising on Google Search, exploiting known flaws in outdated WordPress plugins that compromise legitimate websites which have malicious JavaScript injected on the pages or sites that are “vibe coded” to use SEO poisoned tactics to make them rank higher in results.</p><h2 id="how-to-stay-safe-from-clickfix-attacks">How to stay safe from ClickFix attacks</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="EZMvT9THPzqSi99JAFMEKG" name="shutterstock_1773876581-16x9edit2" alt="Hands typing on a laptop computer with a lock icon" src="https://cdn.mos.cms.futurecdn.net/EZMvT9THPzqSi99JAFMEKG.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The hackers behind ClickFix campaigns use your preexisting knowledge and online habits to get you to do something you otherwise normally wouldn't. They might also use a <a href="https://www.tomsguide.com/news/unpaid-invoices-are-one-of-the-easiest-ways-scammers-try-and-trick-you-what-to-look-out-for">sense of urgency</a> to get you to visit one of the malicious sites used in this campaign.</p><p>If you do see a verification pop-up with instructions, close the website immediately and whatever you do, don’t interact with it or follow its instructions.</p><p>Being asked to open a Terminal or Command Prompt window on your computer is a <a href="https://www.tomsguide.com/news/this-is-the-one-thing-to-look-out-for-in-scam-emails">major red flag</a>. Researchers have recommended that users remember that executing code on the terminal should never be a part of any online based verification process and no copied commands should ever be executed unless the user fully understands what they will do. </p><p>It also never hurts to have strong protections when online – one of the<a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"> best antivirus software </a>solutions can keep your Windows PCs protected while the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> is specifically designed for your Apple computer. These paid solutions also provide you with plenty of useful extra features like secure browsers that warn you about suspicious websites and downloads, ransomware rollback, a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a>, and more.</p><p>Given that ClickFix attacks have been quite successful so far since it's the victims and not the hackers doing most of the work, I seriously doubt cybercriminals are going to stop using these tactics anytime soon. That's why it's up to you to be extremely careful online and practice good cyber hygiene at all times.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/google-warns-of-ai-infused-malware-thats-harder-to-detect-than-normal-viruses">Google issues security warning for millions — AI-powered malware is here</a></li><li><a href="https://www.tomsguide.com/computing/online-security/hundreds-of-malicious-apps-have-been-downloaded-42-million-times-from-the-google-play-store-how-to-stay-safe">Over 200 malicious apps were downloaded more than 40 million times from the Google Play Store this year</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/these-12-malicious-android-apps-are-recording-your-conversations-delete-them-right-now">These 12 malicious Android apps are recording your conversations — delete them right now</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google issues security warning for millions — AI-powered malware is here  ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/google-warns-of-ai-infused-malware-thats-harder-to-detect-than-normal-viruses</link>
                                                                            <description>
                            <![CDATA[ Google has warned that AI-powered malware is circulating that is virulent and harder to detect than most malware. Here's why, and what it means for you. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zwFusAS6WLnukT4QsmGPrK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Mi5yorDM6vJfkbFWJ7UyPF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Nov 2025 22:13:29 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Nov 2025 16:48:24 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ scott.younker@futurenet.com (Scott Younker) ]]></author>                    <dc:creator><![CDATA[ Scott Younker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RZsUpqcJ6Uj2q83oCUwNhQ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the latest tech news, including phones, computing and more. He’s been involved in tech since 2011 covering everything from cameras and swimming pool equipment to the latest gaming consoles and smart TVs. He is on a seemingly never ending hunt to build the easiest to use home media system. &lt;/p&gt;&lt;p&gt;Before Tom’s Guide, Scott worked for publications like &lt;em&gt;Digital Trends, Outdoor Photographer, Dead Beats Panel&lt;/em&gt;, and in a brief detour, &lt;em&gt;America’s Funniest Home Videos&lt;/em&gt;. Yes, he has seen more pratfalls, silly pets and ridiculous home movie fails than is reasonably healthy. &lt;/p&gt;&lt;p&gt;When not writing about the latest devices or advances in chipsets, be sure to ask about Scott about disc golf and sustainability, or just if you’re being cheeky, ask about his noodle arm. If you truly want to get nerdy, bring up board games and his ongoing losing streak. &lt;/p&gt;&lt;p&gt;Scott joined Tom&#039;s Guide in 2024 as the West Coast Reporter. He graduated from the School of Journalism at the University of Oregon with a degree in magazine journalism and a minor in communications. While there he blogged or wrote for several magazines including the Fluxx, Ethos and the Oregon Commentator. He briefly wrote and managed a moderately successful blog focused on web comics. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Mi5yorDM6vJfkbFWJ7UyPF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google ]]></media:description>                                                            <media:text><![CDATA[Google ]]></media:text>
                                <media:title type="plain"><![CDATA[Google ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Mi5yorDM6vJfkbFWJ7UyPF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google's Threat Intelligence Group (GTIG) is warning that bad guys are using artificial intelligence to create and deploy new malware that both utilizes and combats large language models (LLM) like Gemini when deployed. </p><p>The findings were laid out in a <a href="https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools" target="_blank">white paper released</a> on Wednesday, November 5 by the GTIG. The group noted that adversaries are no longer leveraging artificial intelligence (AI) just for productivity gains, they are deploying "novel AI-enabled malware in active operations." They went on to label it a new "operational phase of AI abuse."</p><h2 id="malware-families">Malware families</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:988px;"><p class="vanilla-image-block" style="padding-top:69.53%;"><img id="H9qWKtzAYH4j8UNKF5vZzS" name="misuse-of-ai-two-fig1.max-1000x1000" alt="AI-powered malware found by Google Threat Integlligence Group" src="https://cdn.mos.cms.futurecdn.net/H9qWKtzAYH4j8UNKF5vZzS.png" mos="" align="middle" fullscreen="1" width="988" height="687" attribution="" endorsement="" class="expandable"><a href='https://cdn.mos.cms.futurecdn.net/H9qWKtzAYH4j8UNKF5vZzS.png' target='_blank' class='expand-button icon-expand-image icon' ></a></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Google is calling the new tools "just-in-time" AI used in at least two malware families: PromptFlux and PromptSteal, both of which use LLMs during deployment. They generate malicious scripts and obfuscate their code to avoid detection by antivirus programs. Additionally, the malware families use AI models to create malicious functions "on demand" rather than being built into the code.</p><p>Google says these tools are a nascent but significant step towards "autonomous and adaptive malware."</p><p>PromptFlux is an experimental VBScript dropper that utilizes Google Gemini to generate obfuscated VBScript variants. VBScript is mostly used for automation in Windows environments.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1073px;"><p class="vanilla-image-block" style="padding-top:139.79%;"><img id="Su7NBWC9LRZPzbS3SBbY6T" name="misuse-of-ai-fig4d.max-1500x1500" alt="AI-powered malware found by Google Threat Integlligence Group" src="https://cdn.mos.cms.futurecdn.net/Su7NBWC9LRZPzbS3SBbY6T.png" mos="" align="middle" fullscreen="1" width="1073" height="1500" attribution="" endorsement="" class="expandable"><a href='https://cdn.mos.cms.futurecdn.net/Su7NBWC9LRZPzbS3SBbY6T.png' target='_blank' class='expand-button icon-expand-image icon' ></a></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>In this case, PromptFlux attempts to access your PC via Startup folder entries and then spreads through removable drives and mapped network shares.</p><p>"The most novel component of PROMPTFLUX is its 'Thinking Robot' module, designed to periodically query Gemini to obtain new code for evading antivirus software," GTIG says.</p><p>The researchers say that the code indicates the malware's makers are trying to create an evolving "metamorphic script."</p><p>According to Google, the Threat Intelligence researchers could not pinpoint who made PromptFlux, but did note that it appears to be used by a group for financial gain. Google also claims that it is in early development and can't yet inflict real damage. </p><p>The company says that it has disabled the malware's access to Gemini and deleted assets connected to it.</p><p>Google also highlighted a number of other malware that establish remote command-and control (FruitShell), capturing GitHub credentials (QuietVault), and one that steals and encrypts data on Windows, macOS and Linux devices (PromptLock). All of them utilize AI to work or in the case of FruitShell to bypass LLM-powered security.</p><h2 id="gemini-abuse">Gemini abuse</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2096px;"><p class="vanilla-image-block" style="padding-top:56.39%;"><img id="gHfBJ6FBHKnLbW36hEDvgV" name="Gemini Gems banner.png" alt="Google Gemini" src="https://cdn.mos.cms.futurecdn.net/gHfBJ6FBHKnLbW36hEDvgV.png" mos="" align="middle" fullscreen="" width="2096" height="1182" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Beyond malware, the paper also reports several cases where threat actors abused Gemini. In one case, a malicious actor posed as a "capture-the-flag" participant, basically acting as a students or researchers to convince Gemini to provide information that is supposed to be blocked.</p><p>Google specified a number of threats from Chinese, Iranian and North Korean threat groups that abused Gemini for phishing, data mining, increasing malware sophistication, crypto theft and creating deepfakes.</p><p>Again, Google says it has disabled the associated accounts in identified cases and reinforced its model safeguards. The company goes on to says that underground marketplaces for malicious AI-based tools is growing. </p><p>"Many underground forum advertisements mirrored language comparable to traditional marketing of legitimate AI models, citing the need to improve the efficiency of workflows and effort while simultaneously offering guidance for prospective customers interested in their offerings," the company wrote.</p><p>With AI getting more sophisticated, this seems to indicate a trend of replacing conventional malicious tools with new AI-based ones.</p><h2 id="google-s-ai-approach">Google's AI approach</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2688px;"><p class="vanilla-image-block" style="padding-top:57.14%;"><img id="HUqR5UDqPeCw6FAi2ELtJE" name="ai models" alt="ai models" src="https://cdn.mos.cms.futurecdn.net/HUqR5UDqPeCw6FAi2ELtJE.png" mos="" align="middle" fullscreen="" width="2688" height="1536" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Freepik)</span></figcaption></figure><p>The paper wraps up by advocating that AI developers need to be "both bold and responsible" and that AI systems must be designed with "strong safety guardrails" to prevent these kinds of abuses.</p><p>Google says that it investigates signs of abuse in its products and uses the experience of combating bad actors to "improve safety and security for our AI models."</p><h2 id="how-to-stay-safe">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:66.70%;"><img id="7UiWwShNbtRnUY5RF3TNn9" name="antivirus-macbook-shst.jpg" alt="A person securing their laptop with antivirus software" src="https://cdn.mos.cms.futurecdn.net/7UiWwShNbtRnUY5RF3TNn9.jpg" mos="" align="middle" fullscreen="" width="1000" height="667" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The war against viruses and malware is ever evolving as tools on both sides become more sophisticated especially with the injection of AI.</p><p>There are ways to stay safe. As always, be wary of links and external content. If an AI tool is be used to summarize a web page, PDF, or email that content could be malicious or contain a hidden prompt to attack the AI.</p><p>Additionally, you should always limit AI access to sensitive accounts like bank accounts, email or documents that have sensitive information. Compromised AI could exploit that access. </p><p>Finally, unexpected behavior in an LLM or AI model should be treated as a red flag. If an AI model starts answerint questions strangely, reveals internal knowledge of your PC or worse, tries to perform unusual or unauthorized actions then you should stop that session.</p><p>Make sure you keep your software updated, including the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> and the LLM programs and applications you utilize. this ensures that you have the most recent and patched versions protecting you against known flaws.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/hundreds-of-malicious-apps-have-been-downloaded-42-million-times-from-the-google-play-store-how-to-stay-safe">Hundreds of malicious apps have been downloaded 42 million times from the Google Play Store — how to stay safe</a></li><li><a href="https://www.tomsguide.com/ai/google-maps-gets-the-ai-treatment-with-gemini-integration-heres-all-the-clever-new-things-it-can-do">Google Maps just got a huge AI boost for millions — 4 new upgrades you can try now</a></li><li><a href="https://www.tomsguide.com/ai/google-home-is-rolling-out-a-major-ai-upgrade-heres-what-to-try-first">Google Home is rolling out a major AI upgrade — here’s what to try first</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new Android trojan is taking over phones and draining bank accounts — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-trojan-is-taking-over-phones-and-draining-bank-accounts-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ New Android malware hides in fake apps and then quietly steals passwords and banking info in the background. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">n9P9Vq96eXbGfux9BdoudK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Nov 2025 18:45:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-raton-android-trojan-can-automatically-transfer-money-right-off-your-phone-to-hackers">banking Trojan</a> has been pretending to be legitimate apps, like digital ID apps or news readers, in order to trick victims into downloading it so that it can take over their devices and steal the logins for their financial accounts. According to researchers at<a href="https://www.cyfirma.com/research/investigation-report-android-bankbot-ynrk-mobile-banking-trojan/"> Cyfirma</a>, these Trojan-filled <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now">malicious apps</a> are specifically targeting Android users who have banking and cryptocurrency apps installed. </p><p>The malware is not only capable of stealing sensitive financial data off infected devices, but it also works quietly in the background like an <a href="https://www.tomsguide.com/computing/online-security/macs-under-attack-from-dangerous-new-info-stealing-malware-how-to-stay-safe">infostealer</a>, so it can avoid detection and continue to steal data from victims after the initial heist. Once it’s enabled on one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a>, it can also take over a device and read whatever is on the screen, tap buttons and even fill in forms. Likewise, it uses fake login screens to perform <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-banking-trojan-now-shows-a-fake-lock-screen-to-steal-your-pin-and-your-cash-dont-fall-for-this">overlay attacks</a> on top of real banking and cryptocurrency apps in order to steal any usernames and passwords that are entered by the victim. </p><p>After an initial check to ensure that it’s running on a real phone, it will ask users for special permissions. Like other Android malware it abuses the operating system's which Accessibility Services to do so which it says will help improve the app. However, this actually gives the hackers behind this banking trojan complete control over an infected device while also adding the malware as the device administrator app. This is a common malware tactic which is exactly why we caution against giving apps permissions that they don’t seem to need and why we say that <a href="https://www.tomsguide.com/computing/online-security/5-android-settings-you-need-to-turn-off-right-now-because-theyre-a-huge-security-risk">checking the accessibility services section </a>of your Android phone is a good way to detect potential malware.</p><p>According to the researchers, this Trojan can also connect to a remote center where it will send information about the phone itself including which banking apps are installed, and the handsets location. </p><p>Attackers can even send instructions to the malware and make it perform actions like downloading updates or deleting traces of the malicious activity. The Trojan can also silence notifications and sounds which means that users won't notice any of the malicious activity it's carrying out on their device.</p><p>Researchers say the majority of the activity they have seen from this malware is in Southeast Asia, but there’s not reason that these techniques couldn’t be used in any other country or area. </p><h2 id="how-to-stay-safe-from-android-malware-2">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>In order to protect your data and your devices from malware, the first thing you want to do is to stick to trusted sources and make sure that you're only downloading apps, especially VPNs and streaming services, from first-party app stores like the <a href="https://www.tomsguide.com/news/the-google-play-store-is-making-a-big-change-to-fend-off-malware-heres-how">Google Play Store</a> or from known developer sites. Never install something from a link in a forum or message sent via social media. </p><p>From there, you want to check the permissions requested by an app anytime a new one you've installed asks for control over your device, settings, accessibility services, or if it wants to install other apps. Stop and ask if its necessary. Does it need those permissions and what do you expect it to do with them?</p><p>You also want to use layered and up-to-date protection which is why I recommend installing one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> on your phone alongside <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a>. These security apps can scan for malware, dodgy downloads and any suspicious activity taking place on your device. You always want to keep your security software and your operating system up to date because that ensures that all the vulnerabilities that attackers could exploit are patched promptly.</p><p>Given that we now handle so much of our finances from our mobile devices, hackers likely won't stop developing new banking trojans and using them in their attacks anytime soon. That's why it's up to you to lock down your devices while also being extra careful online.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/these-12-malicious-android-apps-are-recording-your-conversations-delete-them-right-now">These 12 malicious Android apps are recording your conversations — delete them right now</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/fake-whatsapp-and-tiktok-apps-are-trying-to-fool-android-users-into-downloading-spyware-dont-fall-for-this">Fake WhatsApp and TikTok apps are trying to fool Android users into downloading spyware — don't fall for this</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-google-search-results-to-spread-fake-apps-filled-with-malware-dont-fall-for-this">Hackers are using Google search results to spread fake apps filled with malware — don't fall for this</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ These 12 malicious Android apps are recording your conversations — delete them right now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/these-12-malicious-android-apps-are-recording-your-conversations-delete-them-right-now</link>
                                                                            <description>
                            <![CDATA[ These malicious Android apps may appear harmless at first glance but they're actually spreading spyware which can steal texts, record conversations and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wasFKbgC4dAnhG5963BY23</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Nov 2025 18:52:23 +0000</pubDate>                                                                                                                                <updated>Tue, 04 Nov 2025 21:14:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware on phone]]></media:description>                                                            <media:text><![CDATA[Android malware on phone]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Have you ever worried that your phone might be listening in on your private conversations? Or worse, recording them? Well, that's exactly what could be happening if you accidentally installed a malicious app.</p><p>Security researchers at <a href="https://www.welivesecurity.com/en/eset-research/vajraspy-patchwork-espionage-apps/" target="_blank">ESET</a> have identified twelve Android apps that have been secretly recording users audio in the background. These malicious apps are used to infect the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> with a <a href="https://www.tomsguide.com/computing/malware-adware/fake-whatsapp-and-tiktok-apps-are-trying-to-fool-android-users-into-downloading-spyware-dont-fall-for-this">spyware </a>called VajraSpy that's being spread using <a href="https://www.tomsguide.com/computing/online-security/what-is-social-engineering">social engineering techniques</a> on Facebook Messenger and WhatsApp. </p><p>According to the researchers, the attackers first establish relationships with potential victims who are then asked to move their conversations over to another messaging app which is actually a trojan that carries VajraSpy. Once installed on a vulnerable Android phone, the spyware will then steal contact information, as well as messages, call logs and location data and it can even record ambient audio and phone calls. It can also exfilitrate information about the device itself, like its model, operating system version and network identifiers, and then send this data back to the attackers as well.</p><p>Although the ESET research in question was published last year and is currently making the rounds online again right now, some of these apps may still be on your Android device. All 12 apps have since been removed from the Play Store but it's still worth checking to see if any of them are installed on your phone or tablet. If you find any of the 12 below apps on your device, you will need to manually delete them.</p><ul><li><strong>TikTalk</strong></li><li><strong>MeetMe</strong></li><li><strong>Let’s Chat</strong></li><li><strong>Quick Chat</strong></li><li><strong>Chit Chat</strong></li><li>YohooTalk</li><li>Hello Cha</li><li>Rafaqat</li><li>Privee Talk</li><li>Nidus</li><li>GlowChat</li><li>Wave Chat</li></ul><h2 id="how-to-stay-safe-from-spyware-2">How to stay safe from spyware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="8EMYJM7c2XjG883ztUVnrS" name="shutterstock_582843328.jpg" alt="Spyware" src="https://cdn.mos.cms.futurecdn.net/8EMYJM7c2XjG883ztUVnrS.jpg" mos="" align="middle" fullscreen="" width="2000" height="1124" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>There are a few easy ways to stay save from spyware, and one of the main ways is to avoid links to APKs (especially ones sent to you via chat apps) which will need to be sideloaded onto your device. Instead, you should stick to downloads from official Android app stores and always check the developers name and rating, the permissions an app asks for and read the most recent user reviews. </p><p>Likewise, you always want to keep your operating system up-to-date and enable <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> as well. From there, limit app permissions to only what is necessary and watch for any unusual behaviors after your install apps that you're not sure about. Signs that your device may have become compromised include unusual battery drain, unexplained data usage, or persistent background activity you cannot explain. Particularly in the example of VajraSpy, any unexpected microphone prompts are a major warning, and repeated permission requests are a sign that deserve additional attention. </p><p>If you see any of these signs, or notifications that appear briefly and then disappear, or if your contacts are receiving odd messages from you, that's a good indicator that your device may have been infected by malware. </p><p>If your device isn't protected by one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a>, you should make sure that it is covered and that you can look for malware with real-time scans. These programs also offer additional features, like <a href="https://www.tomsguide.com/best-picks/best-vpn">VPNs</a> and scam alerts, that can help protect your privacy and keep you safe online. <br><br>Just because a group of malicious apps came out a long time ago doesn't mean they aren't still doing damage in the real world. This is why I always recommend limiting the number of apps you have installed overall. That way, if one is malicious or it goes bad over time, it will be a lot easier to find.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/70-percent-of-americans-think-antivirus-will-protect-their-online-privacy-heres-the-real-truth">70% of Americans think antivirus will protect their online privacy – here's the real truth</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/fake-whatsapp-and-tiktok-apps-are-trying-to-fool-android-users-into-downloading-spyware-dont-fall-for-this">Fake WhatsApp and TikTok apps are trying to fool Android users into downloading spyware — don't fall for this</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/google-just-took-down-224-malicious-apps-with-38-million-installs-from-the-play-store-how-to-stay-safe">Google just took down 224 malicious apps with 38 million installs in massive SlopAds fraud campaign — how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake WhatsApp and TikTok apps are trying to fool Android users into downloading spyware — don't fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/fake-whatsapp-and-tiktok-apps-are-trying-to-fool-android-users-into-downloading-spyware-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ The ClayRat spyware is tricking Android users into infecting their devices by impersonating popular apps. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YDy2WkqHkLqxtpRLYUFr4B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 10 Oct 2025 18:38:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware on phone]]></media:description>                                                            <media:text><![CDATA[Android malware on phone]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new <a href="https://www.tomsguide.com/computing/malware-adware/this-android-spyware-is-posing-as-an-antivirus-app-to-steal-your-photos-and-passwords-how-to-stay-safe">spyware campaign</a> is mimicking popular apps like TikTok, YouTube and WhatsApp in order to try and lure users into visiting phishing sites and downloading the ClayRat spyware. </p><p>As reported by <a href="https://thehackernews.com/2025/10/new-clayrat-spyware-targets-android.html" target="_blank" rel="nofollow">The Hacker News</a>, this campaign is also using Telegram channels in order to spread the spyware while the <a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-over-free-online-file-converters-that-infect-your-pc-with-malware">malicious sites</a> are using artificially inflated download counts and manufactured testimonials in order to manufacture legitimacy. </p><p>Once installed, the spyware can exfiltrate a large amount of personal data like SMS messages, call logs, notifications and other device information. Additionally, it can take selfies with the front camera, send SMS messages and even place calls according to the researchers at the mobile security company <a href="https://www.tomsguide.com/news/hackers-can-use-this-chrome-extension-to-hijack-your-pc-how-to-stay-safe">Zimperium</a> who discovered it. This is because it requires users make it the default SMS app, which gives it access to sensitive content and message functions. That way, it can capture this sensitive info and then leverage a victim's contacts to spread this malware to other targets. </p><p>Some ClayRat versions act as <a href="https://www.tomsguide.com/news/new-android-malware-dropper-sneaks-past-google-protect-yourself-now">malware droppers</a>, which appear as a lightweight installer that looks like a Play Store update screen. However, an encrypted payload is hidden within the apps assets. Fortunately though, this campaign is only targeting Russian users at the moment. However, in its <a href="https://zimperium.com/blog/clayrat-a-new-android-spyware-targeting-russia" target="_blank">report</a>, Zimperium detected at least 600 samples and 50 droppers in the last 90 days. This indicates that each iteration of the ClayRat campaign is incorporating new layers of obfuscation to bypass being detected by security tools and the spyware could be used to target Android users in the U.S. and other English-speaking countries soon.</p><h2 id="how-to-avoid-spyware-and-malicious-websites">How to avoid spyware and malicious websites</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:56.19%;"><img id="gMi9vtqPLpPYTvdR4TKZbV" name="cwZdsjBoyxVc8tdbUpGiid.jpg" alt="A hacker typing on a computer" src="https://cdn.mos.cms.futurecdn.net/gMi9vtqPLpPYTvdR4TKZbV.jpg" mos="" align="middle" fullscreen="" width="970" height="545" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Android users with <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> are safeguarded against known versions of this malware, as their devices come with this handy security tool pre-installed via Google Play Services. However, it never hurts to remember best practices when it comes to your online safety: Try to stick to known app manufacturers and websites, <a href="https://www.tomsguide.com/news/hackers-often-use-this-clever-trick-to-take-you-to-phishing-sites-can-you-spot-it">check the URLs</a> of websites before visiting them and try not to click on sponsored links or ads as they can be used by hackers in their attacks. </p><p>Additionally, make sure all your devices are protected online with one of the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software </a>solutions. While your phone like comes with Google Play Protect pre-installed, for additional security, you may want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it. At the same time, you want to make full use of extras included with your antivirus app or software like a VPN or a hardened browser and heed any alerts you see regarding potentially suspicious websites. Many of antivirus suites will also feature <a href="https://www.tomsguide.com/features/what-is-a-dark-web-scan-and-should-i-use-one">dark web</a> alerts, identity monitoring, and more. All of these features can help protect you online and alert you immediately when something goes wrong. </p><p>As for ClayRat , given how many iterations of the spyware that have been detected so far, it's likely the cybercriminals behind it are working on new updates and adding extra malicious capabilities to it. For this reason, I don't see this spyware going away anytime soon and it's more likely that it will be used in attacks on Android users in other countries, so you'll want to keep your guard up to stay safe.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/massive-data-leak-just-exposed-the-personal-info-of-6-million-shoppers-how-to-stay-safe">Massive data leak just exposed the personal info of 6 million shoppers — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/researcher-finds-security-flaw-in-gemini-but-google-says-its-not-fixing-it">Researcher finds security flaw in Gemini — but Google says it's not fixing it</a></li><li><a href="https://www.tomsguide.com/computing/online-security/discord-customer-info-stolen-in-data-breach-how-to-stay-safe">Discord customer info stolen in data breach — how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Macs under attack from malware impersonating popular password managers — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/macs-under-attack-from-malware-impersonating-popular-password-managers-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ A new malware campaign is impersonating popular password managers to steal sensitive personal data from Mac users. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">d4uJHC4GWiwnWbNqjVwLCQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PtE6iRxGmU4HDPAuUaB8LZ-1280-80.webp" type="image/webp" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Sep 2025 16:35:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/webp" url="https://cdn.mos.cms.futurecdn.net/PtE6iRxGmU4HDPAuUaB8LZ-1280-80.webp">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[macOS laptop]]></media:description>                                                            <media:text><![CDATA[macOS laptop]]></media:text>
                                <media:title type="plain"><![CDATA[macOS laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PtE6iRxGmU4HDPAuUaB8LZ-1280-80.webp" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over 100 password managers and software solutions are being impersonated by a new <a href="https://www.tomsguide.com/computing/malware-adware/google-just-took-down-224-malicious-apps-with-38-million-installs-from-the-play-store-how-to-stay-safe">malware campaign</a> targeting macOS users to steal their personal information. As reported by <a href="https://www.bleepingcomputer.com/news/security/lastpass-fake-password-managers-infect-mac-users-with-malware/" target="_blank">Bleeping Computer</a>, the popular password manager <a href="https://www.tomsguide.com/reviews/lastpass">LastPass</a> has already started warning users about this malicious software that is being spread through fake GitHub repositories. </p><p>Besides impersonating LastPass, this campaign is also pretending to be other password managers and software solutions including <a href="https://www.tomsguide.com/reviews/1password">1Password</a>, Dropbox, Gemini, Audacity, Adobe After Effects, and SentinelOne, among more than 100 others. It's using these fake repositories to spread the <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-by-malicious-info-stealing-malware-spread-through-ads-and-fake-software-dont-fall-for-this">Atomic macOS Stealer</a>, also known as AMOS, which is an info-stealing malware often used in <a href="https://www.tomsguide.com/computing/online-security/macs-under-attack-from-dangerous-new-info-stealing-malware-how-to-stay-safe">ClickFix style attacks</a>. AMOS is a malware-as-a-service offering that can be bought by hackers and other cybercriminals for roughly $1,000/month on the <a href="https://www.tomsguide.com/news/hackers-have-earned-millions-selling-your-data-on-the-dark-web-how-to-stay-safe">dark web</a> and typically targets the data stored on vulnerable computers. </p><p>The developers of this malware also recently added a backdoor component which gives them persistent and stealthy access to compromised systems. A large number of these deceptive GitHub repositories have been created from multiple accounts in order to optimize them to rank high in search results and to evade detection. LastPass has reported the fake repositories to GitHub but since it's easy to recreate new ones through automation from new accounts, even if they're taken down, new fraudulent ones could pop up just as quickly. </p><p>As ClickFix style attacks, the repositories feature a ‘download;' button that directs users to a secondary website where they are instructed to paste a command into the terminal to perform an installation of what seems to be legitimate software but is in actuality malware. The “ClickFix’ method takes advantage of a target not fully understanding what the commands are doing on their system; in this case the command is performing a <em>curl </em>request to a base64-encoded URL which then downloads an AMOS payload to the /tmp directory. </p><h2 id="how-to-stay-safe-from-clickfix-malware-attacks">How to stay safe from ClickFix malware attacks</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iJKvacosvMoCwbKjwcVGbP" name="hacker computer.jpg" alt="A hand typing at a computer in a dark room, lit up by the laptop's keyboard LEDs and red LED light" src="https://cdn.mos.cms.futurecdn.net/iJKvacosvMoCwbKjwcVGbP.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>In order to stay safe from ClickFix style attacks, the most important thing you need to know is not to run commands on your system, especially when you don't understand them. Additionally, when looking for software online, its recommended to only trust official app stores like the Mac App Store or vendor websites while avoiding offshoots. If there isn’t a macOS version of a particular piece of software available on a company's official site, be extra wary when you find a third-party site or in this case, a GitHub page, suggesting there is one.</p><p>If you do come across a macOS port of a program you're interested in, you  should ensure that it comes from a reputable source that has been vetted by the community first. Still, you are installing it at your own risk, so when in doubt, it's best to wait for an official port.</p><p>It also never hurts to have strong protections when online –  one of the<a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"> best antivirus software </a>solutions can keep your Windows PCs protected while the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> is specifically designed for your Apple computer. These paid solutions also provide you with plenty of extra useful features like web browsers that warn you about suspicious websites and downloads, ransomware rollback, a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a>, and more. <br><br>For those who are really worried about getting hacked or having their bank accounts drained by cybercriminals, you can't go wrong with the best identity theft protection services for even more protection. However, you'll need to sign up before a cyberattack or major security incident to take full advantage of the identity theft insurance and other protections these services offer.<br><br>ClickFix style attacks have been quite successful recently and until the general public learns to recognize and avoid them, hackers are going to keep using them in their malware campaigns. That's why it's up to you to practice good cyber hygiene and most importantly, to always be careful where you click and what you download.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/fbi-warns-hackers-are-impersonating-crime-reporting-sites-to-steal-your-personal-data-heres-how-to-tell">FBI warns hackers are impersonating crime reporting sites to steal your personal data — here’s how to tell</a></li><li><a href="https://www.tomsguide.com/computing/password-managers/chrome-could-soon-let-you-automatically-upgrade-from-passwords-to-passkeys-heres-how">Google will let you use passkeys automatically in Chrome - here's how you can switch</a></li><li><a href="https://www.tomsguide.com/computing/online-security/new-hacker-tool-can-inject-ai-generated-deepfakes-right-into-your-iphone-everything-you-need-to-know">Hackers are now using deepfakes in phishing scams to fool banking apps and steal your money - how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google just took down 224 malicious apps with 38 million installs in massive SlopAds fraud campaign — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/google-just-took-down-224-malicious-apps-with-38-million-installs-from-the-play-store-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Security researchers have uncovered a new global ad fraud campaign that used seemingly innocent Android apps for nefarious purposes. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SuHpQnDaRZ8xQ9X5KrkCzP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 17 Sep 2025 02:22:56 +0000</pubDate>                                                                                                                                <updated>Wed, 17 Sep 2025 14:18:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Android malware on phone]]></media:description>                                                            <media:text><![CDATA[Android malware on phone]]></media:text>
                                <media:title type="plain"><![CDATA[Android malware on phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Bad apps can be hiding in the place you least expect and that’s exactly what happened with 224 malicious apps that were recently removed from the <a href="https://www.tomsguide.com/phones/android-phones/google-play-finally-added-biometric-verification-heres-how-to-set-it-up">Google Play Store</a> following the discovery of a massive ad fraud campaign.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/google-nukes-224-android-malware-apps-behind-massive-ad-fraud-campaign/" target="_blank">BleepingComputer</a>, the campaign itself was discovered by Human’s Satori Threat Intelligence team which revealed in a <a href="https://www.humansecurity.com/learn/blog/satori-threat-intelligence-alert-slopads-covers-fraud-with-layers-of-obfuscation/">new report</a> that these apps had over 38 million downloads in total. However, it was the advanced tricks and obfuscation techniques they used to bypass Google’s defenses that really stood out.</p><p>Unlike previous <a href="https://www.tomsguide.com/computing/malware-adware/hundreds-of-malicious-android-apps-with-60-million-downloads-found-spamming-android-users-with-ads-and-stealing-credentials">ad fraud campaigns</a>, this one spanned across the globe with users of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> downloading them from 228 countries, though they generated the most ad impressions in the U.S. (30%), India (10%) and Brazil (7%). Human’s security researchers have dubbed the campaign “SlopAds” as the <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now">malicious apps</a> used in it had a mass produced look and feel, similar to online content created by AI image generators and other AI tools.</p><p>Here’s everything you need to know about this new ad fraud campaign including what to do if you did download one of the apps in question along with some tips and tricks to help keep your Android phone safe from adware apps.</p><h2 id="from-legitimate-to-malicious-in-an-instant">From legitimate to malicious in an instant</h2><p>In order to avoid being detected by Google’s app review process and Android’s built-in security software, the scammers behind this new ad fraud campaign went to great lengths. </p><p>For instance, if an Android user installed one of these so-called SlopAd apps directly through the Play Store of their own accord, the app would act as it normally would once installed. However, if they stumbled upon one of these apps after clicking through from the scammers’ various ad campaigns, the app would become malicious after installation.</p><p>Once the SlopAds app ran the necessary checks to see whether or not it was installed via the Play Store, it would then download an encrypted configuration file that contained links to the scammers’ ad fraud malware module, cashout servers and a JavaScript payload. From there, the app would run one final check to make sure it was installed on a legitimate Android user’s device and not being analyzed by a researcher or software before proceeding.</p><p>Now this is where things get interesting. These SlopAd apps would download four PNG images that look harmless at first glance. However, they actually use stenography to hide pieces of a malicious APK or installation file which is the driving force behind this ad fraud campaign.</p><p>After being downloaded, the images are decrypted and then reassembled on a targeted device to form the FatModule malware. Once activated, it uses hidden WebViews to collect device and browser information as well as to navigate to scammer-controlled domains which are used to cashout all of this fake ad revenue generated by these SlopAd apps.</p><p>The domains themselves impersonated videogame and news sites while continuously serving hidden WebView screens. This generated over two billion fraudulent ad impressions and clicks each day which brought in quite a lot of money for the scammers.</p><h2 id="how-to-stay-safe-from-ad-fraud-apps">How to stay safe from ad fraud apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Although Human’s Satori Threat Intelligence team hasn’t released the full list of these 224 SlopAd apps, they’ve all been taken down from the Google Play Store. Likewise, if you accidentally downloaded one, you don’t need to worry about tracking it down on your own. This is because Google has updated Android’s built-in security app <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> to warn users to uninstall any of these malicious apps that may be on their smartphones or tablets.</p><p>So besides stealing, what’s so dangerous about ad fraud and adware apps? Well, imagine if your phone was constantly loading random websites in the background throughout the day? Not only would this eat up your mobile data but it would also put unnecessary strain on your phone’s battery and other components. As such, you’d probably need to upgrade to a new device sooner rather than later if you had one of these SlopAd apps or a similar <a href="https://www.tomsguide.com/news/these-android-adware-apps-with-over-2-million-downloads-put-you-at-risk-delete-them-now">adware app</a> installed.</p><p>I know this isn’t as pressing of a threat as your typical <a href="https://www.tomsguide.com/computing/malware-adware/11-million-android-users-infected-with-dangerous-necro-trojan-how-to-stay-safe">Android malware infection</a>, but it’s still something you need to be aware of and look out for. Even though we’re not dealing with an <a href="https://www.tomsguide.com/news/this-new-mac-malware-is-stealing-passwords-credit-card-info-and-more-how-to-stay-safe">infostealer</a> or other dangerous malware here, you can see above how those who chose to sideload these apps were much more at risk than others who downloaded them from an official Android app store, in this case, the Play Store itself.</p><p>If you are worried about malware and other viruses ending up on your phone or tablet, then you might want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside Google Play Protect. Likewise, if you want the ultimate protection from hackers, scammers and even identity thieves, then the <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html">best identity theft protection services</a> are what you’re after. They’re more expensive but a big reason for this is that they include identity theft insurance which can range from anywhere from $1 million to $2 million. This money can be used to cover legal expenses, to get new documents and to compensate you for any funds lost to fraud.</p><p>Given how much money a major ad fraud scheme like this one can generate for scammers and other cybercriminals, this likely isn’t the last one we’ll see. In fact, due to the sophistication of this SlopAds campaign, the security researchers who uncovered it believe that the scammers behind this one we’ll likely try something very similar quite soon. So be on the lookout and as always, be careful what you download.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-google-search-results-to-spread-fake-apps-filled-with-malware-dont-fall-for-this">Hackers are using Google search results to spread fake apps filled with malware — don't fall for this</a></li><li><a href="https://www.tomsguide.com/computing/online-security/i-almost-got-hit-with-a-phishing-attack-and-a-malicious-app-last-week-heres-how-i-knew-not-to-click">I found a phishing email in my inbox and a malicious app in my news feed — here’s how I knew they were scams</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/fake-meta-suspension-warnings-used-in-new-malware-campaign-how-to-protect-your-devices-and-your-data">Fake Meta suspension warnings used in new malware campaign — how to protect your devices and your data</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake Meta suspension warnings used in new malware campaign — how to protect your devices and your data ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/fake-meta-suspension-warnings-used-in-new-malware-campaign-how-to-protect-your-devices-and-your-data</link>
                                                                            <description>
                            <![CDATA[ Hackers are using fake Meta suspension warnings in a new FileFix campaign to lure users into installing info-stealing malware on their own devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tHfNrSybcUDqUBsJfCFfmZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mjMcVn3yy2PbCer4Gv4pAg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Sep 2025 19:15:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mjMcVn3yy2PbCer4Gv4pAg-1280-80.jpg">
                                                            <media:credit><![CDATA[Viacheslav Lopatin | Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Meta logo on screen of mobile phone on Facebook word background. Facebook after rebranding and changing name to Meta.]]></media:description>                                                            <media:text><![CDATA[Meta logo on screen of mobile phone on Facebook word background. Facebook after rebranding and changing name to Meta.]]></media:text>
                                <media:title type="plain"><![CDATA[Meta logo on screen of mobile phone on Facebook word background. Facebook after rebranding and changing name to Meta.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mjMcVn3yy2PbCer4Gv4pAg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new<a href="https://www.tomsguide.com/computing/malware-adware/new-filefix-attack-brings-clickfix-social-engineering-to-windows-file-explorer-how-to-stay-safe "> FileFix</a> attack is using novel lures in order to trick users into downloading malware. As reported by<a href="https://www.bleepingcomputer.com/news/security/new-filefix-attack-uses-steganography-to-drop-stealc-malware/" target="_blank">Bleeping Computer</a>, this latest version of the increasingly popular <a href="https://www.tomsguide.com/computing/online-security/what-is-social-engineering">social engineering attack</a> was first discovered by Acronis, who noticed that hackers have been using the FileFix technique and sending out <a href="https://www.tomsguide.com/news/facebook-users-are-being-locked-out-of-their-accounts-from-this-scam-dont-fall-for-this">fake Meta account suspensions</a> in order to convince users to unknowingly download the StealC infostealer. </p><p>StealC can exfiltrate usernames and passwords from a wide variety of platforms including credentials stored in the cloud, credentials and authentication cookies from web browsers, credentials from messaging apps, cryptocurrency wallets, VPNs and gaming apps, and it can take screenshots of your desktop too. This new FileFix attack is tricking users by sending fake warning messages that appear to come from Meta’s support team. There's even a multi-language fake webpage users are directed to after being warned that their account is about to be suspended or disabled. </p><p>Using typical phishing urgency with a deadline of seven days, it tells targets that in order to avoid account suspension they must view an “incident report” that Meta is sharing with them. The fake incident report is a disguised PowerShell command that downloads the StealC malware onto their system though. </p><p>Users are asked to click a button that says “Copy” which resembles a file path, and are instructed to open File Explorer to paste the copied file path into the address bar which they’re told will open the “incident report.” However, the fake path contains multiple spaces at the end making it easy to miss the malicious code and it's also missing the usual # symbols that identify a <a href="https://www.tomsguide.com/computing/online-security/hackers-target-popular-student-site-iclicker-to-spread-malware-via-clickfix-attacks-how-to-stay-safe">ClickFix attack</a>. </p><p>FileFix is a variant of the ClickFix family, which uses social engineering-style attacks to trick users into pasting malicious commands into operating system dialog boxes so they can ‘fix’ the problems that hackers claim they have. FileFix was created by mr.fox, a researcher, and uses the address bar in Windows' File Explorer to execute malicious commands instead of the Windows Run dialog box which is what ClickFix uses. </p><h2 id="how-to-stay-safe-2">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wbnnjnFdxfHUZGiSFXky2S" name="computer smartphone security.jpg" alt="A woman's hands holding a smartphone with a lock symbol on it, in front of a laptop that also has a lock symbol on it." src="https://cdn.mos.cms.futurecdn.net/wbnnjnFdxfHUZGiSFXky2S.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/i-almost-got-hit-with-a-phishing-attack-and-a-malicious-app-last-week-heres-how-i-knew-not-to-click">I found a phishing email in my inbox and a malicious app in my news feed — here’s how I knew they were scams</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-google-search-results-to-spread-fake-apps-filled-with-malware-dont-fall-for-this">Hackers are using Google search results to spread fake apps filled with malware — don't fall for this</a></li><li><a href="https://www.tomsguide.com/computing/online-security/skincare-giant-clarins-allegedly-hit-in-data-breach-with-600-000-customers-exposed-what-you-need-to-know">Skincare giant Clarins allegedly hit in data breach with 600,000 customers exposed — what you need to know</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using Google search results to spread fake apps filled with malware — don't fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-using-google-search-results-to-spread-fake-apps-filled-with-malware-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ A new malware campaign is using fake search results to spread dangerous malicious apps to unsuspecting victims. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CTL5hoeTyi35QFVDSNqQJo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Sep 2025 07:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new malware campaign is using <a href="https://www.tomsguide.com/computing/malware-adware/new-malware-uses-infected-vpn-apps-to-take-over-your-device-heres-how-to-stay-safe">SEO poisoning</a> in order to lure victims into downloading fake versions of common apps that are malicious. As reported by <a href="https://cybernews.com/security/seo-poisoning-fake-app-downloads/" target="_blank">Cybernews</a>, reports that hackers are putting malware into <a href="https://www.tomsguide.com/computing/malware-adware/more-than-250-malicious-apps-are-spreading-info-stealing-malware-on-android-and-ios-delete-these-right-now">fake apps</a> that mimic popular legitimate ones like Signal, WhatsApp and Chrome in order to trick victims into downloading their malicious versions instead. </p><p>FortiGuard Labs researchers have identified this new attack which both tricks users and games the search algorithms by using SEO plugins and registered lookalike domains in order to get to the top of search results. Once a victim is on their fake website, they’re fooled into downloading a trojanized installer of one of many commonly searched for apps like Telegram, Deepl, Line or others. </p><p>The mimicked websites are able to deliver malware from several known families but those that have been reported include Hiddengh0st and a new Winos variant. Malicious components have been bundled into the installer packages, which appear to also download the real applications, and after launching <a href="https://www.tomsguide.com/news/hackers-are-using-one-of-microsofts-own-tools-to-spread-malware-what-you-need-to-know">malicious DLLs</a> will also drop along with hidden directories, administrator privileges and functions to help the malicious code evade detection. </p><p>From there, attackers can easily collect information about the device and the victim, log keystrokes and clipboard information, load plugins for surveillance and control as well as enumerate any antivirus and security tools, or capture screen activity. The plugins that the malware can deliver also suggest the possibility that the hackers behind the attack can intercept app communications from <a href="https://www.tomsguide.com/computing/online-security/telegram-data-sharing-has-increased-by-6-000-percent-since-ceos-arrest">Telegram</a>. </p><h2 id="how-to-stay-safe-from-fake-sites-in-search-results">How to stay safe from fake sites in search results</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:815px;"><p class="vanilla-image-block" style="padding-top:56.32%;"><img id="fTjpArBh3PnNVTgugbi38e" name="Google Chrome.jpg" alt="Chrome" src="https://cdn.mos.cms.futurecdn.net/fTjpArBh3PnNVTgugbi38e.jpg" mos="" align="middle" fullscreen="" width="815" height="459" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Thaspol/Adobe)</span></figcaption></figure><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/those-urgent-text-messages-arent-from-your-motor-vehicle-department-heres-how-to-tell-theyre-fake">Those urgent text messages aren't from your motor vehicle department - here's how to tell they're fake</a></li><li><a href="https://www.tomsguide.com/computing/online-security/7-iphone-security-settings-you-should-enable-right-now-to-lock-down-your-smartphone">7 iPhone security settings you should enable right now to lock down your smartphone</a></li><li><a href="https://www.tomsguide.com/computing/online-security/skincare-giant-clarins-allegedly-hit-in-data-breach-with-600-000-customers-exposed-what-you-need-to-know">Skincare giant Clarins allegedly hit in data breach with 600,000 customers exposed — what you need to know</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This new Android banking trojan can automatically transfer money off your phone to hackers  ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-new-raton-android-trojan-can-automatically-transfer-money-right-off-your-phone-to-hackers</link>
                                                                            <description>
                            <![CDATA[ The RatOn Android malware may be new, but it’s surprisingly capable at stealing your hard-earned cash through overlay attacks and even automatic money transfers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vw949E6EcxLfDy4wuLnYUN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Sep 2025 06:45:00 +0000</pubDate>                                                                                                                                <updated>Wed, 10 Sep 2025 15:36:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Normally, when it comes to Android malware, when new strains are discovered, they often build upon a previous one. However, that’s not the case with a new <a href="https://www.tomsguide.com/computing/malware-adware/this-android-banking-trojan-steals-passwords-to-take-over-your-accounts-and-all-it-takes-is-a-single-text-message">Android banking trojan</a> currently making the rounds online. Instead, it appears to be written from scratch with no code similarities to existing malware families.</p><p>As reported by <a href="https://thehackernews.com/2025/09/raton-android-malware-detected-with-nfc.html" target="_blank">The Hacker News</a>, this new banking trojan has been dubbed RatOn by security researchers at <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-banking-trojan-now-uses-scheduled-maintenance-to-hide-its-malicious-activities-dont-fall-for-this">Threat Fabric</a> who discovered it while investigating another malware strain that uses near-field communication or NFC in its attacks to steal contactless payment info from unsuspecting Android users. The most surprising part of this new sample was the fact that it wasn’t just in a single <a href="https://www.tomsguide.com/computing/malware-adware/hundreds-of-malicious-android-apps-with-60-million-downloads-found-spamming-android-users-with-ads-and-stealing-credentials">malicious app</a> but instead was part of a campaign involving multiple ones.</p><p>After analyzing this new campaign further, Threat Fabric found that RatOn is a fully functional banking trojan with several unique capabilities. In addition to being able to take over one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> and the accounts on it, the banking trojan can also perform automated money transfers as well as use custom <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-banking-trojan-now-shows-a-fake-lock-screen-to-steal-your-pin-and-your-cash-dont-fall-for-this">overlay attacks</a> to trick victims into thinking their device is infected with ransomware.</p><p>Here’s everything you need to know about this new malware strain, along with some tips and tricks to keep your Android phone safe from banking trojans that can completely drain your financial accounts.</p><h2 id="from-overlays-to-automated-money-transfers">From overlays to automated money transfers</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YwKRVzwvLwup6hDGh5bVNM" name="RzdqY6hhVUXJjJYEgfCrVe.jpg" alt="A hacker typing quickly on a keyboard" src="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>In order to trick potential victims into installing their malicious apps, the hackers behind this campaign registered several domains with adult themes, which they then used as a lure. Specifically, these <a href="https://www.tomsguide.com/computing/online-security/hackers-have-created-hundreds-of-fake-reddit-sites-to-spread-info-stealing-malware">fake sites</a> contained “TikTok18+” in their names. However, Threat Fabric’s security researchers couldn’t find out how the hackers got their victims to go to these sites. In the past, I’ve seen hackers use <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing emails</a>, random messages on social media and even <a href="https://www.tomsguide.com/computing/malware-adware/dont-click-this-malicious-ads-impersonating-google-chrome-spreading-dangerous-malware">fake ads</a> to get people to click on links to their malicious sites.</p><p>If someone is foolish enough to sideload an adults-only version of TikTok onto their Android phone, what ends up getting installed is actually a <a href="https://www.tomsguide.com/news/new-android-malware-dropper-sneaks-past-google-protect-yourself-now">malware dropper</a> or third-party software installer. By tricking users into granting it the permission to install apps from unknown sources, the malware dropper is able to bypass Android’s built-in security protections. This is used to download and install the first payload, after which, the second payload and two more permissions are requested that are essential for hackers looking to commit on-device fraud: access to Accessibility services and Device Admin privilege. </p><p>Like other banking trojans, RatOn abuses Android’s <a href="https://www.tomsguide.com/news/look-out-this-android-malware-can-take-over-your-banking-and-crypto-accounts">Accessibility services</a> to launch overlay attacks on an infected device. For those unfamiliar, these attacks involve hackers putting an overlay on top of popular banking and finance apps that is almost identical to a legitimate login screen. This way, the hackers can harvest a victim’s banking credentials to gain access to their accounts without their knowledge, as they just thought they were logging into one of their banking, finance or crypto wallet apps.</p><p>Another interesting thing cybercriminals deploying the RatOn malware can do is to use an overlay to make victims think their phone has been locked by hackers. Of course, to unlock it, they need to send over a large amount of money, just like with a <a href="https://www.tomsguide.com/news/this-ransomware-makes-you-sign-up-for-roblox-to-get-your-files-back">ransomware attack</a>. However, while their phone isn’t actually infected with ransomware, it is compromised by the RatOn banking trojan. </p><p>RatOn also requests access to read/write contacts and manage system settings to carry out its malicious activity. From there, a third payload is downloaded, which is actually the NFSkate malware Threat Fabric was initially looking into. By using a technique known as Ghost Tap, NFSkate can carry out NFC relay attacks and steal contactless payment info. However, with that malware strain, these attacks needed to be carried out in person within physical range of a targeted Android phone.</p><p>Now, with RatOn, this new malware can perform automated money transfers (ATS) by abusing Android’s Accessibility services. This means that hackers deploying this malware in their attacks can drain your financial accounts from anywhere in the world, as they don’t need to be in the same room with you.</p><h2 id="how-to-stay-safe-from-banking-trojans-2">How to stay safe from banking trojans</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>The good news here is that at the moment, RatOn is only being used to target Android users in the Czech Republic. However, like with any Android malware strain, that geographic location could just be a testing ground to make sure it works before the malware’s creators begin targeting Android phones in other countries like the U.S. or the U.K.</p><p>I’ll be keeping a close eye on RatOn and how this new Android malware strain develops, but in the meantime, here are a few tips and tricks to help keep your phone (and your bank account) safe from dangerous trojans.</p><p>For starters, you never want to <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps">sideload Android apps</a> unless you absolutely have to. Instead, you want to download all of your new apps from official app stores like the Google Play Store and the Samsung Galaxy Store. Google will soon prevent users from sideloading altogether with the next version of Android, but for now, you should avoid doing so even if it seems like a convenient way to put new apps on your phone.</p><p>When it comes to new apps, you want to be very careful when installing them, as even <a href="https://www.tomsguide.com/news/popular-android-screen-recorder-app-went-from-legitimate-to-malicious-overnight-what-you-need-to-know">good apps can go bad</a>. This is why I highly recommend limiting the number of apps on your phone overall and then, if you find you haven’t used a particular app for quite some time, it’s best to just delete it.</p><p>To stay safe from malicious apps, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> is enabled on your phone. This free, built-in security software scans all of your existing apps, along with any new ones you download, for malware or other signs of malicious activity. For extra protection, you may also want to run one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it.</p><p>Hackers aren’t slowing down anytime soon, and there are constantly new malware strains and banking trojans like RatOn you need to look out for. However, if you practice good cyber hygiene, avoid clicking on links from unknown senders and don’t sideload apps you’ve found on less-than-reputable sites, you should be safe. </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/paypal-users-under-attack-from-sophisticated-new-phishing-scam-dont-fall-for-this">PayPal users under attack from sophisticated new phishing scam — don't fall for this</a></li><li><a href="https://www.tomsguide.com/computing/online-security/plex-users-need-to-change-their-passwords-theres-been-another-breach">Plex users need to change their passwords — there’s been another breach</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-cracked-versions-of-legitimate-apps-to-spread-dangerous-mac-malware-how-to-stay-safe">Macs under attack from ‘cracked’ apps spreading dangerous info-stealing malware</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Macs under attack from ‘cracked’ apps spreading dangerous info-stealing malware — don’t fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-using-cracked-versions-of-legitimate-apps-to-spread-dangerous-mac-malware-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ This dangerous Mac malware can steal your passwords, browser data and more, and all it takes is downloading a cracked app or getting tricked by a fake CAPTCHA. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gp3VfZEieKGWQQywrurG2A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iuibyMGxncrhX6RweFUqcb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 08 Sep 2025 18:37:57 +0000</pubDate>                                                                                                                                <updated>Tue, 09 Sep 2025 14:34:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iuibyMGxncrhX6RweFUqcb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop with warning messages displayed on screen]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop with warning messages displayed on screen]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop with warning messages displayed on screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iuibyMGxncrhX6RweFUqcb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <div  class="fancy-box"><div class="fancy_box-title">Follow Apple Event Live now</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pFMXixviEMgjt4GZ3UZDCC" name="Apple Event edit 2" caption="" alt="iPhone 17 Pro Max, Tim Cook and Apple Watch 10" src="https://cdn.mos.cms.futurecdn.net/pFMXixviEMgjt4GZ3UZDCC.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: MacRumors/Getty/Apple)</span></figcaption></figure><p class="fancy-box__body-text">Apple is about to launch the new iPhone. Follow our <a data-analytics-id="inline-link" href="https://www.tomsguide.com/news/live/iphone-17-live-launch-event#mrfhud=true">iPhone 17 event live blog</a> right now!</p></div></div><p>Hackers are once again targeting the <a href="https://www.tomsguide.com/best-picks/best-macbook">best MacBooks</a> and other Apple computers in an effort to infect them with <a href="https://www.tomsguide.com/computing/online-security/macs-under-attack-from-dangerous-malware-targeting-digital-wallets-and-apples-notes-apps-how-to-stay-safe">dangerous malware</a> designed to steal passwords, files, browser data and more.</p><p>As reported by <a href="https://www.infosecurity-magazine.com/news/macos-stealer-cracked-apps-bypass/" target="_blank">Infosecurity Magazine</a>, the cybersecurity firm <a href="https://www.tomsguide.com/reviews/trend-micro-antivirus-mac">Trend Micro</a> recently discovered a new <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-by-malicious-info-stealing-malware-spread-through-ads-and-fake-software-dont-fall-for-this">Atomic macOS Stealer</a> campaign that uses ‘cracked’ or pirated versions of popular macOS software as a lure. When this doesn’t work, the cybercriminals behind this campaign use <a href="https://www.tomsguide.com/computing/online-security/hackers-are-using-recaptcha-to-trick-users-into-infecting-their-own-pcs-with-malware-how-to-stay-safe">fake CAPTCHA</a> to the same end.</p><p>While you might think your Mac is safer than one of the <a href="https://www.tomsguide.com/best-picks/the-best-windows-laptops">best Windows laptops</a>, think again, as hackers now love to target Apple’s computers in their attacks. This makes sense, too, as those willing to pay more for a premium laptop will likely make better (and more profitable) targets.</p><p>Here’s everything you need to know about this new campaign along with some tips and tricks to help keep you and your Apple computer safe from hackers.</p><h2 id="from-cracked-to-hacked">From cracked to hacked</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iJKvacosvMoCwbKjwcVGbP" name="hacker computer.jpg" alt="A hand typing at a computer in a dark room, lit up by the laptop's keyboard LEDs and red LED light" src="https://cdn.mos.cms.futurecdn.net/iJKvacosvMoCwbKjwcVGbP.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>In its <a href="https://www.trendmicro.com/en_us/research/25/i/an-mdr-analysis-of-the-amos-stealer-campaign.html" target="_blank">report</a>, Trend Micro reveals that this new campaign begins with an attacker tricking a macOS user into downloading a fake or cracked version of a popular app. This <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-apps-to-distribute-this-dangerous-mac-malware-dont-fall-for-this">malicious app</a> then acts as a Trojan horse to deliver and install the Atomic macOS Stealer onto their computer.</p><p>These fake apps could be promoted on forums, in direct messages sent over social media or even through malicious ads. When a potential victim goes to download one of them, they’re redirected to a hacker-controlled page and prompted to click on a button which reads “Download for MacOS.” </p><p>In one case analyzed by Trend Micro’s security researchers, victims saw their Macs infected with malware after trying to download a cracked version of the legitimate app CleanMyMac. While the download site appeared to be legitimate at first glance, clicking on the “Download Now” button took them to Atomic macOS Stealer landing page. <br><br>Alternatively, victims might be instructed to <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-mac-malware-just-got-a-major-upgrade-which-makes-it-even-harder-to-delete-how-to-stay-safe">copy and paste commands</a> into Apple Terminal. Doing so leads to the execution of a malicious installation script which creates a binary file that lets the hackers establish persistence on a vulnerable Mac.<br><br>From there, the script copies loads of sensitive data off an infected Apple computer, including:</p><ul><li><strong>System Profile information</strong></li><li><strong>Username and password</strong></li><li><strong>Browser data (including cookies, web data, and login information)</strong></li><li><strong>Cryptocurrency wallet data</strong></li><li><strong>Telegram data</strong></li><li><strong>OpenVPN profiles</strong></li><li><strong>Keychain data</strong></li><li><strong>Apple Notes data</strong></li><li><strong>Various files from folders on the system</strong></li></ul><p>All of this sensitive personal data is then compressed and sent back to a hacker-controlled server to use in follow-up attacks. Likewise, this data could also be sold to other hackers on the <a href="https://www.tomsguide.com/news/hackers-have-earned-millions-selling-your-data-on-the-dark-web-how-to-stay-safe">dark web</a> to use in their own attacks.</p><h2 id="how-to-stay-safe-from-mac-malware">How to stay safe from Mac malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="DgqWmPAUgj3TpRQWmkkka7" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/DgqWmPAUgj3TpRQWmkkka7.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>Just like on one of the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html">best iPhones</a>, you want to stick to the Apple App Store for downloading new apps for your Mac when possible. If you do download an app from outside the App Store, make sure it’s from the website of a reputable Mac developer first. </p><p>To do so, <a href="https://www.tomsguide.com/computing/online-security/hackers-have-created-hundreds-of-fake-reddit-sites-to-spread-info-stealing-malware">carefully examine the URL</a> and you also want to look for signs of misspelled words or poor grammar as these can be a dead giveaway that you’re on a <a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-over-free-online-file-converters-that-infect-your-pc-with-malware">malicious site</a> and not a legitimate one. You also want to be careful how you get to a vendor’s site. Instead of clicking on ads which appear in the top results on Google and other search engines <a href="https://www.tomsguide.com/news/macs-under-threat-from-malicious-ads-spreading-malware-dont-fall-for-this">which can be faked</a>, you want to scroll further down the page to find a company’s actual site.</p><p>Although it goes without saying, you should never download cracked or <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-mac-malware-just-got-a-major-upgrade-which-makes-it-even-harder-to-delete-how-to-stay-safe">pirated software</a>. Besides hurting developers, doing so puts you at risk since you never really know what’s inside an app you downloaded illegally. Sure, it could work as intended but there’s also a chance that it might contain malicious code designed to steal your data or worse, take over your Mac.</p><p>As for staying safe, while your Mac does come with built-in protection in the form of <a href="https://www.tomsguide.com/news/this-severe-macos-flaw-could-let-malware-run-on-your-mac-update-right-now">Gatekeeper</a> and <a href="https://www.tomsguide.com/news/macos-is-getting-even-better-at-scanning-for-malware-heres-how">XProtect</a>, you may also want to consider using one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> solutions alongside them. Third-party antivirus software is updated more regularly and it often includes other useful extras like access to one of the <a href="https://www.tomsguide.com/best-picks/best-vpn">best VPN</a> services or a <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a>.</p><p>Hackers will likely continue to prey on Mac users given that the old and no longer true advice that Apple computers can’t get viruses is still quite widespread. However, you can stay safe by remaining vigilant online and this is especially true when downloading new software and apps.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/paypal-users-under-attack-from-sophisticated-new-phishing-scam-dont-fall-for-this">PayPal users under attack from sophisticated new phishing scam — don't fall for this</a></li><li><a href="https://www.tomsguide.com/computing/online-security/these-icloud-calendar-invites-look-legitimate-but-are-tricky-phishing-attacks-heres-how-to-tell">These iCloud Calendar invites look legitimate but are tricky phishing attacks – here’s how to tell</a></li><li><a href="https://www.tomsguide.com/computing/online-security/over-half-a-million-people-impacted-by-major-data-breach-full-names-ssns-financial-data-and-more-exposed">Over half a million people impacted by major data breach — full names, SSNs, financial data and more exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google wants to fight Android malware by making sideloading more difficult — here's how ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/google-wants-to-fight-android-malware-by-making-sideloading-more-difficult-heres-how</link>
                                                                            <description>
                            <![CDATA[ Google rolls out a new program to verify apps developers in order to prevent the spread of malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">k6sbnZNSzR4R2ZLJhnApj4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xpbQoDrZtFcsKgvftfg4jR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 27 Aug 2025 16:17:59 +0000</pubDate>                                                                                                                                <updated>Wed, 27 Aug 2025 16:52:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xpbQoDrZtFcsKgvftfg4jR-1280-80.jpg">
                                                            <media:credit><![CDATA[Rafapress/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Play store on an Android device]]></media:description>                                                            <media:text><![CDATA[Google Play store on an Android device]]></media:text>
                                <media:title type="plain"><![CDATA[Google Play store on an Android device]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xpbQoDrZtFcsKgvftfg4jR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/over-1-million-hit-in-farmers-insurance-data-breach-names-addresses-partial-ssns-and-more-exposed">Over 1 Million Hit In Farmers Insurance Data Breach — Names, Addresses, Partial SSNs And More Exposed</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/dangerous-android-banking-trojan-found-lurking-in-malicious-apps-with-19-million-installs-dont-fall-for-this">Dangerous Android banking trojan found lurking in malicious apps with 19 million installs — don’t fall for this</a></li><li><a href="https://www.tomsguide.com/computing/online-security/macs-under-attack-from-dangerous-new-info-stealing-malware-how-to-stay-safe">Macs under attack from dangerous new info-stealing malware — how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous Android banking trojan found lurking in malicious apps with 19 million installs — don’t fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-android-banking-trojan-found-lurking-in-malicious-apps-with-19-million-installs-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ The Anatsa banking trojan and other malware strains were discovered in 77 malicious apps that have since been removed from the Google Play Store. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4rHRfRUjDNn74AVEe3L9Qj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Aug 2025 22:50:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Even on official app stores, you need to be careful what you download. Case in point, 77 <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now">malicious apps</a> with a combined total of 19 million installs were found spreading malware on the Google Play Store. </p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/malicious-android-apps-with-19m-installs-removed-from-google-play/" target="_blank">BleepingComputer</a>, the malicious apps in question were discovered by Zscaler’s ThreatLabs team. At the time, its researchers were investigating a new campaign that uses the <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-banking-trojan-now-uses-scheduled-maintenance-to-hide-its-malicious-activities-dont-fall-for-this">Anatsa banking trojan</a> (also known as <a href="https://www.tomsguide.com/news/17-android-apps-have-been-stealing-your-banking-data-delete-them-now">Tea Bot</a>) to target vulnerable Android phones.</p><p>In addition to taking screenshots, intercepting and reading text messages, keylogging and device takeover, Anatsa is also able to impersonate banking and finance apps by using overlay attacks. Just last year, the trojan was able to impersonate over 600 popular apps. Now though, that number has jumped to 831 banking and finance apps according to <a href="https://www.zscaler.com/blogs/security-research/android-document-readers-and-deception-tracking-latest-updates-anatsa" target="_blank">Zscaler’s new report</a>.</p><p>Here’s everything you need to know about this new malware campaign including some tricks and tips to help you keep your Android phone virus-free and safe from hackers.</p><h2 id="hiding-in-plain-view">Hiding in plain view</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1271px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bXhSjkdzQTXp3pYotR8eSf" name="zscaler-malicious-app-example" alt="An example of a malicious app found on the Google Play Store by ZScaler's ThreatLabs security researchers" src="https://cdn.mos.cms.futurecdn.net/bXhSjkdzQTXp3pYotR8eSf.jpg" mos="" align="middle" fullscreen="" width="1271" height="715" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: ZScaler/Tom's Guide)</span></figcaption></figure><p>The reason malicious apps can be quite difficult to spot is that they often pose as seemingly harmless ones on both official and unofficial app stores. For instance, cybercriminals might create a <a href="https://www.tomsguide.com/news/hackers-are-using-a-fake-pdf-viewer-to-infect-macs-with-malware-how-to-stay-safe">PDF reader</a>, <a href="https://www.tomsguide.com/news/these-android-flashlight-apps-could-be-spying-on-you">flashlight</a> or some other type of utility, trick people into downloading it using fake reviews or even <a href="https://www.tomsguide.com/news/hackers-using-google-ads-to-steal-your-info-and-drain-your-accounts-what-you-need-to-know">fake ads</a> and then infect their device with malware.</p><p>In Anatsa’s case, the banking trojan uses decoy apps that appear to be legitimate at first glance. However, once they're installed, this decoy app downloads a malicious payload disguised as an app update which actually includes the Anatsa banking trojan. Even though apps on the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a> go through rigorous security checks just like on Apple’s App </p><p>Store, this approach allows these bad apps to avoid detection since they only become malicious after they’ve been downloaded and installed.</p><p>Once one of these malicious apps is updated and opened, Anatsa scans the apps on a victim’s phone to see which banking and finance apps they use. If one of the apps the trojan can impersonate are loaded on a victim’s phone, it then places an overlay of a login screen when they’re launched. If you opened the app for your bank and saw that you had to re-login before checking your account, you wouldn’t think twice about it, right? Well, in this case, instead of logging in, you’re actually handing over your username and password to the hackers behind this campaign who can then drain your accounts.</p><p>In addition to the Anatsa banking trojan, ZScaler’s researchers also found other malware strains being distributed by the malicious apps. As BleepingComputer points out, the <a href="https://www.tomsguide.com/news/malware-hits-10-million-android-users-delete-these-apps-right-now">Joker malware</a> was the most popular and was found in a quarter of these malicious apps. </p><p>Just like with Anatsa, the Joker malware is able to take screenshots and access device information. However, it can also read and send text messages, steal a victim’s contacts from their phone and even sign up for premium subscription services. Likewise, the Joker variant <a href="https://www.tomsguide.com/news/move-over-joker-harly-malware-infects-millions-of-android-phones">Harly</a> was also found in these malicious apps among other malware strains.</p><h2 id="how-to-stay-safe-from-android-malware-3">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Normally with malware, I’d recommend not opening links or downloading attachments in <a href="https://www.tomsguide.com/news/avoid-these-email-attachments-if-you-dont-want-to-get-phished">emails from unknown senders</a> or downloading new apps from suspicious sites online. However, in this situation, things are a little more tricky since all of these 77 malicious apps were available to download right on the Google Play Store.</p><p>For this reason, I always recommend that people limit the number of apps they have installed. This makes it easier to find out if you accidentally downloaded a malicious one but keep in mind, <a href="https://www.tomsguide.com/news/popular-android-screen-recorder-app-went-from-legitimate-to-malicious-overnight-what-you-need-to-know">even good apps can go bad</a> when injected with malicious code like how the Anatsa banking trojan is distributed via fake app updates.</p><p>Before downloading any new app, you want to carefully check its review score and ratings. However, since these can be faked, it’s always a good idea to look for external reviews on other sites and especially video reviews since they show you how the app in question works. It’s best to stick to well-known developers with trusted track records but before you download any app, you should first ask yourself if another one of your pre-installed apps or even your mobile operating system can accomplish the same thing. If so, skip the app.</p><p>To stay safe from Android malware, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> is enabled on your smartphone. The reason being is that this free, pre-installed app scans all of your existing apps and any new ones you download for malware. So let’s say you accidentally install one of the decoy apps used in this campaign, it would get flagged as dangerous once the Anatsa malware is downloaded after an update. For additional protection though, you might want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it and to help you recover funds lost to malicious apps or other malware, then the <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html">best identity theft protection</a> might be worth investing in too.</p><p>Malicious apps provide hackers with an easy entry point into your phone as well as your digital life, so they’re not going to go away anytime soon despite Google and Apple’s best efforts. That’s why you need to be careful when installing new apps and periodically check your existing apps to make sure that nothing is amiss.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li>Macs under attack from dangerous new info-stealing malware — how to stay safe</li><li>Two-factor authentication provides an easy way to secure your accounts — here's how it works and how to enable it</li><li>AI browsers can’t tell legitimate websites from malicious ones — here’s why that’s putting you at risk</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Booking.com phishing scam is infecting users with malware by using lookalike URLs — don't fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/booking-com-phishing-scam-is-infecting-users-with-malware-by-using-lookalike-urls-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ A new scam is using lookalike characters to trick Booking.com users into visiting malicious websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TNnPGym3Nt4Ww4je7Sv4u9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qjwDgzaSA5VEUruzxLTJfn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Aug 2025 20:36:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qjwDgzaSA5VEUruzxLTJfn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Booking.com logo on a smartphone in front of a screen of computer code]]></media:description>                                                            <media:text><![CDATA[Booking.com logo on a smartphone in front of a screen of computer code]]></media:text>
                                <media:title type="plain"><![CDATA[Booking.com logo on a smartphone in front of a screen of computer code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qjwDgzaSA5VEUruzxLTJfn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/i-improved-my-digital-security-by-making-these-7-easy-changes">7 easy changes I made that drastically improved my digital security</a></li><li><a href="https://www.tomsguide.com/computing/online-security/at-and-t-users-may-be-eligible-for-usd177-million-data-breach-payments-what-you-need-to-know">AT&T agrees to $177 million data breach settlement — here's how to file a claim</a></li><li><a href="https://www.tomsguide.com/computing/parental-controls/how-to-track-your-kids-screen-time-and-the-best-tools-to-do-it">How to track your kids screen time — and the best tools to do it</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Android spyware is posing as an antivirus app to steal your photos and passwords — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-android-spyware-is-posing-as-an-antivirus-app-to-steal-your-photos-and-passwords-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ This fake 'antivirus' app is just a front for spyware designed to go after the sensitive personal and financial data on your Android phone. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Wt95Ci9SSdVjVxdZwhLzZk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 13 Aug 2025 11:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ scott.younker@futurenet.com (Scott Younker) ]]></author>                    <dc:creator><![CDATA[ Scott Younker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/RZsUpqcJ6Uj2q83oCUwNhQ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the latest tech news, including phones, computing and more. He’s been involved in tech since 2011 covering everything from cameras and swimming pool equipment to the latest gaming consoles and smart TVs. He is on a seemingly never ending hunt to build the easiest to use home media system. &lt;/p&gt;&lt;p&gt;Before Tom’s Guide, Scott worked for publications like &lt;em&gt;Digital Trends, Outdoor Photographer, Dead Beats Panel&lt;/em&gt;, and in a brief detour, &lt;em&gt;America’s Funniest Home Videos&lt;/em&gt;. Yes, he has seen more pratfalls, silly pets and ridiculous home movie fails than is reasonably healthy. &lt;/p&gt;&lt;p&gt;When not writing about the latest devices or advances in chipsets, be sure to ask about Scott about disc golf and sustainability, or just if you’re being cheeky, ask about his noodle arm. If you truly want to get nerdy, bring up board games and his ongoing losing streak. &lt;/p&gt;&lt;p&gt;Scott joined Tom&#039;s Guide in 2024 as the West Coast Reporter. He graduated from the School of Journalism at the University of Oregon with a degree in magazine journalism and a minor in communications. While there he blogged or wrote for several magazines including the Fluxx, Ethos and the Oregon Commentator. He briefly wrote and managed a moderately successful blog focused on web comics. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In an attempt to protect yourself online, you might have downloaded a seemingly safe antivirus app that turned out to be a <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now">malicious app</a> spreading <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-spyware-has-returned-via-malicious-play-store-apps-delete-them-right-now">dangerous spyware</a>. Unfortunately, it may have come via a random Telegram or strange text message from a friend too.</p><p>The LunaSpy Android spyware program was reported on in a recent Kaspersky <a href="https://www.kaspersky.com/blog/disguised-spy-for-android/54051/">blog post</a> which revealed that the spyware has been infiltrating phones since at least February of this year. Allegedly, LunaSpy can be sent via messaging apps and sold as an antivirus program and sometimes as a banking protection app.</p><p>The spyware pretends to scan your device for viruses to trick you into granting permissions to the app. However, doing so enables it to steal data, track you, and even record audio and video.</p><p>While it pretends to run antivirus scans, LunaSpy is actually swiping passwords, recording your screen, and even running commands on your phone. Kaspersky even found unused code that would allow it to <a href="https://www.tomsguide.com/computing/malware-adware/sparkkitty-spyware-caught-stealing-photos-on-iphone-and-android-and-the-reason-might-surprise-you">steal your photos</a>.</p><p>If you're data is stolen via LunaSpy, it's reportedly sent to over 150 command and control servers. These servers are then used by cybercriminals to communicate with and control infected devices.</p><h2 id="how-to-stay-safe-from-malicious-apps">How to stay safe from malicious apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>A spyware or malware infection can come from clicking on <a href="https://www.tomsguide.com/news/hackers-are-using-a-new-trick-to-fool-android-users-into-installing-malicious-apps-how-to-stay-safe">malicious links</a>, downloading attachments in emails from unknown senders or through piracy. However, one of the most common ways to be infected is through both official and unofficial app stores.</p><p>In the LunaSpy case, it can be traced back to malicious links. With that in mind, you need to be extremely careful putting new apps on your Android phone and especially ones recommended by others through messages on social media or over text.</p><p>If you haven't heard of an app before, look for it in the Google Play Store and read reviews as well as check its ratings first. Since these can both be faked though, you'll want to look for external reviews on other sites. Video reviews are especially helpful as they give you a chance to see the app in action.</p><div><blockquote><p>For Android phones, you want to make sure that Google Play Protect is enabled on your devices</p></blockquote></div><p>Even <a href="https://www.tomsguide.com/news/popular-android-screen-recorder-app-went-from-legitimate-to-malicious-overnight-what-you-need-to-know">good apps can go bad</a> when injected with malicious code, we recommend limiting the number of apps you have installed overall just to be safe. Fewer apps means less risk that you've downloaded a malicious one or a legitimate app that has been taken over by hackers.</p><p>For Android phones, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> is enabled on your devices. It's a free and built-in security app that scans your existing apps and any new ones you download for malware and other malicious activity. You might also want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it for additional protection.</p><p>Malicious apps aren't going anywhere, and suspicious links are only one prong in hackers' attempts to get sensitive data. However, if you pause before tapping on a strange link and limit the number apps on your phone, your chances of getting infected go down significantly.</p><p>Additionally, you'll want to discuss these safety practices with your younger and older family members and friends since not clicking suspicious links and investigating any new apps before you download them is key to keeping your loved ones safe from hackers.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/5-android-settings-you-need-to-turn-off-right-now-because-theyre-a-huge-security-risk">5 Android settings you need to turn off right now because they’re a huge security risk</a></li><li><a href="https://www.tomsguide.com/computing/online-security/im-a-security-editor-and-this-is-one-security-rule-i-never-break">I’m a security editor and this is one security rule I never break</a></li><li><a href="https://www.tomsguide.com/computing/online-security/12-computer-security-mistakes-youre-probably-making-and-what-to-do-instead">12 computer security mistakes you're probably making — and what to do instead</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 200,000 passwords, credit card data and more stolen by this dangerous new malware — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/200-000-passwords-credit-card-data-and-more-stolen-by-this-dangerous-new-malware-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Hackers are using a new info-stealing malware strain to steal sensitive personal and financial data right from your browser. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vaerbn7YLvAuCMrZ7ZuyF8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iJKvacosvMoCwbKjwcVGbP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Aug 2025 22:17:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iJKvacosvMoCwbKjwcVGbP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand typing at a computer in a dark room, lit up by the laptop&#039;s keyboard LEDs and red LED light]]></media:description>                                                            <media:text><![CDATA[A hand typing at a computer in a dark room, lit up by the laptop&#039;s keyboard LEDs and red LED light]]></media:text>
                                <media:title type="plain"><![CDATA[A hand typing at a computer in a dark room, lit up by the laptop&#039;s keyboard LEDs and red LED light]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iJKvacosvMoCwbKjwcVGbP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are now using legitimate-looking software and documents to infect unsuspecting users with a new <a href="https://www.tomsguide.com/computing/malware-adware/more-than-250-malicious-apps-are-spreading-info-stealing-malware-on-android-and-ios-delete-these-right-now">info-stealing malware</a> capable of pilfering your passwords, credit card data and more.</p><p>As reported by <a href="https://thehackernews.com/2025/08/vietnamese-hackers-use-pxa-stealer-hit.html" target="_blank">The Hacker News</a>, this new campaign is believed to be the work of Vietnamese-speaking cybercriminals who have begun deploying the PXA Stealer malware in their attacks.</p><p>First discovered by security researchers at <a href="https://www.tomsguide.com/computing/online-security/hackers-can-gain-access-to-your-macs-microphone-camera-and-more-through-flaws-in-these-popular-microsoft-apps-how-to-stay-safe">Cisco Talos</a>, PXA Stealer is an info-stealing malware written in Python. While it was initially used to target government organizations and businesses in the education sector throughout Europe and Asia, the hackers behind this new campaign have shifted their sights to go after ordinary people in the U.S., South Korea, the Netherlands, Hungary and Austria.</p><p>So far, SentinelOne has identified 4,000 unique <a href="https://www.tomsguide.com/computing/online-security/what-can-someone-do-with-my-ip-address">IP addresses</a> across 62 countries that have been infected by the PXA Stealer. What makes this particular malware campaign so dangerous is that in addition to how it can steal saved passwords, cookies, credit card info and any other autofill data stored in your browser as well as from crypto wallets and popular applications like <a href="https://www.tomsguide.com/news/hackers-are-tricking-discord-users-into-installing-malware-dont-fall-for-this">Discord</a>, the hackers behind it are also using a number of tricks and techniques to avoid detection.</p><p>Here’s everything you need to know about this new malware campaign along with some tips and tricks to help you avoid falling victim to it.</p><h2 id="sideloading-to-avoid-detection">Sideloading to avoid detection</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1306px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="rjvaLaDqTmZTLZ7RKhKSUB" name="shutterstock 1378498490.jpg" alt="Malware" src="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB.jpg" mos="" align="middle" fullscreen="" width="1306" height="734" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>In this new wave of attacks, the hackers responsible either tricked potential victims into visiting <a href="https://www.tomsguide.com/news/hackers-often-use-this-clever-trick-to-take-you-to-phishing-sites-can-you-spot-it">phishing sites</a> or convinced them to download a ZIP file which, in addition to a signed copy of the free Haihaisoft PDF Reader, also contains a malicious Dynamic link-library or <a href="https://www.tomsguide.com/news/hackers-are-using-one-of-microsofts-own-tools-to-spread-malware-what-you-need-to-know">DLL file</a>.</p><p>As SentinelOne’s security researchers explain in their <a href="https://www.sentinelone.com/labs/ghost-in-the-zip-new-pxa-stealer-and-its-telegram-powered-ecosystem/" target="_blank">report</a>, this malicious DLL file is an essential part of this campaign as it’s what allows the PXA Stealer malware to establish persistence via the Windows Registry on infected systems. However, it’s also used to download additional malicious components like Windows executables that are hosted remotely on file-sharing sites like Dropbox.</p><p>Once the PDF reader is installed and launched, this malicious DLL creates a command line script that tells Microsoft’s Edge browser to open a virus-filled PDF file. While the file doesn’t actually open and an error message is displayed, the damage is done.</p><p>Besides using a <a href="https://www.tomsguide.com/computing/malware-adware/these-malicious-android-malware-apps-were-downloaded-150000-times-from-the-play-store-delete-them-right-now">free PDF reader</a> as a lure, the hackers behind this campaign are also using a Microsoft Word 2013 executable to distribute the PXA Stealer malware. This executable looks like your standard Word file and comes attached in emails but when opened, it uses a different malicious DLL file to achieve the same end goal: infecting your PC with info-stealing malware.</p><p>To get all of this stolen data off of your computer, the hackers behind this campaign are using Telegram as an exfiltration channel. From there, all of those stolen passwords, credit card data and other sensitive personal information is then <a href="https://www.tomsguide.com/news/hackers-have-earned-millions-selling-your-data-on-the-dark-web-how-to-stay-safe">sold on the dark web</a> for other cybercriminals to use in their own attacks.</p><h2 id="how-to-stay-safe-from-malware-2">How to stay safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:66.70%;"><img id="6KXS4iqE4rw2D8SCHP62JF" name="Woman-Using-Laptop.jpg" alt="Woman using smartphone and laptop" src="https://cdn.mos.cms.futurecdn.net/6KXS4iqE4rw2D8SCHP62JF.jpg" mos="" align="middle" fullscreen="" width="1000" height="667" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Everywhere you turn online these days, there seems to be hackers lurking around the corner waiting to infect your devices with malware in order to steal your data.</p><p>In this particular campaign, the hackers behind it used either phishing sites or malicious email attachments to trick unsuspecting users. This is why you need to be extra careful when checking your inbox. </p><p>Don’t just click on any link you see in an email. Instead, you want to hover your mouse over the link to see where it’s taking you. If you don’t recognize the URL, don’t click on the link. Likewise, when it comes to email attachments, you always want to be wary when an unknown sender attaches a file to an email they’ve sent you. When in doubt, if you don’t recognize the sender, don’t download the attachment even if it appears to be legitimate at first glance.</p><p>Given that the PXA Stealer and other malware strains often target the data you’ve stored in your browser, you should avoid keeping sensitive information in it when possible. For instance, instead of having your browser store your saved passwords, you should use one of the <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">best password managers</a> instead. The same thing goes for your credit card details and other sensitive information.</p><p>While I would normally recommend keeping your PC protected with the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a>, the hackers behind this campaign used all sorts of clever tricks and techniques to avoid having their malware detected. In this case, it’s up to you to use your best judgement when clicking on links or downloading files online. Still, it never hurts to use a reliable antivirus to keep you protected from other viruses and threats online.</p><p>Given that the PXA Stealer was first used to target governments and educational organizations before regular people, I don’t think this is the last we’ve seen of this info-stealing malware yet. Instead, other hackers may try to use this malware strain in future attacks.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/i-ditched-my-passwords-for-passkeys-on-these-3-popular-services-and-it-took-me-less-than-10-minutes">I ditched my passwords for passkeys on these 3 popular services — and it took me less than 10 minutes</a></li><li><a href="https://www.tomsguide.com/computing/online-security/what-is-the-most-private-way-of-verifying-your-age">What is the most private way of verifying your age?</a></li><li><a href="https://www.tomsguide.com/computing/online-security/email-security-features-are-being-hijacked-to-steal-microsoft-365-logins-what-you-need-to-know">Email security features are being hijacked to steal Microsoft 365 logins — what you need to know</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More than 250 malicious apps are spreading info-stealing malware on Android and iOS — delete these right now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/more-than-250-malicious-apps-are-spreading-info-stealing-malware-on-android-and-ios-delete-these-right-now</link>
                                                                            <description>
                            <![CDATA[ New SarangTrap campaign uses malicious apps and domains to infect unsuspecting users with dangerous info-stealing malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pdgrVt6eerduwZ7FiuQnU9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Jul 2025 19:51:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You can never be too careful when downloading a new app to your iPhone or Android phone as what may look harmless on the surface could actually be a <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now">malicious app</a> designed to infect your device with malware.</p><p>Case in point, the mobile security firm <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-banking-trojan-now-shows-a-fake-lock-screen-to-steal-your-pin-and-your-cash-dont-fall-for-this">Zimperium</a> has discovered a new malware campaign which targets users of the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html">best iPhones</a> and <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> with over 250 malicious apps spread via 80+ malicious domains.</p><p>What sets this particular campaign apart is that in addition to posing as utility apps, many of the malicious apps used in it also posed as <a href="https://www.tomsguide.com/computing/online-security/fbi-warns-scammers-are-using-free-verification-services-to-dupe-dating-app-users-how-to-stay-safe">dating apps</a> along with file sharing ones and car service platforms.</p><p>Once installed on a vulnerable smartphone, the apps were then used to download a dangerous <a href="https://www.tomsguide.com/computing/online-security/youre-cordially-invited-to-get-scammed-hackers-are-using-fake-wedding-invites-to-steal-data-and-completely-take-over-victims-phones">info-stealing malware</a> capable of stealing all sorts of sensitive personal data including a victim’s contacts and even their photos. The hackers behind this campaign then took things a step further, threatening to extort victims by leaking their private info and photos to their contacts or online if their demands weren't met.</p><p>Here’s everything you need to know about this new malware campaign along with some tips and tricks to help you stay safe from malicious apps and the dangers they pose to both your data and your devices.</p><h2 id="delete-these-apps-right-now">Delete these apps right now</h2><p>Before we go into the campaign itself and how it worked, you should first check your phone to make sure that you haven’t installed any of the apps below. If you have, you’re going to want to manually delete them from your devices:</p><ul><li><strong>Pilatess</strong></li><li><strong>Mfile</strong></li><li><strong>Zcloud</strong></li><li><strong>Haikiss</strong></li><li><strong>WhaleS</strong></li><li><strong>KingCloud</strong></li><li><strong>Acloud</strong></li><li><strong>Cloud-k</strong></li><li><strong>AceCloud</strong></li><li><strong>Lovelush</strong></li><li><strong>LOVESS</strong></li><li><strong>Slovehome</strong></li><li><strong>Erotic-s</strong></li><li><strong>BKing</strong></li></ul><p>I’ve highlighted just a few of them above but you can see the <a href="https://docs.google.com/spreadsheets/d/1TxyUKtgGC0dFB3nYjS-LMANAmkjvmiY1PuVOdPd2ZBo/edit?gid=1869422751#gid=1869422751">full list here</a> (Google Sheet). If you take a closer look at the names of these malicious apps, you’ll notice that many of them are in Korean which makes sense given that this campaign mainly targeted users in South Korea. </p><p>Given that anyone could have shared a link to one of the <a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-over-free-online-file-converters-that-infect-your-pc-with-malware">malicious domains</a> hosting these fake apps, iPhone and Android users worldwide could be impacted. Either way, it’s always a good idea to take a closer look at all of the apps you have installed and to delete any you don’t recognize or haven’t used in a while.</p><h2 id="from-phishing-sites-to-fake-apps">From phishing sites to fake apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="jowW99UuNc2qV2qHzCyhoV" name="phishing-hook-shst.jpg" alt="A fishing hook resting on a laptop keyboard." src="https://cdn.mos.cms.futurecdn.net/jowW99UuNc2qV2qHzCyhoV.jpg" mos="" align="middle" fullscreen="" width="1000" height="562" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: wk1003mike/Shutterstock)</span></figcaption></figure><p>In a <a href="https://zimperium.com/blog/the-dark-side-of-romance-sarangtrap-extortion-campaign" target="_blank">blog post</a> detailing the inner workings of this new campaign dubbed SarangTrap, Zimperium’s security researchers explain that potential victims are first tricked into visiting carefully crafted <a href="https://www.tomsguide.com/news/hackers-often-use-this-clever-trick-to-take-you-to-phishing-sites-can-you-spot-it">phishing sites</a>.</p><p>These are designed to <a href="https://www.tomsguide.com/news/6000-sites-used-to-impersonate-100-top-brands-and-steal-your-banking-info-how-to-stay-safe">impersonate popular brands</a> and app stores which not only adds legitimacy to the campaign but may also entice users to download these bad apps.</p><p>Once installed, these fake apps lure users in with slick user interfaces while requesting access to loads of <a href="https://www.tomsguide.com/computing/malware-adware/scammers-are-tricking-android-users-into-installing-a-fake-antivirus-app-thats-actually-malware-how-to-stay-safe">unnecessary permissions</a> with the caveat that they won’t work without them. To make these apps seem more exclusive, especially the ones posing as dating apps, users are also prompted to enter a valid invitation code.</p><p>After being entered, this invitation code is sent to a hacker-controlled server for validation after which, these malicious apps then request access to the sensitive permissions they’ll use to infect a device with malware and steal personal info from it.</p><p>Besides acting as a lure, this process allows the malware to remain undetected by the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> and other security solutions designed to stop malicious activity from bad apps.</p><p>With the necessary permissions in hand, these fake apps reveal their true nature. While they look slick and polished at first, they contain no dating features or other functionality at all. Instead, they’re just a facade used by the hackers behind this campaign to gain a foothold on vulnerable devices from which they can then steal all sorts of valuable sensitive data.</p><p>When it comes to the types of data the malware spread by these fake apps is able to steal, it can download a victim’s phone number and device identifiers along with all their photos and text messages. With all this info, the hackers behind this campaign can easily extort victims, though they could also bundle it altogether and <a href="https://www.tomsguide.com/news/hackers-have-earned-millions-selling-your-data-on-the-dark-web-how-to-stay-safe">sell this data to other cybercriminals</a> to use in their own attacks.</p><p>Surprisingly, in addition to malicious Android apps, this campaign also uses a deceptive mobile configuration profile to go after iPhone users. By installing this profile on an iPhone, the hackers are able to steal much of the same sensitive data on iOS including a victim’s contacts and photos.</p><h2 id="how-to-stay-safe-from-malicious-apps-2">How to stay safe from malicious apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:66.70%;"><img id="6KXS4iqE4rw2D8SCHP62JF" name="Woman-Using-Laptop.jpg" alt="Woman using smartphone and laptop" src="https://cdn.mos.cms.futurecdn.net/6KXS4iqE4rw2D8SCHP62JF.jpg" mos="" align="middle" fullscreen="" width="1000" height="667" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Just like with new software on your computer, you always need to be careful when installing new apps on your phone, especially as we now have so much personal and even financial info on our mobile devices.</p><p>For starters, you want to avoid <a href="https://www.tomsguide.com/news/over-60000-compromised-android-apps-found-spreading-adware-how-to-stay-safe">sideloading apps</a> or installing apps from unknown sources or websites. If you’re taken to a site trying to get you to install an app instead of to an official app store like the Google Play Store or Apple’s App Store, this is a major red flag and a great indication that you should avoid this particular app altogether.</p><p>When you install a new app on your devices, you want to pay close attention to the types of permissions it requests the first time that you open it. While it makes sense for a messaging app to request access to your text messages, it definitely doesn’t when a dating app does so. If any permissions seem odd or unnecessary, this is another red flag that something could be off with a particular app.</p><p>Besides being extra careful when installing new apps, I highly recommend that you limit the number of apps on your phone overall. Having a lot of apps installed makes it difficult to find malicious ones and <a href="https://www.tomsguide.com/news/popular-android-screen-recorder-app-went-from-legitimate-to-malicious-overnight-what-you-need-to-know">even good apps can go bad</a> when injected with malicious code. The fewer apps you have, the less likely it is that one of them will be malicious or turn malicious later.</p><p>If you’re using an Android phone, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> is enabled as this pre-installed security solution scans all of the new apps you download as well as all of your existing apps for malware. For extra protection though, you may also want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it. </p><p>While there isn't an iPhone equivalent of these apps due to Apple’s own restrictions, the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> from <a href="https://www.tomsguide.com/reviews/intego-premium-bundle-x9">Intego</a> can scan your iPhone or iPad for malware when plugged into your Mac via a USB cable. </p><p>Given that downloading and installing a malicious app even accidentally can have very serious consequences, you may also want to invest in one of the <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html">best identity theft protection services</a>. They can help you get your identity back after having it stolen as well as compensate you for any funds lost to fraud or a cyberattack.</p><p>Malicious apps are the easiest way for hackers to establish a foothold on your devices and gain leverage over you and your data which is why they aren’t going anywhere anytime soon. This is why it’s up to you to be proactive as well as careful when it comes to which apps you download and where you download them from.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/your-ring-cameras-werent-hacked-over-the-weekend-heres-what-actually-happened">Your Ring cameras weren’t hacked over the weekend — here’s what actually happened</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/12-signs-your-phone-has-been-hacked-and-what-to-do-next">12 signs your phone has been hacked — and what to do next</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/this-android-malware-poses-as-real-apps-to-take-you-to-dangerous-sites-and-flood-your-phone-with-spam">This Android malware poses as real apps to take you to dangerous sites and flood your phone with spam</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 12 signs your phone has been hacked — and what to do next ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/12-signs-your-phone-has-been-hacked-and-what-to-do-next</link>
                                                                            <description>
                            <![CDATA[ Hacks can happen to anyone, even on mobile devices. Here's what to do when the worst occurs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WLmXRAr2njWcWAMCxTwCsS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/m3TQswzZRHakuHwBtjMzFf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 20 Jul 2025 08:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/m3TQswzZRHakuHwBtjMzFf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Confused woman looks at phone]]></media:description>                                                            <media:text><![CDATA[Confused woman looks at phone]]></media:text>
                                <media:title type="plain"><![CDATA[Confused woman looks at phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/m3TQswzZRHakuHwBtjMzFf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While signs that you've been hacked may be obvious if you're on your home computer, it might be a little more subtle if you're looking for them on your smartphone. Many people still don't believe that security issues and hacks are likely on a smartphone, so they don't take precautions against such attacks, making them vulnerable to threats like phishing, malicious downloads or unsecured Wi-Fi. </p><p>However, if you don't have any<a href="https://www.tomsguide.com/best-picks/best-android-antivirus"> antivirus protection</a> or coverage for your smartphone and you're not practicing safe cyber practices when it comes to securing your mobile devices, they're at risk too. Here are the warning signs to look out for when it comes to mobile malware — and what to do if you suspect that you may have already been victimized by a virus or worse. </p><h2 id="what-to-look-for">What to look for</h2><ul><li><strong>Pop up ads:</strong> Just like on a desktop, if you're seeing pop up ads appear on your phone, that's a big red flag warning sign. Do not click on any of these, as they can lead you to malicious websites.</li><li><strong>Performance issues:</strong> For example, if your phone is frequently freezing, crashing, or lagging when performing its usual tasks. Malware and viruses consume huge amounts of processing power, so your device will have problems when trying to do typical day-to-day jobs.</li><li><strong>Randomly rebooting or shutting down: </strong>This could be caused by malicious code, or by a hacker trying to remote control your device through the malicious code. Either way, it's never a great indicator about your device.</li><li><strong>Microphone or camera turning on:</strong> If either the microphone or camera turns on, when you don't turn them on yourself, it's another red flag — and it could mean that an attacker is spying on you and your activities.</li><li><strong>Unfamiliar apps, messages, or calls: </strong>If you see apps you don't remember installing, or calls or texts you didn't make, that's unauthorized use and it usually indicates malware.</li><li><strong>Unusually low battery:</strong> Malware is a battery hog, so if your phone is constantly needing a recharge for no good reason, this could be why.</li><li><strong>Overheating (when idle):</strong> If your device is getting quite warm when it's not working hard, again, that could be malware which will work your device's processor hard.</li><li><strong>Unexpected two-factor authentication requests:</strong> Two-factor and multi-factor authentication is set up as an extra layer to protect your accounts from being accessed by hackers, so if you're getting requests you don't expect it's a good indication that someone has your password and is trying to access your accounts.</li><li><strong>Account issues:</strong> Any unexpected password changes like reset requests, or obviously, getting locked out of accounts is reason for serious concern.</li><li><strong>Data spikes and/or unknown call charges:</strong> A threat actor could be using your phone to transfer data, make purchases, send messages or make calls.</li><li><strong>Websites look different:</strong> Whether they're redirecting you to spammy websites you don't want to be or they just appear strange, this may mean your web traffic is being hijacked.</li><li><strong>Unable to shut down or turn off:</strong> Malware may be keeping your device turned on.</li></ul><h2 id="what-to-do-now">What to do now</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MKZXHBEXXXQw7syUEuWt9" name="shutterstock_1260320974 (1).jpg" alt="A picture of a skull and bones on a smartphone depicting malware" src="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>So you think you may have been hacked — what now? There are a few steps you can take to get control back, protect your data and your device. None of them are sure things and none of them are fool-proof but they're a good starting point. </p><ul><li>If you have an <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">antivirus program</a> installed on your mobile device, <strong>start by running a security scan</strong> that can find and (hopefully also) remove the malware.</li><li>If you see any unfamiliar or suspicious apps, downloads or files on your phone that you don't remember installing, remove them —  don't just delete the icon, but make sure you're deleting the app entirely.</li><li><strong>Back up essential data:</strong> Not applications or system data, but other important things that may not have been infected like your photos, contacts, and important documents.</li><li><strong>Check your backups:</strong> Make sure that they are from a date before the hack or infection occurred so you don't just reinfect your phone over and over again. Restore only essential, necessary data and manually reinstall apps from the app store.</li><li><strong>Change your passwords:</strong> This should be done as soon as possible, and should be done from a separate, uninfected device. Make sure you're creating strong, unique passwords for all your accounts, enabling multi-factor authentication whenever available and using a <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a>.</li><li><strong>Clear cookies, cached data and saved history: </strong>Anything stored in your browser settings should get wiped clean as it could remove malicious code that is being stored there.</li><li><strong>Secure accounts:</strong> Review all recent activity on your online accounts, looking for any unauthorized activity, transactions or messages. If necessary, consider freezing accounts, requesting new cards or updating credentials.</li><li><strong>Update your operating system:</strong> An easy way to make sure you have the most up-to-date protection against malware.</li><li><strong>Disconnect:</strong> Disconnect your phone from Wi-Fi and cellular networks, then restart your phone in Safe Mode or Recover Mode (depending on your operating system).</li><li><strong>Shut it down: </strong>Perform a full shut down (when needed) and disable always on location features, which could be used by malware.</li><li><strong>Perform a factory reset:</strong> To be used as a last resort, and only when you have your files backed up. This can sometimes be the only way to resolve an issue.</li><li><strong>Notify contacts and authorities:</strong> Let your contacts know that you've been hacked so they can be on alert for any potential <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing messages</a>, but also let your financial and banking institutions know so they can be aware of any potential identity theft or financial fraud.</li></ul><p>Hacks can happen to anyone and it's important to realize that you're not powerless — if you stay calm, and know what to do, you can salvage a good amount of your data and even your device. Knowing what to do after a hack is just as important as knowing how to stay safe in the first place and anyone can make a mistake and quickly become a victim to a phishing scam, a malicious website or a bad Wi-Fi connection. Stay calm, stay safe and stay informed. </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/best-picks/best-android-antivirus">The best Android antivirus apps in 2025</a></li><li><a href="https://www.tomsguide.com/computing/antivirus/why-arent-there-antivirus-apps-for-the-iphone">Why aren't there antivirus apps for the iPhone?</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Android malware poses as real apps to take you to dangerous sites and flood your phone with spam ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-android-malware-poses-as-real-apps-to-take-you-to-dangerous-sites-and-flood-your-phone-with-spam</link>
                                                                            <description>
                            <![CDATA[ The Konfety malware has returned and it's now posing as real apps to better avoid detection on vulnerable Android smartphones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bYpinzj7y47PSBrhuFxb3Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Jul 2025 17:37:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:description>                                                            <media:text><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new version of the Konfety malware that attacks the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> now uses distorted APK files as well as other methods in order to avoid being detected and analyzed. </p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/android-malware-konfety-uses-malformed-apks-to-evade-detection/" target="_blank">Bleeping Computer,</a> this latest Konfety malware strain, which is neither <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-android-spyware-has-returned-via-malicious-play-store-apps-delete-them-right-now">spyware</a> nor a <a href="https://www.tomsguide.com/computing/malware-adware/this-nasty-android-banking-trojan-lets-hackers-completely-hijack-your-phone-how-to-stay-safe">remote access trojan</a>, can pretend it is a legitimate app by copying both the branding and names of real apps from the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a>. </p><p>Konfety mimics real products available on the Play Store, though it does not reproduce the same functionality of those apps. Likewise, it's distributed and promoted through third-party stores. This is a method that researchers have sometimes called a ‘decoy twin’ or ‘<a href="https://www.tomsguide.com/computing/malware-adware/over-one-million-android-devices-infected-with-password-stealing-pre-installed-botnet-malware-how-to-stay-safe">evil twin</a>’ tactic, and is exactly why it is recommended to only download software from trusted publishers and to avoid installing APK files from third-party app stores. </p><p>Still, some users will resort to searching on these marketplaces for supposedly free versions of popular apps either because they don’t have access to Google services as their Android device isn’t supported or because they don’t want to pay for legitimate software. </p><p>Here's everything you need to know about this new Android threat including some tips and tricks to help keep your phone safe from hackers and malware free.</p><h2 id="hiding-in-plain-sight">Hiding in plain sight</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:970px;"><p class="vanilla-image-block" style="padding-top:56.29%;"><img id="YrLiKU6FUufsbEckjUp8Rd" name="Android apps.jpg" alt="Android apps" src="https://cdn.mos.cms.futurecdn.net/YrLiKU6FUufsbEckjUp8Rd.jpg" mos="" align="middle" fullscreen="" width="970" height="546" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Lukmanazis/Shutterstock)</span></figcaption></figure><p>Once Konfety has been installed on a victim’s device it uses a malformed ZIP structure to avoid analysis and detection, and will begin its malicious behavior. It can redirect users to <a href="https://www.tomsguide.com/news/these-misspelled-websites-are-spreading-nasty-malware-how-to-stay-safe">dangerous websites</a>, install unwanted apps and provide <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-chrome-word-and-onedrive-errors-to-trick-people-into-installing-malware-how-to-stay-safe">fake browser notifications</a>. Additionally, it can produce ads using a CaramelAds SKD and exfiltrate device data like installed apps, network configuration and system information. </p><p>Thanks to the capabilities of this latest version, it can also <a href="https://www.tomsguide.com/news/these-35-malicious-android-apps-have-infected-millions-delete-them-now">hide its app icon and name</a>, and then use geofencing to alter its behavior depending on the region the device is located in. It performs all its nefarious hidden features courtesy of an encrypted DEX file inside the APK which is loaded and decrypted during runtime, and contains hidden services declared in the AndroidManifest file which allows for the delivery of more dangerous modules. </p><p>Konfety also manipulates the APK files to confuse and break static analysis and reverse engineering tools by signaling that the file is encrypted when it is not, which triggers a false password prompt when trying to inspect the file. This can block or delay access to the APKs contents. </p><p>Next, critical files within the APK are declared using BZIP compression, which is not supported by analysis tools and this results in a parsing failure. Android ignores the declared method and returns to the default processing which allows Konfety to install and run on the device without issue.</p><h2 id="how-to-stay-safe-from-android-malware-4">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/5-4-million-hit-in-major-healthcare-data-breach-names-emails-ssns-and-more-exposed">5.4 million hit in major healthcare data breach — names, emails, SSNs and more exposed</a></li><li><a href="https://www.tomsguide.com/computing/online-security/google-gemini-for-workspace-has-been-exploited-to-send-emails-with-hidden-malicious-messages">Google Gemini flaw exploited to turn AI-powered email summaries into the perfect phishing tool — everything you need to know</a></li><li><a href="https://www.tomsguide.com/computing/online-security/this-new-android-attack-could-trick-you-into-compromising-your-own-phone-everything-you-need-to-know">This new Android attack could trick you into compromising your own phone — everything you need to know</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This dangerous banking trojan now uses scheduled maintenance to hide its malicious activities — don’t fall for this ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-dangerous-banking-trojan-now-uses-scheduled-maintenance-to-hide-its-malicious-activities-dont-fall-for-this</link>
                                                                            <description>
                            <![CDATA[ The Anatsa banking trojan was recently discovered hiding in a malicious app as part of a new campaign that uses the malware to drain bank accounts. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3qaghnf2VAZp2FXzWqKL49</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Jul 2025 21:32:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:description>                                                            <media:text><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a skull and bones on a smartphone depicting malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MKZXHBEXXXQw7syUEuWt9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Even if you stick to official app stores, you could end up downloading a <a href="https://www.tomsguide.com/computing/online-security/delete-these-20-apps-right-now-if-you-downloaded-them-from-the-play-store-theyre-malicious">malicious app</a>, which is exactly what happened to 50,000 Android users who accidentally installed a dangerous <a href="https://www.tomsguide.com/computing/malware-adware/this-android-banking-trojan-just-got-a-serious-upgrade-to-take-over-your-phone-and-it-now-hides-in-legitimate-apps">banking trojan</a> on their devices. </p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/android-malware-anatsa-infiltrates-google-play-to-target-us-banks/" target="_blank">BleepingComputer</a>, the <a href="https://www.tomsguide.com/news/dangerous-android-trojan-can-drain-your-bank-accounts-how-to-stay-safe">Anatsa banking trojan</a> is back as part of a new campaign that uses a malicious app posing as a PDF viewer to infect unsuspecting users of the best Android phones.</p><p>The discovery was made by security researchers at <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-malware-is-adding-fake-contacts-to-your-phone-while-draining-bank-accounts">Threat Fabric</a> who have been tracking Anatsa for years. The banking trojan is often hidden in popular utilities, and to date, it has been downloaded almost a million times.</p><p>What makes malware like this particularly dangerous is that it’s designed to target popular banking and finance apps. From JP Morgan to Capital One to TD Bank and others, Anatsa can impersonate them all and the banking trojan does this through <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts">overlay attacks</a>. While you might think you’re logging into your bank account, if your phone is infected, you’re actually handing over your credentials to hackers who can then use them to drain your accounts and steal your hard-earned cash.</p><p>Here’s everything you need to know about this latest Anasta campaign, including some tips and tricks to help keep you and your devices safe from Android malware.</p><h2 id="hiding-in-a-seemingly-harmless-app">Hiding in a seemingly harmless app</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AYcKTPANzzvhtXKQHywAU6" name="malicious-pdf-app-threat-fabric" alt="A screenshot of a listing page for a malicious app that has since been removed from the Google Play Store" src="https://cdn.mos.cms.futurecdn.net/AYcKTPANzzvhtXKQHywAU6.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Threat Fabric / Tom's Guide)</span></figcaption></figure><p>Although it has since been removed, Threat Fabric’s researchers recently found the Anatsa banking trojan hiding in a PDF viewer app on the <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-google-play-store-pages-to-infect-android-phones-with-a-dangerous-trojan-how-to-stay-safe">Google Play Store</a> called “Document Viewer – File Reader” published by the developer “Hybrid Cars Simulator, Drift & Racing,” according to a <a href="https://www.threatfabric.com/blogs/anatsa-targets-north-america-uses-proven-mobile-campaign-process" target="_blank">new report</a>.</p><p>Based on a screenshot of the app’s download page taken by the cybersecurity firm, more than 50,000 Android users downloaded this malicious app before it was taken down. If you did download this app, you should stop what you’re doing and immediately manually remove it from your phone.</p><p>Just like with other malicious apps, Threat Fabric found that this one used a sneaky tactic where the app was “clean” until it raked up enough users. Once it became popular, though, its creator or hackers who hijacked the app then <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps">added malicious code</a> to it via an update.</p><p>As you might have guessed, this injected code contains the Anatsa banking trojan, which is installed on a vulnerable Android device as a separate app. By connecting to a hacker-controlled server, malware is able to get a list of targeted apps, then looks for them on the infected device. If any of them are found, then overlay attacks are used to steal user credentials from them.</p><p>This latest campaign adds a new trick, though, to prevent users from taking action until it’s too late. You know those 'down for scheduled maintenance' error messages you often see when trying to check your account balance? Well, Anatsa now shows them too over your legitimate banking apps to hide its malicious activities in the background, and by the time the message is gone, so too are your banking credentials.</p><p>Google has since removed the latest malicious app spreading the Anatsa banking trojan from the Play Store. However, if you did download it, you need to remove it and then run a full system scan using <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a>. Likewise, it’s also recommended that you reset your bank credentials just in case they ended up in the wrong hands. </p><h2 id="how-to-stay-safe-from-android-malware-5">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>While I often recommend sticking to official app stores and not <a href="https://www.tomsguide.com/news/over-60000-compromised-android-apps-found-spreading-adware-how-to-stay-safe">sideloading apps</a>, this doesn’t always work due to malicious apps. For this reason, even if you’re extra careful when installing new apps, you could accidentally end up infecting your Android phone with malware.</p><p>This is why you want to carefully scrutinize any app you’re thinking about installing. Check its rating and reviews on the Play Store, and since these can be faked, you also want to look for external reviews on other sites. Video reviews are even better if you can find them, since they give you a chance to see the app in question in action before you download it.</p><p>At the same time, you also want to <a href="https://www.tomsguide.com/news/60-android-apps-with-100-million-installs-actually-contain-malware-delete-them-right-now">limit the number of apps</a> you have installed on your phone overall. The reason for this is that with fewer apps, you’re less likely to have one of the apps you do have installed go bad after an update. </p><p>Likewise, it’s always a good idea to stick to known, trusted developers when installing new apps. You also want to ask yourself if you really need a new app or if one of your existing apps or even your phone itself can accomplish the same functionality.</p><p>As for staying safe from Android malware, you want to make sure that Google Play Protect is enabled on your phone. This free and pre-installed security app scans all of your existing apps and any new ones you download for malware to help keep you and your devices safe. However, for extra protection, you may want to consider installing one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it.</p><p>Malicious apps are one of the easiest ways for hackers to establish a foothold on your devices, and as a result, I don’t see them going away anytime soon. This is why you always need to be extra careful when installing new apps on your phone, even if they come from official app stores.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/nearly-2-million-people-hit-by-malicious-chrome-installations-that-can-track-you-what-to-do-now">Nearly 2 million people hit by malicious Chrome installations that can track you — what to do now</a></li><li><a href="https://www.tomsguide.com/computing/online-security/more-than-1-200-fake-amazon-sites-pop-up-ahead-of-prime-day-avoid-getting-scammed">More than 1,200 fake Amazon sites pop up ahead of Prime Day — avoid getting scammed</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-mac-malware-just-got-a-major-upgrade-which-makes-it-even-harder-to-delete-how-to-stay-safe">This dangerous Mac malware just got a major upgrade which makes it even harder to delete — how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Mac malware just got a major upgrade which makes it even harder to delete — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-dangerous-mac-malware-just-got-a-major-upgrade-which-makes-it-even-harder-to-delete-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ The hackers behind the infamous Atomic Stealer have added a new component to the malware that allows it to maintain persistence on infected Macs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bAkB6X9iZQ3bUwFKzfmeSS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Jul 2025 10:30:00 +0000</pubDate>                                                                                                                                <updated>Tue, 08 Jul 2025 21:13:10 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:description>                                                            <media:text><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:text>
                                <media:title type="plain"><![CDATA[MacBook Pro 16-inch 2021 sitting on a patio table]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wKaEoNvjNpRkyZH74YAq2B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Just when you thought your Mac was safe, an updated version of a popular <a href="https://www.tomsguide.com/computing/malware-adware/new-cuckoo-macos-malware-can-take-over-all-macs-and-steals-your-passwords-too-dont-fall-for-this">Mac malware</a> strain is making the rounds online which can leave a backdoor on your computer that hackers can use as they please.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/atomic-macos-infostealer-adds-backdoor-for-persistent-attacks/" target="_blank">BleepingComputer</a>, the <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-by-malicious-info-stealing-malware-spread-through-ads-and-fake-software-dont-fall-for-this">Atomic Stealer</a> malware was first discovered back in 2023. Since then though, it’s been constantly upgraded with new capabilities that allow it to target the <a href="https://www.tomsguide.com/best-picks/best-macbook">best MacBooks</a> and other Apple computers in an effort to steal keychain passwords, local files, passwords, browser cookies, stored credit card data and of course, cryptocurrency.</p><p>Now though, the Moonlock cybersecurity division of the software provider <a href="https://www.tomsguide.com/computing/antivirus/5-common-mistakes-people-make-when-shopping-for-antivirus-software">MacPaw</a> has observed a new Atomic Stealer version that can create a <a href="https://www.tomsguide.com/news/this-new-macos-backdoor-lets-hackers-take-over-your-mac-remotely-how-to-stay-safe">backdoor on infected Macs</a>, leaving them vulnerable to additional and more devastating attacks.</p><p>Here’s everything you need to know about this upgraded Mac malware along with some tips and tricks on how you can keep your Mac safe from hackers and virus-free.</p><h2 id="from-hidden-file-to-backdoor">From hidden file to backdoor</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YwKRVzwvLwup6hDGh5bVNM" name="RzdqY6hhVUXJjJYEgfCrVe.jpg" alt="A hacker typing quickly on a keyboard" src="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Atomic Stealer is actually a <a href="https://www.tomsguide.com/news/password-stealing-erbium-malware-is-spreading-fast-and-loved-by-cybercriminals">malware-as-a-service</a> offering which means that other cybercriminals pay its creator a monthly subscription fee of $1,000 to $3,000 in order to use the malware in their own attacks.</p><p>Thanks to a tip from the independent security researcher g0njxa on X, MacPaw’s cybersecurity division was able to get their hands on a new Atomic Stealer sample that includes this updated backdoor functionality. After analyzing the sample, Moonlock found that it contains an embedded backdoor that’s able to remain on an infected Mac even after the device has been rebooted.</p><p>The executable that makes this backdoor possible is a binary file named ‘.helper’ which is downloaded and saved in a victim’s home directory after their Mac is infected with the Atomic Stealer malware. In a <a href="https://moonlock.com/amos-backdoor-persistent-access" target="_blank">blog post</a> discussing their findings, Moonlock’s security researchers explain that this binary file is hidden after an infection to make it harder to detect.</p><p>The malware’s creators are using a persistent wrapper script named ‘.agent’ which is also hidden to run ‘.helper’ in a loop as the logged-in user. Meanwhile, a LaunchDaemon (com.finder.helper) installed via AppleScript is used to ensure that this ‘.agent’ wrapper script runs every time an infected Mac is powered on.</p><p>By using a victim’s stolen password, this action is executed with elevated privileges which allows this new backdoor to be used by hackers to do things like execute commands remotely, log key strokes, introduce additional payloads or even to move laterally across a network to target other devices connected to it.</p><p>A malware infection is bad enough as it is but one that creates a backdoor into your computer is the last thing you want to deal with. This is because persistent malware is much harder to remove.</p><h2 id="how-to-stay-safe-from-mac-malware-2">How to stay safe from Mac malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="DgqWmPAUgj3TpRQWmkkka7" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/DgqWmPAUgj3TpRQWmkkka7.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>In their blog post, Moonlock’s security researchers also explain that this new version of the Atomic Stealer malware is currently being distributed through two main avenues: <a href="https://www.tomsguide.com/news/heres-another-big-reason-to-avoid-pirating-content-online">cracked or pirated software</a> and <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">spear phishing</a> campaigns targeting high-value users.</p><p>As such, to avoid being infected with the Atomic Stealer malware, you shouldn’t download any cracked or pirated software. Besides being illegal, downloading pirated software puts you at risk from malware since there’s no telling whether or not there may be malicious code inside. This is why you want to stick to official app stores like the <a href="https://www.tomsguide.com/computing/macos/macos-sequoia-is-streamlining-downloads-from-the-mac-app-store-heres-what-you-need-to-know">Mac App Store</a> or download software (you’ve paid for) directly from a reputable company.</p><p>When it comes to spear phishing, the less information that’s available about you online, the better. Let’s say you have a lot of cryptocurrency stored in your crypto wallet. Well just like with money in the bank, you want to keep that info to yourself instead of advertising it online via social media. </p><p>Once the hackers using Atomic Stealer have a high-profile individual in their sights, they often use <a href="https://www.tomsguide.com/computing/online-security/macs-under-attack-from-north-korean-malware-stealing-passwords-and-more-how-to-stay-safe">fake job interviews</a> as a means to get close to potential victims. From there, they coerce them into handing over their system password by having them enter it to enable screen sharing. This is a huge red flag since screen sharing is built into most video conferencing software and even then, you’d never have to type in your password to get it to work, especially if you aren’t the one hosting the video call.</p><p>As for staying safe from malware and other viruses, your Mac does come with built-in security software in the form of <a href="https://www.tomsguide.com/news/macos-is-getting-even-better-at-scanning-for-malware-heres-how">XProtect</a>. However, given the sheer number of threats and online scams these days, it’s worth investing in one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> solutions to run alongside it for even stronger protection.</p><p>Given how successful the Atomic Stealer malware has proven to be for hackers over the past few years, I don’t see this threat going away anytime soon. This is why you need to improve your own cyber hygiene and stay up to date on the latest threats. That way, you’ll be far less likely to fall for the tricks hackers use to gain initial access to you and your devices.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/more-than-1-200-fake-amazon-sites-pop-up-ahead-of-prime-day-avoid-getting-scammed">More than 1,200 fake Amazon sites pop up ahead of Prime Day — avoid getting scammed</a></li><li><a href="https://www.tomsguide.com/computing/antivirus/prime-day-antivirus-deals-2025">Best Prime Day antivirus deals: 7 heavily discounted security suites to keep you safe online</a></li><li><a href="https://www.tomsguide.com/computing/online-security/your-old-accounts-are-an-online-gold-mine-for-cybercriminals-what-you-need-do-right-now-to-stay-safe">Your old accounts are an online gold mine for cybercriminals — what you need do right now to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New FileFix attack brings ClickFix social engineering to Windows File Explorer — how to stay safe  ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-filefix-attack-brings-clickfix-social-engineering-to-windows-file-explorer-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ The ClickFix malware has evolved and can now attack you directly through Windows Explorer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jKD4Y3xZrBibSTh8s2k6Zk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gMi9vtqPLpPYTvdR4TKZbV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Jun 2025 17:35:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gMi9vtqPLpPYTvdR4TKZbV-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker typing on a computer]]></media:description>                                                            <media:text><![CDATA[A hacker typing on a computer]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker typing on a computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gMi9vtqPLpPYTvdR4TKZbV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Developed by cybersecurity researcher, mr. d0x, a FileFix attack is a new version of the ever popular <a href="https://www.tomsguide.com/computing/online-security/hackers-target-popular-student-site-iclicker-to-spread-malware-via-clickfix-attacks-how-to-stay-safe">ClickFix</a> social engineering tool.  </p><p>For those unfamiliar with ClickFix, it tricks users into executing malicious commands by convincing them that they need to ‘fix’ something in order to complete a task on their machines. </p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/filefix-attack-weaponizes-windows-file-explorer-for-stealthy-powershell-commands/" target="_blank">BleepingComputer</a>, this new FileFix method uses the Windows File Explorer address bar instead. Mr.d0x not only discovered the new method but has demonstrated that it can be used in attacks to target company employees via the same <a href="https://www.tomsguide.com/computing/online-security/what-is-social-engineering">social engineering techniques</a> that have proven highly successful with ClickFix.</p><p>ClickFix attacks, which have surged in popularity recently, are browser-based and use a variety of tactics to get victims to click on a button in their browser that will copy a command to their Windows clipboard. The victim is then told to paste the command into PowerShell or prompted to perform an additional command in order to “fix” the issue. </p><p>This is frequently seen as a <a href="https://www.tomsguide.com/computing/online-security/hackers-are-using-recaptcha-to-trick-users-into-infecting-their-own-pcs-with-malware-how-to-stay-safe">reCAPTCHA</a> or an error that needs to be corrected via the Win+R Run Dialog. It has proven to be an extremely effective malware tool, used to spread <a href="https://www.tomsguide.com/computing/malware-adware/neptune-rat-malware-is-hijacking-windows-pcs-holding-them-for-ransom-and-stealing-passwords">dangerous infostealers</a> and launch <a href="https://www.tomsguide.com/computing/online-security/windows-pcs-under-threat-from-zero-day-flaw-used-in-ransomware-attacks-update-your-computer-right-now">ransomware attacks</a>. </p><p>The FileFix update created by mr.d0x is similar to a typical<a href="https://www.tomsguide.com/computing/online-security/macs-under-threat-from-thousands-of-hacked-sites-spreading-malware-how-to-stay-safe"> ClickFix </a>attack but pastes the command into Windows File Explorer, which many users are more comfortable using. File Explorer can also execute operating system commands which means it has a functional upload feature; the ‘trick’ portion of the attack is that it no longer requires an error or an issue as a lure and may simply appear as a notification for a shared file that the user needs to locate through File Explorer. </p><p>FileFix is a <a href="https://www.tomsguide.com/news/avoid-these-email-attachments-if-you-dont-want-to-get-phished">phishing page</a> that includes an ‘Open Fixe Explorer’ button that will launch File Explorer through the file upload functionality and copy the PowerShell command to the clipboard. The fake path is initially seen in the Fixe Explorer address bar, which hides the malicious command and then executes it. </p><h2 id="how-to-stay-safe-from-clickfix-attacks-2">How to stay safe from ClickFix attacks</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ggfqETDAhhJhzfhkdsPiV3" name="computer security.jpg" alt="A person typing on a computer, lit up by the screen" src="https://cdn.mos.cms.futurecdn.net/ggfqETDAhhJhzfhkdsPiV3.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p>The ClickFix tactic that’s currently being used in more and more in attacks is working due to the fact that it’s able to bypass the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> and many other security tools. The reason for this is that victims end up doing most of the heavy lifting themselves as the hackers behind this and similar campaigns use social engineering to coerce them into taking action.</p><p>The hackers behind this and similar campaigns use your preexisting knowledge and online habits to get you to do something you otherwise normally wouldn't. They might also use a <a href="https://www.tomsguide.com/news/unpaid-invoices-are-one-of-the-easiest-ways-scammers-try-and-trick-you-what-to-look-out-for">sense of urgency</a> to get you to visit one of the <a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-over-free-online-file-converters-that-infect-your-pc-with-malware">malicious sites</a> used in this campaign.</p><p>If you do see a verification pop-up with instructions, close the website immediately and whatever you do, don’t interact with it or follow its instructions. </p><p>Being asked to open a Terminal or Command Prompt window on your computer is a <a href="https://www.tomsguide.com/news/this-is-the-one-thing-to-look-out-for-in-scam-emails">major red flag</a>. However, not everyone is as tech savvy which is why you should share what you’ve learned with both older and younger family members, friends and colleagues to help keep them safe, too.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/sparkkitty-spyware-caught-stealing-photos-on-iphone-and-android-and-the-reason-might-surprise-you">SparkKitty spyware caught stealing photos on iPhone and Android — and the reason might surprise you</a></li><li><a href="https://www.tomsguide.com/computing/online-security/7-online-scams-that-can-leave-you-broke-exposed-and-feeling-helpless">7 online scams that can leave you broke, exposed, and feeling helpless — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/over-700k-people-hit-in-major-healthcare-data-breach-full-names-ssns-medical-info-and-more-exposed">Over 700K people hit in major healthcare data breach — full names, SSNs, medical info and more exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This spyware is stealing photos on iPhone and Android — protect yourself now  ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/sparkkitty-spyware-caught-stealing-photos-on-iphone-and-android-and-the-reason-might-surprise-you</link>
                                                                            <description>
                            <![CDATA[ Both iPhones and Android phones are being targeted by the SparkKitty malware which steals photos to find screenshots of crypto recovery phrases. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Ttva6TBotynXTGJJReHFRA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 24 Jun 2025 06:45:00 +0000</pubDate>                                                                                                                                <updated>Tue, 24 Jun 2025 18:07:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Whether you use an iPhone or an Android phone, chances are, there’s plenty of sensitive personal and financial information on your smartphone. While hackers have been known to go after your passwords, there’s a new <a href="https://www.tomsguide.com/news/rilide-malware-is-stealing-2fa-codes-and-passwords-what-you-need-to-know">malware strain</a> making the rounds online that also has your photo library in its sights.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/malware-on-google-play-app-store-stole-your-photos-and-crypto/" target="_blank" rel="nofollow">BleepingComputer</a>, both the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html">best iPhones</a> and the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> are currently being targeted in a new campaign that uses SparkKitty to steal all of the images of an infected device. </p><p>According to the cybersecurity firm Kaspersky, this campaign has been active since February of last year. However, what sets it apart is the fact that the malware in question found its way onto both <a href="https://www.tomsguide.com/computing/malware-adware/malicious-iphone-apps-are-spreading-screenshot-reading-malware-on-the-apple-app-store-how-to-stay-safe">Apple’s App Store</a> and the <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-google-play-store-pages-to-infect-android-phones-with-a-dangerous-trojan-how-to-stay-safe">Google Play Store</a>.</p><p>If you thought the hackers behind this campaign were after your selfies, think again. Instead, they’re looking for screenshots of <a href="https://www.tomsguide.com/computing/password-managers/millions-stolen-from-lastpass-users-in-massive-hack-attack-what-you-need-to-know">crypto wallet seed phrases</a>. For those unfamiliar, these very important phrases are the only way you can regain access to a crypto wallet if you forget your password. With them in hand though, hackers can easily drain all of your digital currency and good luck trying to get it back.</p><p>Here’s everything you need to know about this new campaign along with some tips and tricks on how you can avoid having your Android phone or even your iPhone come down with a nasty malware infection.</p><h2 id="infiltrating-official-and-unofficial-app-stores">Infiltrating official and unofficial app stores</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="24t83YtrpM3vuay3GLHNj9" name="app store shutterstock.jpg" alt="finger about to touch Apple App Store icon on iPhone" src="https://cdn.mos.cms.futurecdn.net/24t83YtrpM3vuay3GLHNj9.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Just like with many other malware campaigns, this one uses malicious apps to establish a foothold on targeted devices before infecting them with SparkKitty.</p><p>In its <a href="https://securelist.com/sparkkitty-ios-android-malware/116793/" target="_blank" rel="nofollow">report</a> on the matter, Kaspersky explains that the hackers behind this campaign used the SOEX messaging app which also has cryptocurrency exchange features to target Android users directly on the Google Play Store. Meanwhile, on iPhone, they used the 币coin app on Apple’s App Store to achieve the same thing.</p><p>While Google has already removed the SOEX app from the Play Store, at the time of writing, the 币coin app is still up on the App Store and has yet to be removed by Apple. Either way, if you downloaded either of these apps, you should manually delete them right now.</p><p>At the same time, Kaspersky also found modded TikTok clones with fake online cryptocurrency stores as well as gambling apps, adult-themed games and casino apps distributing the SparkKitty malware. However, instead of being available on an official app store, these apps had to be <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps">sideloaded</a>.  </p><p>SparkKitty is embedded as fake frameworks or delivered via enterprise provisioning profiles on iOS whereas on Android, the malware is embedded in both Java and Kotlin apps. On an iPhone, the malware is automatically executed when an app starts but on Android, it’s triggered when an app launches or when a specific action like opening a certain screen type takes place.</p><p>To gain access to a victim’s photo library, SparkKitty requests access to an iPhone’s photo gallery but on Android, the malicious app used to install the malware prompts the user to grant storage permissions so that it can access any images stored on their device. Either way, once installed, the malware begins exfiltrating both existing pictures and any new ones taken on an infected phone.</p><p>From there, the malware goes through all of these stolen images, specifically looking for screenshots of crypto wallet seed phrases. When you sign up for a new crypto wallet or exchange, you’re given a seed phrase and told to write it down to store it for safekeeping. </p><p>Although taking a screenshot seems like a fast and practical way to do this, this campaign and others like it show just how dangerous doing this can be. This is why old-fashioned paper and pen is the best way to store your seed phrases. However, you should also store them under lock and key to protect them further.</p><h2 id="how-to-stay-safe-from-malicious-apps-spreading-malware">How to stay safe from malicious apps spreading malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Although you can end up with a malware infection from clicking on <a href="https://www.tomsguide.com/computing/malware-adware/this-android-malware-can-steal-all-your-photos-and-texts-without-being-opened-how-to-stay-safe">malicious links</a>, downloading <a href="https://www.tomsguide.com/news/avoid-these-email-attachments-if-you-dont-want-to-get-phished">email attachments from unknown senders</a> and through <a href="https://www.tomsguide.com/news/heres-another-big-reason-to-avoid-pirating-content-online">piracy</a>, one of the most common ways is via malicious apps either on official or unofficial app stores. </p><p>For this reason, you need to be extremely careful when putting any new app on your iPhone or Android phone. You want to make sure that you read an app’s reviews and check its rating but since these can be faked, you also want to look for external reviews on other sites. If you can find one, video reviews are an even better option since you get to see an app in action before installing it.</p><p>It’s also worth noting that even <a href="https://www.tomsguide.com/news/popular-android-screen-recorder-app-went-from-legitimate-to-malicious-overnight-what-you-need-to-know">good apps can go bad</a> when injected with malicious code which is why I always recommend limiting the number of apps you have installed on your devices. With fewer apps installed, there’s less of a risk that you downloaded a malicious one or that a legitimate app has been hijacked by hackers. </p><p>Before downloading any new app, you first want to ask yourself if you really need it. It’s likely one of your existing apps or even your phone’s operating system is able to accomplish the same thing. </p><div><blockquote><p>I always recommend limiting the number of apps you have installed on your devices. With fewer apps installed, there’s less of a risk that you downloaded a malicious one.</p></blockquote></div><p>Additionally, you also want to stick to trusted and well-known apps when possible and for most people, you should never sideload any app onto your phone. The reason being is that the apps on Apple’s App Store and the Google Play Store go through rigorous security checks that both sideloaded apps and those from unofficial app stores don’t.</p><p>Bad apps do manage to slip through the cracks from time to time. However, if you aren’t carelessly downloading new ones, you’ll be far less likely to accidentally install a malicious app. </p><p>As for staying safe from mobile malware, if you have an Android phone, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> is enabled on your devices. This free and built-in security app scans all of your existing apps and any new ones you download for malware or other malicious activity to keep you safe. For extra protection though, you might also want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it.</p><p>While there’s no equivalent to these Android antivirus apps due to Apple’s own malware scanning restrictions, the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> from Intego is able to scan both your iPhone or iPad for malware but they have to be plugged into a Mac via USB cable to do so.</p><p>Malicious apps aren’t going anywhere anytime soon given how successful they’ve been for hackers in malware campaigns like the one described above. However, if you think before you tap and limit the number of apps on your phone overall, your chances of ending up with a malware infection after downloading a malicious app will be a lot lower. </p><p>Likewise, you also want to make sure that you talk to both your younger and older family members and friends about the risks posed by malicious apps in order to keep everyone you know safe from hackers.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/if-youre-a-gmail-user-its-time-to-implement-these-critical-security-steps">Security warning for over 1.8 billion Gmail users — implement these critical security steps now</a></li><li><a href="https://www.tomsguide.com/computing/online-security/7-online-scams-that-can-leave-you-broke-exposed-and-feeling-helpless">7 online scams that can leave you broke, exposed, and feeling helpless — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/over-700k-people-hit-in-major-healthcare-data-breach-full-names-ssns-medical-info-and-more-exposed">Over 700K people hit in major healthcare data breach — full names, SSNs, medical info and more exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Godfather malware is now hijacking legitimate banking apps — and you won’t see it coming ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/godfather-malware-is-now-hijacking-legitimate-banking-apps-and-you-wont-see-it-coming</link>
                                                                            <description>
                            <![CDATA[ The Godfather malware has been upgraded with a new ability that allows it to conduct real-time fraud using virtual versions of financial apps. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uL9WCMerdQ9PBMTPAS3DoT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Jun 2025 19:28:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A notorious <a href="https://www.tomsguide.com/computing/malware-adware/this-nasty-android-banking-trojan-lets-hackers-completely-hijack-your-phone-how-to-stay-safe">banking malware</a> that targets the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> has returned with new capabilities that make it even easier for hackers to siphon off your hard-earned cash.</p><p>As reported by <a href="https://www.infosecurity-magazine.com/news/godfather-upgraded-hijack-mobile/" target="_blank">Infosecurity Magazine</a>, an updated version of the <a href="https://www.tomsguide.com/news/godfather-malware-is-draining-banking-and-crypto-accounts-what-you-need-to-know">Godfather malware</a> has been spotted online by the mobile security firm <a href="https://www.tomsguide.com/news/hackers-can-use-this-chrome-extension-to-hijack-your-pc-how-to-stay-safe">Zimperium</a>. </p><p>Back when I first reported on this malware several years ago, it was being used by hackers to target popular banking and finance apps in countries around the world. At that time, Godfather primarily used <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts">overlay attacks</a> to trick unsuspecting users into entering their usernames and passwords. These credentials were then used to log into their financial accounts to steal both cash and cryptocurrency.</p><p>Now though, the Godfather malware is back with a major upgrade that allows it to create virtualized versions of legitimate apps to commit fraud in real-time. </p><p>Here’s everything you need to know about this new malware threat along with some tips and tricks on how you can keep your devices and financial accounts safe from hackers.</p><h2 id="from-overlays-to-virtualized-apps">From overlays to virtualized apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.20%;"><img id="hQZK4TmEJdev8aHEsJa3KN" name="mobile banking.jpg" alt="Person using mobile app for banking" src="https://cdn.mos.cms.futurecdn.net/hQZK4TmEJdev8aHEsJa3KN.jpg" mos="" align="middle" fullscreen="" width="2000" height="1124" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Overlay attacks can definitely be convincing and many Android users have fallen for them in the past. However, as they require copying a banking or crypto app’s user interface and branding perfectly, this can be a lot of extra work.</p><p>To appear more convincing while making things easier for hackers, Godfather now launches virtual instances of targeted apps from within a sandboxed environment on vulnerable Android smartphones. That way, instead of having to rely on potential victims enabling the necessary permissions, the malware can now essentially clone financial apps to more easily steal credentials from potential victims.</p><p>The implication here is also huge since due to this new attack method, you can’t even trust the legitimate apps you have installed on your phone. Likewise, doing things this way allows the Godfather malware to evade detection.</p><p>Before creating virtual versions of banking and financial apps, the malware first scans an infected device to see which apps a victim actually has on their smartphone. From there, it compares a user’s installed apps against a list of targeted apps. If one of the targeted apps is found, Godfather creates a virtualized version of it that launches when a user tries to run the legitimate app.</p><p>Depending on which banking or financial app is being targeted, the malware has several different methods for stealing a user’s credentials. At the same time, it’s also able to steal the PIN or unlock pattern for an Android smartphone. Unsurprisingly, Godfather does this by using a fake overlay that’s designed to mimic a user’s actual lock screen.</p><p>To make matters worse, this malware is also able to remotely control an infected device using a number of different commands. This lets the hackers behind this campaign commit real-time fraud on an infected device oftentimes without a victim’s knowledge. For instance, with a phone’s PIN or unlock pattern, they could unlock the device when it’s in a victim’s pocket or charging overnight and steal their passwords and cash without anything seeming amiss.</p><h2 id="how-to-stay-safe-from-android-malware-6">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Fortunately (at least for now), this upgraded version of the Godfather malware has only been used in attacks targeting Turkish Android users according to <a href="https://zimperium.com/blog/your-mobile-app-their-playground-the-dark-side-of-the-virtualization">Zimperium’s report</a> on the matter. However, this could easily change and the hackers behind this campaign could branch out to target users in other countries like the U.S., the U.K. or Canada.</p><p>As such, you’re going to want to take steps now to protect your Android smartphone and any banking or financial data it contains. The easiest way to stop Godfather and other Android malware strains in their tracks is to turn off an Android smartphone’s ability to <a href="https://www.tomsguide.com/news/look-out-this-android-malware-can-take-over-your-banking-and-crypto-accounts">install apps from unknown sources</a>. This feature is disabled by default but if you’ve turned it on, you’re going to want to turn it off right now.</p><p>Many malware strains use <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now">malicious apps</a> as a means to gain entry to a vulnerable Android smartphone and Godfather is no different. You also want to be wary about files sent to you via email or on social media as they could also contain malware. </p><p>For this reason, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> is enabled on your smartphone as this pre-installed security app can scan all of your existing apps and any new ones you download for malware. If you want extra protection though, you can always run one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it.</p><p>Another useful step you can take to stay safe is to limit the number of apps installed on your phone overall. Since even good apps can go bad, having too many apps on your phone puts you at greater risk. Besides deleting unused apps, you also want to ask yourself whether or not you really need a new app before installing it.</p><p>Banking malware is dangerous enough on its own but now that Godfather can create virtualized copies of legitimate Android banking and financial apps, we could soon see other malware strains implementing this capability too. Thankfully, Google always tries to stay one step ahead of hackers and often updates Android to prevent these kinds of attacks from being possible in the first place. This is why you should always <a href="https://www.tomsguide.com/computing/online-security/google-just-fixed-two-critical-android-zero-days-and-60-other-flaws-update-your-phone-right-now">update your Android smartphone</a> as soon as new software becomes available. And if you’re phone isn’t receiving updates anymore, then it’s certainly time for an upgrade.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/if-youre-a-gmail-user-its-time-to-implement-these-critical-security-steps">If you’re a Gmail user it’s time to implement these critical security steps</a></li><li><a href="https://www.tomsguide.com/computing/online-security/new-qr-code-threat-can-infect-your-phone-as-soon-as-you-scan">New QR code threat can infect your phone as soon as you scan</a></li><li><a href="https://www.tomsguide.com/computing/online-security/i-was-hacked-12-years-ago-and-the-attackers-are-still-trying-to-get-in-heres-how-i-stopped-them">Hackers are still trying to break into my accounts 12 years later — here's how I managed to stop them</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Major Windows Secure Boot flaw can be used by hackers to install bootkit malware — update your PC right now ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/major-windows-secure-boot-flaw-can-be-used-by-hackers-to-install-bootkit-malware-update-your-pc-right-now</link>
                                                                            <description>
                            <![CDATA[ A new Secure Boot bypass flaw can be exploited to disable your PC’s security and install bootkit malware that runs every time you turn on your computer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TmKge5Zs4MetUrcCKAU8xK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Jun 2025 22:24:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker typing quickly on a keyboard]]></media:description>                                                            <media:text><![CDATA[A hacker typing quickly on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker typing quickly on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sometimes the features designed to keep our computers safe can put us most at risk thanks to a worrying security flaw that can be exploited by hackers in their attacks.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/new-secure-boot-flaw-lets-attackers-install-bootkit-malware-patch-now/" target="_blank">BleepingComputer</a>, a new Secure Boot bypass (tracked as <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-3052" target="_blank">CVE-2025-3052</a>) was recently discovered that can be used to disable Windows 11’s built-in security measures to install bootkit malware.</p><p>Unlike your typical <a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-new-windows-malware-hides-from-your-antivirus-while-impersonating-a-popular-pc-brand">Windows malware</a>, <a href="https://www.tomsguide.com/news/dangerous-blacklotus-bootkit-can-be-used-to-hack-even-fully-updated-windows-11-pcs">bootkit malware</a> targets your computer’s boot process which allows an attacker to gain full control over your operating system before it even loads. To make matters worse, this type of malware is also persistent and can remain on your PC even after you <a href="https://www.tomsguide.com/computing/online-security/new-indie-game-found-spreading-malware-on-steam-how-to-see-if-your-pc-is-infected-and-what-to-do-next">reinstall Windows</a>.</p><p>Here’s everything you need to know about this new Secure Boot flaw and why it’s imperative that you update your Windows PC right now to stay safe from any attacks exploiting it.</p><h2 id="bypassing-secure-boot">Bypassing Secure Boot</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1583px;"><p class="vanilla-image-block" style="padding-top:56.85%;"><img id="43feUogzceEtWd5Y4KTf7e" name="windows key.jpg" alt="How to disable the Windows key" src="https://cdn.mos.cms.futurecdn.net/43feUogzceEtWd5Y4KTf7e.jpg" mos="" align="middle" fullscreen="" width="1583" height="900" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>According to a new <a href="https://www.binarly.io/blog/another-crack-in-the-chain-of-trust" target="_blank">blog post</a>, this flaw was discovered by Binarly security researcher Alex Matrosov after he found a BIOS-flashing utility online. Signed with Microsoft’s UEFI signing certificate, the utility in question was originally designed for rugged tablets. However, it can run on any of the <a href="https://www.tomsguide.com/best-picks/the-best-windows-laptops">best Windows laptops</a> or desktops with Secure Boot enabled. </p><p>First introduced back in 2012 with the release of Windows 8, Secure Boot was created to protect against bootkit malware by ensuring that only trusted software could load during a PC’s startup sequence. Ironically, thanks to this flaw, Secure Boot-enabled PCs are now vulnerable to the very thing this security feature was designed to protect against.</p><p>Following an investigation, it was discovered that the vulnerable module in the utility found by Mastrosov had been available online since at least the end of 2022, though it wasn’t until last year that it was uploaded to the malware detection service <a href="https://www.tomsguide.com/news/these-popular-apps-are-being-mimicked-to-spread-malware-heres-how-to-protect-yourself">VirusTotal</a>.</p><p>To show how serious this flaw was, he and the team at Binarly created a proof of concept (PoC) exploit that set the LoadImage function used to enforce Secure Boot to zero which effectively disabled it. With this feature disabled, an attacker can install bootkit malware that can hide from both Windows and any security software installed on a system.</p><p>Back in February of this year, Mastrosov disclosed the flaw to Microsoft and a fix for it was created. However, while it worked to address the flaw, the software giant determined that it impacted 13 other modules which then had to be fixed as well.</p><h2 id="how-to-keep-your-windows-pc-safe">How to keep your Windows PC safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:5342px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MC3iNmQLKLcYS2fWGgAouZ" name="shutterstock_631810814" alt="A man clicking on a mouse while browsing the web on his laptop" src="https://cdn.mos.cms.futurecdn.net/MC3iNmQLKLcYS2fWGgAouZ.jpg" mos="" align="middle" fullscreen="" width="5342" height="3005" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>So how do you protect yourself from malware that starts before Windows even loads and can easily bypass the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a>? Well, by updating your PC with the latest security updates from Microsoft.</p><p>In June’s <a href="https://www.tomsguide.com/computing/operating-systems/microsoft-patches-over-160-security-flaws-including-3-active-zero-days-update-your-pc-right-now">Patch Tuesday</a> updates, Microsoft has included a fix for this major security flaw along with patches for other recently discovered vulnerabilities. However, the company has also added 14 new hashes to its Secure Boot dbx revocation list. Fortunately for you, this updated dbx file is contained within Microsoft’s latest round of Patch Tuesday updates.</p><p>While installing the latest Windows updates may seem tedious at times, I highly recommend that you stop and take the time to do so as Microsoft often includes fixes for a variety of different security flaws while also adding new features to its operating system. </p><p>Given that Patch Tuesday takes place on the second Tuesday of every month, at least you know ahead of time when these very important updates will arrive. This way, you can set aside the time needed to install them or better yet, set your PC to install them automatically.</p><p>When dealing with security flaws that can bypass your antivirus software, the <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html">best identity theft protection services</a> can help you recover your identity as well as any funds lost to malware or other scams as a result of them. Keep in mind though that for identity theft insurance to pay out, you need to be signed up for one of these services before an attack takes place.</p><p>Although this Secure Boot bypass is worrying, it’s worth noting that it wasn’t exploited by hackers in the wild. Instead, security researchers created an exploit for it in order to show how dangerous this flaw could be if knowledge of it ended up in the wrong hands. Either way, it’s a great reminder as to why it’s so important to keep your PC (and all of the computers in your household for that matter) up to date.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/delete-these-20-apps-right-now-if-you-downloaded-them-from-the-play-store-theyre-malicious">Delete these 20 apps right now if you downloaded them from the Play Store — they’re malicious</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-from-new-malware-campaign-impersonating-major-isp-how-to-stay-safe">Macs under threat from new malware campaign impersonating major ISP</a></li><li><a href="https://www.tomsguide.com/computing/online-security/these-great-deals-on-facebook-are-not-from-amazon-rolex-or-nordstrom-theyre-from-a-network-of-scammers">These “great” deals on Facebook are not from Amazon, Rolex or Nordstrom – they’re from a network of scammers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Macs under threat from new malware campaign impersonating major ISP — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/macs-under-threat-from-new-malware-campaign-impersonating-major-isp-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ New malware campaign uses ClickFix social engineering to infect vulnerable Macs with the AtomicStealer malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8CARDWy6mtCcG9YZ8PohTB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/76BX7qw85vqQucCvUnTHHQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 10 Jun 2025 01:05:46 +0000</pubDate>                                                                                                                                <updated>Tue, 10 Jun 2025 06:09:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/76BX7qw85vqQucCvUnTHHQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[MacBook Pro 2021 (16-inch) on a patio table]]></media:description>                                                            <media:text><![CDATA[MacBook Pro 2021 (16-inch) on a patio table]]></media:text>
                                <media:title type="plain"><![CDATA[MacBook Pro 2021 (16-inch) on a patio table]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/76BX7qw85vqQucCvUnTHHQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Even though people often think Macs are safe from malware, that definitely isn’t true. Case in point, a new <a href="https://www.tomsguide.com/computing/malware-adware/macs-under-threat-from-info-stealing-malware-dont-fall-for-this-microsoft-teams-scam">Atomic Stealer</a> campaign, which is being used to infect the <a href="https://www.tomsguide.com/best-picks/best-macbook">best MacBooks</a> and other Apple computers with info-stealing malware, has been spotted online.</p><p>As reported by <a href="https://thehackernews.com/2025/06/new-atomic-macos-stealer-campaign.html?m=1">The Hacker News</a>, the campaign was discovered by the cybersecurity firm <a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-hackers-are-using-fake-pdf-converters-to-spread-malware-and-steal-your-passwords">CloudSEK,</a> and it’s believed to be the work of Russian hackers due to comments in the malware’s source code.</p><p>What makes this campaign particularly interesting is the fact that, in addition to typosquatting, it also uses <a href="https://www.tomsguide.com/computing/online-security/what-is-social-engineering">social engineering</a> to trick unsuspecting Mac users into falling for it. For those unfamiliar, <a href="https://www.tomsguide.com/news/these-misspelled-websites-are-spreading-nasty-malware-how-to-stay-safe">typosquatting</a> is a type of attack where cybercriminals register lookalike domains in order to lay traps for potential victims who mistype a popular site’s URL into their browser’s address bar. While they might think they’re on a popular company’s website, instead, they’re actually on a <a href="https://www.tomsguide.com/computing/online-security/hackers-have-created-hundreds-of-fake-reddit-sites-to-spread-info-stealing-malware">fake site</a> designed to mimic the real one, which is also used to spread dangerous malware.</p><p>Once infected with Atomic Stealer, the malware can steal personal and sensitive data from your Mac like passwords stored in your <a href="https://www.tomsguide.com/news/new-macstealer-malware-steals-icloud-keychain-data-and-passwords-how-to-stay-safe">Apple Keychain</a>, browser cookies, login credentials, credit card details, and more. </p><p>Here’s everything you need to know about this new malware campaign, along with some tips and tricks to prevent you from falling victim to it and other cyberattacks.</p><h2 id="not-the-spectrum-you-were-looking-for">Not the Spectrum you were looking for</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1700px;"><p class="vanilla-image-block" style="padding-top:56.24%;"><img id="H85KrzxvjfuCs4YYbCxFNA" name="fake-spectrum-site-cloudsek" alt="A screenshot of a fake site impersonating the internet and cable provider Spectrum" src="https://cdn.mos.cms.futurecdn.net/H85KrzxvjfuCs4YYbCxFNA.jpg" mos="" align="middle" fullscreen="" width="1700" height="956" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: CloudSEK/Tom's Guide)</span></figcaption></figure><p>According to CloudSek, the hackers behind this new campaign are impersonating the U.S. internet and cable provider Spectrum using several fake websites. While Spectrum’s official website can be found at spectrum[.]com, the firm's <a href="https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers" target="_blank">blog post</a> highlights one of these fake sites, which uses the URL panel-spectrum[.]net. </p><p>Once on this fake site, potential victims are asked to complete a <a href="https://www.tomsguide.com/computing/online-security/hackers-are-using-recaptcha-to-trick-users-into-infecting-their-own-pcs-with-malware-how-to-stay-safe">reCAPTCHA</a> to verify that they aren’t bots. Since many sites use this or similar forms of verification, many people might not even think twice when asked to check a box to prove they’re human. However, on the fake site shared by CloudSek, once verification fails, potential victims are then asked to complete an alternative verification instead.</p><p>However, when someone clicks on the button that reads “Alternative Verification”, a command is copied to their clipboard without their knowledge. A set of instructions appears that asks them to open a command prompt, paste the code that was copied to their clipboard, and hit “Enter” to run it on Windows. If someone is using a Mac, though, slightly different instructions are shown that lead to the same outcome: they’re computer is being infected with info-stealing malware.</p><p>On Macs, a <a href="https://www.tomsguide.com/computing/online-security/macs-under-threat-from-thousands-of-hacked-sites-spreading-malware-how-to-stay-safe">malicious shell script</a> is used to steal system passwords and download a variant of the Atomic Stealer malware. As CloudSek security researcher Koushik Pal points out in the company’s report, the script “uses native macOS commands to harvest credentials, bypass security mechanisms, and execute malicious binaries.”</p><h2 id="how-to-stay-safe-from-mac-malware-3">How to stay safe from Mac malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="DgqWmPAUgj3TpRQWmkkka7" name="apple shutterstock.jpg" alt="A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop." src="https://cdn.mos.cms.futurecdn.net/DgqWmPAUgj3TpRQWmkkka7.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: robert coolen/Shutterstock)</span></figcaption></figure><p>Given that hackers use all kinds of different tricks to lead potential victims to fake sites spreading malware, it’s always best to type a company’s website into your browser’s address bar manually. However, you should also double-check that you spelled it correctly.</p><p>If you don’t know a company’s official site, you can use a search engine to find it. One thing, though, that you want to be careful about is that you’re not clicking the first link that you see. The reason is that on Google and other search engines, the links at the top are often ads, while finding a company’s actual website often requires that you scroll a bit further down the page. The problem with clicking on an ad or a sponsored search result is that cybercriminals often use <a href="https://www.tomsguide.com/computing/malware-adware/dont-click-this-malicious-ads-impersonating-google-chrome-spreading-dangerous-malware">malicious ads</a> to take users to fake sites instead of to a company’s actual site, as anyone (even hackers) can buy ad space online.</p><p>From here, it’s a matter of knowing how to identify a ClickFix attack. Many sites ask that you complete a reCAPTCHA or other form of verification before entering. However, if a site asks you to open a command window and paste something from your clipboard there before hitting “enter”, this is a major red flag. A legitimate company might ask you to select all of the images that are cars, but they would never copy code to your clipboard without your knowledge and then ask you to paste and run it somewhere else.</p><p>Although your Mac does come with built-in security software in the form of Apple’s own <a href="https://www.tomsguide.com/news/macos-is-getting-even-better-at-scanning-for-malware-heres-how">XProtect</a>, it’s still a good idea to consider investing in one of the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> solutions. Unlike <a href="https://www.tomsguide.com/computing/antivirus/do-you-really-need-to-pay-for-antivirus-software">free antivirus software</a>, these paid options are updated more frequently and are more likely to spot and help you avoid newer malware strains like Atomic Stealer.</p><p>Given that attacks using this ClickFix technique have proven both successful and profitable for hackers and other cybercriminals, they’re not going anywhere anytime soon. This is why it makes sense to educate yourself and your family members about these sorts of threats so that you can spot any red flags before your Mac or PC becomes infected with malware.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/millions-of-mac-owners-urged-to-be-on-alert-for-info-stealing-malware">Millions of Mac owners urged to be on alert for info-stealing malware</a></li><li><a href="https://www.tomsguide.com/computing/antivirus/does-your-mac-need-antivirus-software">Does your Mac need antivirus software?</a></li><li><a href="https://www.tomsguide.com/computing/online-security/macs-under-attack-from-dangerous-malware-targeting-digital-wallets-and-apples-notes-apps-how-to-stay-safe">Macs under attack from malware targeting digital wallets and Apple’s Notes app</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new Android malware adds fake contacts to your phone while draining bank accounts — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-new-android-malware-is-adding-fake-contacts-to-your-phone-while-draining-bank-accounts</link>
                                                                            <description>
                            <![CDATA[ The Crocodilus Android malware now allows hackers to add fake contacts to your phone to make social engineering even easier. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qZA3NjXbk6Sx2pjKzYcExX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 03 Jun 2025 18:22:31 +0000</pubDate>                                                                                                                                <updated>Wed, 04 Jun 2025 01:12:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new <a href="https://www.tomsguide.com/computing/malware-adware/new-android-malware-drains-your-bank-accounts-and-completely-wipes-your-device-how-to-stay-safe">Android malware strain</a> is making the rounds online that makes it incredibly difficult to distinguish who’s actually calling you as it was recently updated with the ability to add fake contacts to your phone.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/android-malware-crocodilus-adds-fake-contacts-to-spoof-trusted-callers/" target="_blank">BleepingComputer</a>, the malware in question is called Crocodilus, and it was first discovered back in March of this year by Threat Fabric. While it was initially used to target crypto users in Turkey to drain their wallets, the malware is now being distributed on a global scale and is currently being used to target the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> in the U.S., Spain, Argentina, Brazil, Indonesia and India.</p><p>In a <a href="https://fieldeffect.com/blog/new-crocodilus-malware-snaps-up-crypto-wallets">blog post</a>, the cybersecurity firm Field Effect explains that Crocodilus is distributed using a <a href="https://www.tomsguide.com/computing/malware-adware/this-nasty-android-banking-trojan-lets-hackers-completely-hijack-your-phone-how-to-stay-safe">custom dropper</a> so that it can bypass Android’s built-in security measures. For instance, it doesn’t need access to Android’s Accessibility Services or other user permissions to end up on a vulnerable smartphone. Likewise, it’s also able to bypass the built-in defenses of <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a>.</p><p>Crocodilus’ latest new ability is particularly worrying since hackers can easily use it in <a href="https://www.tomsguide.com/computing/online-security/what-is-social-engineering">social engineering attacks</a>. For instance, you might see a call come through from your bank after visiting a <a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-over-free-online-file-converters-that-infect-your-pc-with-malware">malicious website</a> on your phone. However, since Crocodilus can now be used to add fake contacts to your phone, it could actually be hackers trying to scam you out of your hard-earned cash on the other end of the line.</p><p>Here’s everything you need to know about this new threat, including some tips and tricks to help you stay safe from hackers trying to infect your smartphone with malware.</p><h2 id="even-your-contacts-can-t-be-trusted">Even your contacts can’t be trusted</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jooLQTGPeDLH8jBwTuAjXe" name="stressed-woman-phone-shutterstock.jpg" alt="A nervous woman looking at her phone" src="https://cdn.mos.cms.futurecdn.net/jooLQTGPeDLH8jBwTuAjXe.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Though still quite new, Crocodilus is already a full-featured Android malware with loads of malicious capabilities. For example, it can remotely take over your smartphone, steal data from it and use <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts">overlay attacks</a> to mimic popular financial and banking apps to steal your credentials.</p><p>Now, in the latest version of this malware, the ability to add fake contacts to a victim’s phone has been added to Crocodilus. Once this is done, the device will display the name listed in a caller’s contact profile as opposed to their caller ID when an incoming call is received.</p><p>With this new capability, hackers using the Crocodilus malware in their attacks can easily impersonate banks, trusted companies and even your friends and family members. Given that more people text than call these days, potential victims could easily fall for a text from a friend or family member asking them to send money in an emergency and have no idea that they did so.</p><p>It’s also worth noting that these fake contacts aren’t tied to your Google account. Instead, they remain on an infected phone and won’t sync with your other devices once you log in to them.</p><p>At this time, it’s currently unknown how Android users are being tricked into infecting their phones with the Crocodilus malware. However, Field Effect’s researches suggest that the malware is likely being distributed via malicious sites, <a href="https://www.tomsguide.com/computing/malware-adware/12-million-people-fooled-by-fake-midjourney-facebook-page-used-to-spread-malware-dont-fall-for-this">fake promotions</a> sent through social media or via text and on third-party app stores.</p><h2 id="how-to-stay-safe-from-android-malware-7">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>You can never be too careful on your phone and this is especially true with new malware strains like Crocodilus. From clicking a bad link to downloading a <a href="https://www.tomsguide.com/news/200-malicious-android-and-ios-apps-caught-draining-bank-accounts-check-your-phone-now">malicious app</a>, there are plenty of ways in which your devices can become infected with a virus.</p><p>For this reason, I always recommend limiting the number of apps on your phone. This is because <a href="https://www.tomsguide.com/news/popular-android-screen-recorder-app-went-from-legitimate-to-malicious-overnight-what-you-need-to-know">even good apps can go bad</a> when injected with malicious code and it’s always easier to ensure that the apps you do have installed are up to date when there are few of them overall.</p><p>At the same time, you want to stick to downloading new apps from the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a> or other first-party Android app stores like the Samsung Galaxy Store or the Amazon App Store. The reason being is that the apps on unofficial, third-party app stores don’t go through the same rigorous security checks that they would on other platforms.</p><p>To stay safe from Android malware, first and foremost, you want to make sure that Google Play Protect is enabled on your smartphone. This free security tool scans all of the new apps you download as well as any existing apps on your phone for malware and other threats. However, as hackers will often find ways to bypass Android’s built-in security tools like we’ve seen here, you may also want to consider downloading and installing one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> for extra protection.</p><p>If you want to be extra safe, though, the <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html">best identity theft protection services</a> can help you regain your identity and any funds lost to fraud after a major malware attack.</p><p>Given that the Crocodilus malware has already been updated quite frequently despite it being fairly new, I expect this won’t be the last we hear of this Android malware strain, especially now that hackers are using it in attacks in even more countries. </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/hackers-are-using-fake-booking-com-sites-to-infect-summer-travelers-with-dangerous-malware-how-to-stay-safe">Hackers are using this to spread dangerous malware just in time for summer travel season</a></li><li><a href="https://www.tomsguide.com/computing/antivirus/its-time-to-stop-believing-these-lies-about-antivirus-software">It’s time to stop believing these lies about antivirus software</a></li><li><a href="https://www.tomsguide.com/computing/online-security/more-than-184-million-passwords-exposed-in-massive-data-breach-apple-google-microsoft-and-more">More than 184 million passwords exposed in massive data breach — Apple, Google, Microsoft and more</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AirPlay flaw exposes all Apple devices to hacking over Wi-Fi — what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/airplay-flaw-exposes-all-apple-devices-to-hacking-over-wi-fi-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ An AirPlay flaw made Apple and third-party smart home devices vulnerable to remote hacking over Wi-Fi. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BDmdQToGc8MWndn2zJB24J</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L8aeWcCHYkQiDY85vCh7in-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 29 Apr 2025 17:18:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L8aeWcCHYkQiDY85vCh7in-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Apple AirPlay]]></media:description>                                                            <media:text><![CDATA[Apple AirPlay]]></media:text>
                                <media:title type="plain"><![CDATA[Apple AirPlay]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L8aeWcCHYkQiDY85vCh7in-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Millions of <a href="https://www.tomsguide.com/tvs/apple-just-struck-a-deathblow-to-overpriced-movies-in-hotels-with-airplay-debut">AirPlay</a>-enabled devices were at risk for months as Apple and security researchers at <a href="https://www.oligo.security/blog/airborne" target="_blank">Oligo</a> worked together to develop and roll out patches for a collection of bugs the researchers dubbed “AirBorne.” </p><p>The bugs discovered by the Oligo team would essentially permit any threat actor connected to the same Wi-Fi network as a third-party AirPlay enabled device to run their own code on it. That means anyone  connected to the same Wi-Fi as a smart TV, speaker or set-top box at a party, could potentially use that open AirPlay connection to spread <a href="https://www.tomsguide.com/news/hackers-have-developed-a-clever-new-way-to-add-malware-to-android-apps">malicious code</a> from one device to another. </p><p>Infected devices could then be used for a variety of malicious behavior like <a href="https://www.tomsguide.com/news/this-ransomware-makes-you-sign-up-for-roblox-to-get-your-files-back">ransomware</a>, surveillance, espionage or supply-chain infiltration. Since many of these devices also contain microphones, they could hypothetically also be used as listening devices. </p><p>The good news is that Apple products regularly receive fixes and all of these AirBorne bugs have been patched at this point. The bad news is that smart home devices, also affected by these vulnerabilities as are <a href="https://www.tomsguide.com/phones/iphones/apple-carplay-just-got-3-upgrades-with-ios-18-4-heres-whats-new">CarPlay</a> devices, are very rarely patched so millions of them remain open vectors for this flaw. </p><p>AirPlay, Apple's radio-based protocol for local wireless communication, is popular among users because it is convenient and 'always-on.' It's a security issue for much the same reason  – and because manufacturers are able to incorporate the SDK (software developers kit) without having to notify Apple or receive certification to become an approved device, many devices use the protocol without requiring or getting regular updates on their end. </p><p>So, while the Apple-based devices have patched the bugs, and while Apple tells <a href="https://www.wired.com/story/airborne-airplay-flaws/" target="_blank">Wired</a> that it has developed a patch for the affected third-party devices but it would require users to actually update the devices themselves. Apple also told the news outlet that in order for the AirBorne bugs to deploy correctly on Apple-based devices, the user would have had to change their default AirPlay settings. </p><p>While a motivated hacker on a <a href="https://www.tomsguide.com/computing/malware-adware/urgent-windows-security-flaw-lets-hackers-infect-your-pc-over-wi-fi-update-right-now">public Wi-Fi network</a> who had brought their own smart-home device may be able to create the right set of circumstances, there are few situations wherein a hacker would find themselves in an ideal situation to spread malware or viruses. </p><p>That being said, and we've said this before, it is of critical importance to <a href="https://www.tomsguide.com/computing/malware-adware/this-newly-discovered-ios-flaw-could-completely-brick-your-iphone-with-a-single-line-of-code">keep your devices updated</a> and to make sure that your smart home devices (and all your accounts for that matter) have<a href="https://www.tomsguide.com/computing/online-security/im-a-security-editor-and-these-are-my-top-3-tips-to-improve-your-password-hygiene-on-world-password-day"> strong, unique passwords. </a></p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://futurenet.questionpro.eu/Trustsurvey?custom1=Tomsguide" target="_blank">Help Tom's Guide - your chance to win a $250 Amazon gift card</a></li><li><a href="https://www.tomsguide.com/computing/online-security/new-choicejacking-attack-lets-hackers-steal-data-from-your-phone-using-public-chargers-how-to-stay-safe">New ChoiceJacking attack lets hackers steal data from your phone using public chargers — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/this-newly-discovered-ios-flaw-could-completely-brick-your-iphone-with-a-single-line-of-code">This newly discovered iOS flaw could completely brick your iPhone with a single line of code</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This newly discovered iOS flaw could completely brick your iPhone with a single line of code ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-newly-discovered-ios-flaw-could-completely-brick-your-iphone-with-a-single-line-of-code</link>
                                                                            <description>
                            <![CDATA[ Researchers have discovered a new iOS vulnerability that could be exploited by hackers to remotely access and brick your iPhone. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uiwpJNjnwCUKbLYEVxjmp</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HpQRk3BGaJ7VCsCkAkEUw8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 28 Apr 2025 15:15:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HpQRk3BGaJ7VCsCkAkEUw8-1280-80.jpg">
                                                            <media:credit><![CDATA[Tom&#039;s Guide]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[iPhone 15 Pro Max shown in hand]]></media:description>                                                            <media:text><![CDATA[iPhone 15 Pro Max shown in hand]]></media:text>
                                <media:title type="plain"><![CDATA[iPhone 15 Pro Max shown in hand]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HpQRk3BGaJ7VCsCkAkEUw8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An app developer and security researcher discovered an <a href="https://www.tomsguide.com/computing/online-security/apple-just-fixed-a-major-zero-day-used-in-sophisticated-attacks-update-your-iphone-and-ipad-right-now">iOS vulnerability</a> that could have allowed threat actors to remotely sabotage and brick the <a href="https://www.tomsguide.com/us/best-apple-iphone,review-6348.html">best iPhones</a> using only a single line of code. </p><p>Gilherme Rambo found a proof of concept flaw hidden in the internal messaging system; the vulnerability was related to Darwin notifications. </p><p>A Darwin notification is a low-level interprocess communication mechanism within iOS and doesn’t require any special privileges to send or receive. It also doesn’t verify the sender, and is available as a public API. </p><p>That means that any process or app on iOS could have sent a <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-chrome-word-and-onedrive-errors-to-trick-people-into-installing-malware-how-to-stay-safe">malicious notification</a> or message for basic updates or status changes and remotely bricked the device. Rambo tells <a href="https://cybernews.com/security/single-line-of-code-iphone-exploit-unveiled/" target="_blank">CyberNews</a> that the Darwin notifications interfere with system operations because of the way that certain components on the phone respond to them, which is how they’re able to disrupt normal device functionality. </p><p>Rambo first disclosed the issue to Apple in June of last year, and demonstrated his proof of concept named “EvilNotify” by running an app that could cause an iOS device to display specific icons in a status bar. For example, he could cause a “liquid detection” warning, trigger a Display Port connection status in the Dynamic Island or block system-wide gestures for pulling down Control Center, Notification Center or Lock screens. </p><p>Additionally, the EvilNotify app could also potentially cause other issues such as ignoring a Wi-Fi connection in order to force a device to use a cellular connection, lock a screen and trigger a device to enter the “restore in progress” mode and other commands. </p><p>It is this “restore in progress” mode that Rambo says is most devastating, as there is no way out of it other than by Restarting, which would cause the device to reboot – and it only takes a single line of code in the app to cause this type of crash. Even when the app was not running in the foreground, these notifications worked meaning the device would repeatedly reboot. </p><p>Rambo also crafted a widget extension he dubbed “VeryEvilNotify” that would soft-brick a device requiring a user to erase and restore from backup. He adds that even if the device was restored, he suspects the bug would continue to be triggered again and again, making it effective as a denial of service. </p><p>Apple has acknowledged and awarded Rambo a bug bounty of $17,500. They’ve also issued a fix for the bug in security updates, which Rambo has confirmed by saying that he’s noted that with the release of 18.3 all issues demonstrated in his proof of concept had been addressed. <br><br>If you haven't updated your iPhone to iOS 18.3, you should do so immediately to patch this and other bugs fixed by Apple in its latest release.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://futurenet.questionpro.eu/Trustsurvey?custom1=Tomsguide" target="_blank">Help Tom's Guide - your chance to win a $250 Amazon gift card</a></li><li><a href="https://www.tomsguide.com/computing/antivirus/why-arent-there-antivirus-apps-for-the-iphone">Why aren't there antivirus apps for the iPhone?</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-zoom-to-spread-malware-and-take-over-pcs-heres-how-to-stay-safe">Hackers are using Zoom to spread malware and take over PCs — here’s how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using Zoom to spread malware and take over PCs — here’s how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-using-zoom-to-spread-malware-and-take-over-pcs-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ A hacker group is using Zoom calls to spread malware and take over computers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S97zkzvLMpA2tjihjLontQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2qfZXagbSfzkQGg3pyykPF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Apr 2025 18:39:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2qfZXagbSfzkQGg3pyykPF-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zoom down]]></media:description>                                                            <media:text><![CDATA[Zoom down]]></media:text>
                                <media:title type="plain"><![CDATA[Zoom down]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2qfZXagbSfzkQGg3pyykPF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.securityalliance.org/news/2025-03-elusive-comet">Security Alliance</a> is putting out an alert for high profile users to be aware of a new crime group that is using Zoom to trick users into allowing remote access in order to install malware.</p><p>Once the malware or RAT is installed, the attackers can steal cryptowallet funds, take over accounts or other assets. </p><p>The group, dubbed ELUSIVE COMET but also known to operate as Aureon Capital, Aureon Press and The OnChain Podcast have created a carefully engineered backstory and history of accounts in order to convince their targets into accepting their requests, including active social media accounts that impersonate real people with legitimate credentials and polished websites. </p><p>The group typically approaches victims with media opportunities to get them interested, then sets up a Zoom meeting.</p><p>During the Zoom video call, they keep their screens switched off but will then send a remote control request with their screen name switched to ‘Zoom’ so it appears as though the app itself is requesting control of the system.</p><p>Those who are rushed, distracted or less tech savvy may assume it is a valid request and accept and now the attacker has full control of the victim’s system. </p><p>According to reports, two recent attempts involve attackers approaching CEOs on X, then using a third-party booking system. The attackers created fake accounts including a history of posts and videos, YouTube accounts and have an audience that convinced one of their victims to agree to an interview, during which digital assets from Bitcoin and Etherum wallets were stolen and their Gmail, Twitter (X) and other accounts were taken over. </p><p>The other potential target noticed that some of the branding for the accounts wasn’t consistent and backed out after seeing some of the data gathered on the group on the Security Alliance advisory. However, the group has gone through great lengths to create a sense of legitimacy to convince their targets to agree to Zoom calls. </p><h2 id="how-to-stay-safe-3">How to stay safe</h2><p>Don’t accept Zoom calls from people you don’t know. Or when using Zoom, <a href="https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0065790#mcetoc_1id03huu8jb">disable remote control functionality</a> entirely. </p><p>Another way to keep yourself safe is to avoid using the Zoom app and instead use the browser version when possible, which limits the functionality – including not allowing remote control of the system. Zoom will offer this option when you attempt to join a meeting without opening the app. </p><p>The Security Alliance also recommends users perform due diligence when receiving an offer or request from unknown individuals to ensure they are communicating with legitimate profiles and not an impersonator, and that all video calls take place over trusted platforms – Zoom, Google Meet, Microsoft Teams. </p><p>Always make sure that your <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">antivirus software</a> is current, and if you have additional features for online protection like a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a>, hardened browser, or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a>, make sure that those are set up too  – those extra steps could make a difference in protecting your accounts if there's ever a malware infection or a breach. </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/fbi-issues-warning-over-scammers-impersonating-agents-to-steal-your-money">FBI issues warning over scammers impersonating agents to steal your money</a></li><li><a href="https://www.tomsguide.com/computing/online-security/more-than-21-million-employee-screenshots-leaked-from-workcomposer-workplace-surveillance-app">More than 21 million employee screenshots leaked from WorkComposer workplace surveillance app</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-impersonating-banks-to-infect-your-android-phone-with-credit-card-stealing-malware">Hackers are impersonating banks to infect your Android phone with credit card-stealing malware</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are impersonating banks to infect your Android phone with credit card-stealing malware ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-impersonating-banks-to-infect-your-android-phone-with-credit-card-stealing-malware</link>
                                                                            <description>
                            <![CDATA[ A new Android malware campaign uses phishing and social engineering to trick you into voluntarily giving up your credit card data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HAiLekNZK5NVZ9GMpkVGyX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Apr 2025 20:48:42 +0000</pubDate>                                                                                                                                <updated>Mon, 21 Apr 2025 21:19:01 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers love using malware to go after your credit card details but a new <a href="https://www.tomsguide.com/news/password-stealing-erbium-malware-is-spreading-fast-and-loved-by-cybercriminals">malware-as-a-service</a> platform makes it incredibly easy for them to use these stolen cards in person at stores and even at ATMs.</p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/supercard-x-android-malware-use-stolen-cards-in-nfc-relay-attacks/" target="_blank">BleepingComputer</a>, SuperCard X is the platform in question and it’s currently being used to target the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a> via NFC relay attacks. With your credit card details in hand, the hackers behind this campaign then use them to make small transactions and withdrawals at ATMs to avoid having them flagged as fraudulent.</p><p>Discovered by the mobile security firm <a href="https://www.tomsguide.com/news/new-nexus-trojan-targets-450-financial-apps-and-is-taking-over-bank-accounts">Cleafy</a>, SuperCard X bears a lot of similarities to the <a href="https://www.tomsguide.com/computing/malware-adware/think-tap-to-pay-is-safer-new-android-malware-uses-stolen-nfc-data-to-drain-your-accounts">NGate malware</a> I covered last summer. It too uses contactless cards to commit fraud by taking over a vulnerable device’s NFC capabilities.</p><p>Here’s everything you need to know about this new <a href="https://www.tomsguide.com/computing/malware-adware/this-nasty-android-trojan-is-hijacking-calls-to-your-bank-and-sending-them-to-hackers-how-to-stay-safe">Android malware</a> threat, how to avoid falling victim to it and some tips and tricks to keep your phone malware-free and safe from hackers.</p><h2 id="from-phishing-to-social-engineering-to-fraud">From phishing to social engineering to fraud</h2><p>Just like with other malware attacks, this one begins with a victim receiving a text message or a WhatsApp message impersonating their bank. This <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing</a> message claims that they need to call a number to resolve issues with their account caused by a suspicious transaction.</p><p>The hackers behind this campaign pose as bank support on the other end of the call and they use social engineering to trick potential victims into “confirming” their card number and PIN. From there, they then try to convince the victim to remove spending limits via their banking app which is definitely a red flag as no bank would try to do something like this over the phone.</p><p>To gain access to their credit cards, the hackers convince victims to install a malicious app called Reader that’s disguised as either a security or verification tool. As you may have guessed, it contains the SuperCard X malware.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sMBrJVK3YBQYLkVgeP5oYX" name="supercard-x-malware-on-phone-cleafy" alt="The malicious app used to steal credit card data on a victim's phone and the app used to emulate stolen cards on a hacker's phone" src="https://cdn.mos.cms.futurecdn.net/sMBrJVK3YBQYLkVgeP5oYX.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Cleafy / Tom's Guide)</span></figcaption></figure><p>After installation, the Reader app doesn’t request loads of unnecessary permissions like we’ve seen other malicious apps do in the past. Instead, it only asks for a few essential permissions with the main one being access to an Android device’s NFC module.</p><p>The app then tells victims to tap their payment cards to their phone and to verify them. This allows the malware to read a card’s chip data and send it back to the hackers behind this campaign. This data arrives on a hacker-controlled phone which runs another app called Tapper which is able to emulate a victim’s card using this stolen data.</p><p>The hackers then use these emulated cards to make contactless payments at stores and to withdraw small amounts of money from ATMs. Since all of these transactions are small and happen instantly, a victim’s bank likely won’t even flag them as fraudulent and reverse the charges.</p><h2 id="how-to-stay-safe-from-android-malware-8">How to stay safe from Android malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4865px;"><p class="vanilla-image-block" style="padding-top:57.06%;"><img id="b6kHN5w33oqtSXyNEacmve" name="Android malware on phone.jpg" alt="Android malware on phone" src="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve.jpg" mos="" align="middle" fullscreen="" width="4865" height="2776" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The good news with this campaign is that according to <a href="https://www.cleafy.com/cleafy-labs/supercardx-exposing-chinese-speaker-maas-for-nfc-relay-fraud-operation">Cleafy’s report</a>, SuperCard X is currently only being used by hackers and scammers in Italy. However, since it is a malware-as-a-service offering purchased on the dark web, it could easily spread to other countries and continents any day now. As such, here are a few tips and tricks to stay safe from SuperCard X and other Android malware.</p><p>In this particular campaign, a random text from your bank is the kind of lure that you should know to avoid but can still fool some people due to the <a href="https://www.tomsguide.com/news/unpaid-invoices-are-one-of-the-easiest-ways-scammers-try-and-trick-you-what-to-look-out-for">sense of urgency</a> used in the message. Instead of responding to the message, you can always try looking up the phone number first. However, if the hackers or scammers spoofed your bank quite well, that number will be the same. In that case, it’s always a good idea to call your bank directly to verify something like this before responding.</p><p>Another big warning sign is when the hackers behind this campaign sent potential victims a URL for an app to download to their phone. No legitimate bank would ever ask you to do something like this and instead, they’d point you to their app’s listing page on the <a href="https://www.tomsguide.com/news/google-play-store-is-making-a-big-upgrade-to-fight-malware-what-you-need-to-know">Google Play Store</a>.</p><p>As for staying safe from Android malware, you want to make sure that <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> is enabled on your devices. This free, built-in security app checks all of the new apps you download as well as the existing ones on your phone or tablet for malware. For additional protection though, you might want to consider running one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it. </p><p>Now that SuperCard X is being used in attacks in the wild, I wouldn’t be surprised if other hackers and scammers started using this new malware-as-a-service in attacks in the U.S. and other countries.</p><p>By practicing good cyber hygiene and staying up to date on the latest threats (by reading this and other security articles on Tom’s Guide), you’ll be prepared to recognize the warning signs before it’s too late.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/samsung-phone-security-flaw-leaves-passwords-exposed-protect-yourself-now">Samsung phone security flaw leaves passwords exposed — protect yourself now</a></li><li><a href="https://www.tomsguide.com/computing/antivirus/do-you-really-need-to-pay-for-antivirus-software">Do you really need to pay for antivirus software?</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-hackers-are-using-fake-pdf-converters-to-spread-malware-and-steal-your-passwords">FBI warns hackers are using fake PDF converters to spread malware and steal your passwords</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI issues warning — hackers are using fake PDF converters to spread malware and steal your passwords  ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-hackers-are-using-fake-pdf-converters-to-spread-malware-and-steal-your-passwords</link>
                                                                            <description>
                            <![CDATA[ Be very vigilant about online file converting websites – some of them are fake and spreading malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cPUdHPwjWBcnw84NDV8w5A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Apr 2025 19:08:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker typing quickly on a keyboard]]></media:description>                                                            <media:text><![CDATA[A hacker typing quickly on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker typing quickly on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Be vigilant if you’re using an online PDF converter – the <a href="https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam">FBI recently issued a warning</a>  that threat actors have specifically been using online file conversion services to spread infostealing malware. </p><p>As reported by the <a href="https://indianexpress.com/article/technology/tech-news-technology/fake-free-pdf-to-docx-converter-info-stealing-virus-9945722/">Indian Express</a>, security firm CloudSEK has discovered an attack that mimics pdfcandy.com in order to trick users into downloading the ArechClient malware, which belongs to the SectopRAT family of infostealers. </p><p>The ArechClient malware has been active for several years and is used to steal critical personal data and information like usernames, browser passwords and crypto wallet information.</p><p>The report suggests that this latest phishing site, and others like it, have received more than 6,000 visits last month. This indicates that this malware has already been actively exploited by threat actors in order to steal data. </p><p>While many people search online for a PDF converter, this site has replicated the visual elements including the logo and the domain name, echoing it by using candyxpdf[.]com and candycoverterpdf[.]com in order to gain legitimacy. </p><p>The fake site allows users to upload a PDF file to convert it into a Word document, which requires CAPTCHA verification to complete. Upon completion of the CAPTCHA, users are given a prompt to run a PowerShell command to begin downloading the malware which is downloaded onto their computers under the file name ‘adobe.zip.’ </p><h2 id="how-to-stay-safe-4">How to stay safe</h2><p>Because this malware relies on users visiting look-a-like websites instead of the actual company's site that they intent to visit, being extremely cautious and vigilant about what websites you visit to download software is the first step.</p><p>Make sure you're downloading software from legitimate sources, and double and triple check the URLs you're visiting and the developer pages. </p><p>It also's good to make sure you have one of the<a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html"> best antivirus programs </a>set up, and updated, before you begin downloading files on the internet – many of them include features that can help protect you from malware as well as additional features like a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a> or hardened browser that can help protect you online. </p><p>Keep in mind, there are offline tools that will convert these files as well. </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/1-6-million-hit-in-massive-insurance-data-breach-full-names-addresses-ssns-and-more-exposed">1.6 million hit in massive insurance data breach — full names, addresses, SSNs and more exposed</a></li><li><a href="https://www.tomsguide.com/computing/online-security/hertz-confirms-data-breach-that-exposes-credit-cards-drivers-licenses-and-more">Hertz confirms data breach that exposed credit cards, drivers' licenses and more — what to do now</a></li><li><a href="https://www.tomsguide.com/computing/online-security/12-computer-security-mistakes-youre-probably-making-and-what-to-do-instead">12 computer security mistakes you're probably making — and what to do instead</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using fake Google Play Store pages to infect Android phones with a dangerous trojan — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-google-play-store-pages-to-infect-android-phones-with-a-dangerous-trojan-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ A new SpyNote malware campaign has been discovered online targeting Android users via fake Google Play Store pages. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rcagfWt65HK5CauNjmgdsM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Apr 2025 17:26:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new  campaign is bringing back the troublesome <a href="https://www.tomsguide.com/news/this-android-malware-is-spreading-like-wildfire-after-going-open-source-how-to-stay-safe">SpyNote malware</a> and this remote access trojan features a wide range of malicious capabilities while also being quite difficult to remove from an infected Android smartphone. </p><p>As reported by <a href="https://siliconangle.com/2025/04/10/spynote-android-malware-resurfaces-campaign-using-spoofed-app-install-pages/" target="_blank">SiliconANGLE</a>, this time around it is being spread via fake websites hosted on recently registered domains; the sites in question are imitating <a href="https://www.tomsguide.com/computing/malware-adware/fake-google-play-store-pages-are-spreading-trojan-malware-that-can-steal-your-financial-data">Google Play Store app pages</a> with incredibly accurate detail in order to trick users into downloading infected files instead of the apps they’re looking for. </p><p>The deceptive websites include detailed elements like image carousels with screenshots of the alleged apps in question, install buttons and code remnants – all familiar visual elements that are used to create an illusion of legitimacy. </p><p>Once a user has been tricked into clicking on the install button on one of these fake sites, JavaScript code is executed which triggers a download of a <a href="https://www.tomsguide.com/news/thousands-of-android-malware-apps-use-stealthy-apks-to-bypass-security-study-finds">malicious APK file</a>. This dropper APK executes a function that deploys a second, embedded APK. This secondary payload is the one that carries the core functionality of the malware, and will allow it to communicate with the command-and-control (<a href="https://www.tomsguide.com/news/this-new-macos-backdoor-lets-hackers-take-over-your-mac-remotely-how-to-stay-safe">C2</a>) servers of the threat actors using hardcoded IP addresses and ports. </p><p>The command-and-control parameters are embedded in SpyNote’s DEX files, which means it can support both dynamic and hardcoded connections. And the SSL certificates and DNS configurations point to systematic and automated deployment of these <a href="https://www.tomsguide.com/news/these-misspelled-websites-are-spreading-nasty-malware-how-to-stay-safe">malicious sites</a>, meaning they have likely been developed by someone with access to a <a href="https://www.tomsguide.com/news/password-stealing-erbium-malware-is-spreading-fast-and-loved-by-cybercriminals">malware-as-a-service</a> tool. </p><p>SpyNote itself is a particularly nasty malware as it has a wide range of capabilities and features: It can intercept text messages, call logs and contacts; activate a phone's camera and microphone remotely; log keystrokes (including credentials and 2FA codes); track your GPS location; record your phone calls; download and install apps; wipe or lock devices remotely and prevent its own removal by abusing <a href="https://www.tomsguide.com/news/look-out-this-android-malware-can-take-over-your-banking-and-crypto-accounts">Android's accessibility services</a>. </p><p>This is largely possible because of aggressive permission requests that also allow SpyNote to survive even after rebooting. It can also <a href="https://www.tomsguide.com/news/new-chameleon-banking-trojan-is-stealing-account-info-what-you-need-to-know">hide its app icon</a>, automatically relaunch after a reboot, and exclude itself from battery optimization so it can remain running in the background. DomainTools LLC, the internet intelligence company that discovered this latest campaign, has said that because of its persistent nature, the only way to completely remove the malware is often a <a href="https://www.tomsguide.com/computing/online-security/new-indie-game-found-spreading-malware-on-steam-how-to-see-if-your-pc-is-infected-and-what-to-do-next">factory reset</a>. </p><h2 id="how-to-stay-safe-5">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Android users should be very wary about fake Google Play Store pages and make sure they're only downloading apps from a legitimate app store. Don't sideload APKs from unknown places and always, always check the URLs of the websites you're visiting. </p><p>The usual rules of <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing</a> and good online web practices also apply: Don't click on links, QR codes or attachments from unknown or unexpected senders. Likewise, having one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> installed on your smartphone and make sure it's kept up to date can help keep you safe from mobile malware infections.</p><p>Impersonating popular brands and services is one of the oldest tricks in a hackers' playbook which is why you need to be on the lookout at all times for fake sites, <a href="https://www.tomsguide.com/news/you-should-think-twice-before-clicking-on-ads-even-on-google-search">malicious ads</a> and other lures. This way, you can keep your phone and all the sensitive personal and financial data it contains safe from hackers. </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/scammers-are-impersonating-quickbooks-in-last-minute-tax-phishing-scam-and-its-stealing-financial-data">Scammers are impersonating QuickBooks in last-minute tax phishing scam — and it's stealing financial data</a></li><li><a href="https://www.tomsguide.com/computing/online-security/windows-pcs-under-threat-from-zero-day-flaw-used-in-ransomware-attacks-update-your-computer-right-now">Windows PCs under threat from zero-day flaw used in ransomware attacks — update your computer right now</a></li><li><a href="https://www.tomsguide.com/computing/online-security/microsoft-just-patched-134-windows-security-flaws-including-a-zero-day-used-by-hackers-update-your-pc-right-now">Microsoft just patched 134 Windows security flaws including a zero-day used by hackers — update your PC right now</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous Windows malware can hijack your PC, hold it for ransom, steal your passwords and even let hackers spy on you ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/neptune-rat-malware-is-hijacking-windows-pcs-holding-them-for-ransom-and-stealing-passwords</link>
                                                                            <description>
                            <![CDATA[ The Netune RAT can wreak havoc on vulnerable Windows PCs by stealing crypto and passwords from over 270 different apps. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QAiMd6XE9tf2go8XtKR42H</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ampbc94VKRrFc2UNgDpJyg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Apr 2025 21:49:53 +0000</pubDate>                                                                                                                                <updated>Tue, 08 Apr 2025 05:08:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ampbc94VKRrFc2UNgDpJyg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A picture of a skull made from computer code depicting a malware infection]]></media:description>                                                            <media:text><![CDATA[A picture of a skull made from computer code depicting a malware infection]]></media:text>
                                <media:title type="plain"><![CDATA[A picture of a skull made from computer code depicting a malware infection]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ampbc94VKRrFc2UNgDpJyg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybercriminals are currently using a new malware strain that’s been dubbed as the “Most Advanced RAT” (or <a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-password-stealing-trojan-automatically-reinstalls-itself-on-infected-pcs">remote access trojan</a>) ever to infect vulnerable Windows PCs to steal crypto and passwords as well as hold them for ransom.</p><p>As reported by <a href="https://cybernews.com/security/rat-malware-youtube-password-stealer/" target="_blank">Cybernews</a>, the Neptune RAT is currently making the rounds online and this dangerous malware shouldn’t be ignored. This is because it’s highly advanced and can hijack Windows devices, spy on their owners and more, all while evading detection from the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a>.</p><p>According to a new <a href="https://www.cyfirma.com/research/neptune-rat-an-advanced-windows-rat-with-system-destruction-capabilities-and-password-exfiltration-from-270-applications/" target="_blank">blog post</a> from the cybersecurity firm <a href="https://www.tomsguide.com/news/this-android-chat-app-is-actually-spyware-that-steals-your-data-how-to-stay-safe">CYFIRMA</a>, the Neptune RAT is currently being spread on GitHub, Telegram and even YouTube. Like other malware strains before it, it uses a <a href="https://www.tomsguide.com/news/password-stealing-erbium-malware-is-spreading-fast-and-loved-by-cybercriminals">malware-as-a-service</a> model where any hacker can pay a monthly fee to deploy it in their attacks.</p><p>Here’s everything you need to know about this new Windows malware along with some tips and tricks to help keep your PC and your data safe from the Neptune RAT.</p><h2 id="wreaking-havoc-on-windows-pcs">Wreaking havoc on Windows PCs</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:8256px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iuibyMGxncrhX6RweFUqcb" name="shutterstock_2407734581" alt="A person typing on a laptop with warning messages displayed on screen" src="https://cdn.mos.cms.futurecdn.net/iuibyMGxncrhX6RweFUqcb.jpg" mos="" align="middle" fullscreen="" width="8256" height="4644" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>The Neptune RAT is a feature-rich malware strainpacked with plenty of dangerous capabilities.</p><p>For starters, it features a crypto clipper which can swap out a victim’s cryptocurrency wallet address with a hacker’s address and divert digital funds right from your account. Neptune RAT’s theft doesn’t stop there though, as it also comes with a <a href="https://www.tomsguide.com/computing/online-security/new-malware-locks-google-chrome-in-kiosk-mode-until-you-enter-your-password-how-to-stay-safe">password stealer</a>. Once installed on a vulnerable PC, this malware is able to steal usernames and passwords from more than 270 different apps including popular browsers like Chrome.</p><p>With all of this sensitive personal and financial data in hand, hackers who have deployed the Neptune RAT in their attacks can take over your social media accounts to launch additional attacks and even <a href="https://www.tomsguide.com/computing/malware-adware/new-android-malware-drains-your-bank-accounts-and-completely-wipes-your-device-how-to-stay-safe">drain your bank accounts</a>.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:958px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="jNRotGUo8ZzNr8MaJxSWvM" name="neptune-rat-ransomware-screenshot" alt="A screenshot showing how easy it is for hackers to use the Neptune RAT's ransomware capabilities" src="https://cdn.mos.cms.futurecdn.net/jNRotGUo8ZzNr8MaJxSWvM.jpg" mos="" align="middle" fullscreen="" width="958" height="539" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: CYFIRMA/Tom's Guide)</span></figcaption></figure><p>If all this wasn’t bad enough, the malware also includes a <a href="https://www.tomsguide.com/news/this-ransomware-makes-you-sign-up-for-roblox-to-get-your-files-back">ransomware</a> feature that locks a victim’s files until they pay up. Neptune RAT can even disable <a href="https://www.tomsguide.com/news/windows-defender-good-enough-for-new-laptop">Windows Defender</a> and other antivirus programs.</p><p>The malware can also be used for espionage and blackmail since it also has a screen monitoring feature that can be used to view what a victim is doing on their computer in real time. </p><p>Finally, Neptune RAT has a destruction feature that can be used to completely wipe your PC if the hackers using it feel like they’ve exhausted the malware’s other capabilities.</p><h2 id="how-to-keep-your-pc-safe-from-malware">How to keep your PC safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="D8JxHKmGbugi82MYYGGRNE" name="shutterstock_1964563111-2" alt="A woman using her laptop securely with a cup of coffee in hand" src="https://cdn.mos.cms.futurecdn.net/D8JxHKmGbugi82MYYGGRNE.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Since the Neptune RAT is currently being spread on GitHub, Telegram and YouTube, you want to be extra careful when downloading any files from these services as well as clicking on any links, especially ones from unknown senders.</p><p>Due to the way in which the malware’s creator has distributed it, cybersecurity researchers are having a difficult time analyzing it. As such, it might take a while before its viral signature is added to antivirus software and even then, it features advanced capabilities to avoid detection.</p><p>Normally, I’d recommend investing in a good antivirus suite but considering little can be done at this point, signing up for the <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html">best identity theft protection</a> makes more sense. Identity theft protection services can help you recover lost funds after an attack and they also come with insurance if you need to replace your PC completely which could very well be the case with the Neptune RAT.</p><p>Given that the Neptune RAT is already highly advanced, I expect this won’t be the last we hear of this new Windows threat. This is why it’s of the utmost importance that you practice good cyber hygiene online and avoid downloading suspicious files onto your PC.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/security-spring-cleaning-7-things-you-should-do-now-to-avoid-getting-hacked">Security spring cleaning — 7 things you should do now to avoid getting hacked</a></li><li><a href="https://www.tomsguide.com/computing/online-security/no-that-toll-text-scam-isnt-over-yet-how-to-avoid-getting-phished">No, that toll text scam isn’t over yet — how to avoid getting phished</a></li><li><a href="https://www.tomsguide.com/computing/online-security/google-just-fixed-two-critical-android-zero-days-and-60-other-flaws-update-your-phone-right-now">Google just fixed two critical Android zero-days and 60 other flaws — update your phone right now</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake Zoom installer tries to trick users into installing dangerous ransomware – here’s how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/fake-zoom-installer-tries-to-trick-users-into-installing-dangerous-ransomware-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Hackers are tricking people trying to install Zoom into infecting their computers with the BlackSuit ransomware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SauL8y9YMiV7XUmCNimBWP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/f3jPiJfdU4TFDyQPkWoWXo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Mar 2025 15:49:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/f3jPiJfdU4TFDyQPkWoWXo-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zoom call on MacBook]]></media:description>                                                            <media:text><![CDATA[Zoom call on MacBook]]></media:text>
                                <media:title type="plain"><![CDATA[Zoom call on MacBook]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/f3jPiJfdU4TFDyQPkWoWXo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are once again targeting <a href="https://www.tomsguide.com/news/zoom-security-privacy-woes">Zoom</a> users by tricking them into infecting their own PCs with ransomware by using fake sites.</p><p>As reported by <a href="https://cybernews.com/security/fake-zoom-installer-deploys-ransomware/" target="_blank">Cybernews</a>, security researchers at DFIR have discovered a new campaign from the BlackSuit ransomware gang which impersonates the popular video conferencing software.</p><p>Instead of going to the official site and downloading Zoom directly, users are being tricked into going to a <a href="https://www.tomsguide.com/computing/online-security/hackers-have-created-hundreds-of-fake-reddit-sites-to-spread-info-stealing-malware">lookalike site</a> where they end up accidentally downloading the BlackSuit ransomware instead. </p><p>Once installed, the ransomware will lie in wait for a period of time before it begins carrying out malicious activity. After scraping and then encrypting sensitive personal and financial data on an infected PC, the hackers behind this campaign demand a ransom to unlock them. </p><p>The BlackSuit ransomware is known to target schools, healthcare systems, law enforcement facilities and other critical services. The malicious loader is first downloaded to a victims device where it’s capable of staying hidden from security tools and can also disable <a href="https://www.tomsguide.com/news/windows-defender-good-enough-for-new-laptop">Windows Defender</a>. </p><p>Next the malware connects to a Steam Community page where it can find the next stage server address and downloads both the real Zoom installer and the malicious software. It secretly injects itself into a MSBuild executable and remains inactive for eight days before it begins its next round of malicious activities. </p><p>On the ninth day, it will run Windows Commands to gather system information, and deploy <a href="https://www.tomsguide.com/news/macs-are-under-attack-from-this-cybersecurity-tool-what-you-need-to-know">Cobalt Strike</a> which is a hacking tool used to spread across the network.  A tool called QDoor is also installed that lets attackers remotely control infected systems by routing traffic through a domain controller. </p><p>The malware then compresses important fields and downloads them, and in its final step, the BlackSuit ransomware is deployed across all Windows systems on the network. Important files are locked behind a password and a <a href="https://www.tomsguide.com/news/this-ransomware-makes-you-sign-up-for-roblox-to-get-your-files-back">ransom note</a> is left on these now infected PCs.</p><h2 id="how-to-stay-safe-6">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:5342px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="MC3iNmQLKLcYS2fWGgAouZ" name="shutterstock_631810814" alt="A man clicking on a mouse while browsing the web on his laptop" src="https://cdn.mos.cms.futurecdn.net/MC3iNmQLKLcYS2fWGgAouZ.jpg" mos="" align="middle" fullscreen="" width="5342" height="3005" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Since the BlackSuit ransomware is being installed from fake sites, the best way to avoid it is to make sure that you’re installing Zoom's video conferencing software from the company's official site. </p><p>The suspicious site spreading malware in this campaign is said to be zoommanager[.]com which is quite different from the official Zoom download page that can be found at zoom[.]us/download.</p><p>As well as making sure you're always downloading software from the correct source, make sure you are aware of common <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing techniques</a> and tricks so you can recognize them when you see them. You also want to install the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> on your computer and update it regularly just in case anything gets by you, and make sure it covers all your devices. </p><p>Many of the top antivirus software suites also include features like a<a href="https://www.tomsguide.com/best-picks/best-vpn"> VPN </a>or <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a> that will provide an extra layer of protection as well.</p><p>Zoom isn't nearly as popular with hackers now as it was a few years ago but given how widely used the service is, it's an easy way to target unsuspecting users online. This is why you also have to be careful when downloading new software and instead of clicking on a link sent to you by someone else or even one at the top of a search results page, it's always better to navigate to a software's download page directly. </p><p>Unfortunately, I doubt this is the last time we'll see hackers impersonating Zoom in their attacks though.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/security-spring-cleaning-7-things-you-should-do-now-to-avoid-getting-hacked">Security spring cleaning — 7 things you should do now to avoid getting hacked</a></li><li><a href="https://www.tomsguide.com/computing/online-security/unchecked-browser-extensions-could-be-opening-you-up-to-attacks-what-you-need-to-know-and-how-to-stay-safe">Unchecked browser extensions could be opening you up to attacks — what you need to know and how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/this-dangerous-new-windows-malware-hides-from-your-antivirus-while-impersonating-a-popular-pc-brand">This dangerous new Windows malware hides from your antivirus while impersonating a popular PC brand</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This dangerous new Windows malware hides from your antivirus while impersonating a popular PC brand ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/this-dangerous-new-windows-malware-hides-from-your-antivirus-while-impersonating-a-popular-pc-brand</link>
                                                                            <description>
                            <![CDATA[ A new Windows malware impersonating a popular utility from Asus is making the rounds online and infecting vulnerable PCs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XKGBK7q59ChxZaQaGbpdE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NhaQzM2e7wGRizKpRHZiUW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Mar 2025 15:53:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NhaQzM2e7wGRizKpRHZiUW-1280-80.jpg">
                                                            <media:credit><![CDATA[solarseven / Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic screen displaying malware detection warning ]]></media:description>                                                            <media:text><![CDATA[Graphic screen displaying malware detection warning ]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic screen displaying malware detection warning ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NhaQzM2e7wGRizKpRHZiUW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new <a href="https://www.tomsguide.com/news/this-windows-malware-is-stealing-passwords-and-other-data-how-to-stay-safe">malware family</a> is targeting Windows users by impersonating an ASUS utility to deliver malicious code – but perhaps most concerningly, it uses multiple techniques to hide itself from the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> and other security tools. </p><p>As reported by <a href="https://cybernews.com/security/coffeeloader-malware-asus-windows/" target="_blank">Cybernews</a>, the CoffeeLoader malware, identified by researchers from the cybersecurity firm Zscaler, mimics Asus' Armoury Crate. This utility is used to set up and manage the <a href="https://www.tomsguide.com/best-picks/best-gaming-laptops">best gaming laptops</a> from Asus as well as the company's other peripherals.</p><p>The researchers say CoffeeLoader originated around September 2024 and has several similarities to the <a href="https://www.tomsguide.com/news/this-mysterious-new-malware-uses-wi-fi-networks-to-give-hackers-your-exact-location">SmokeLoader</a> malware. </p><p>Once the malware has infected a system, it delivers several infostealers – among them the well known  <a href="https://www.tomsguide.com/news/hackers-using-google-ads-to-steal-your-info-and-drain-your-accounts-what-you-need-to-know">Rhadamanthys Infostealer</a>. From there, it uses a number of tricks to stay undetected by antivirus programs and other security tools. </p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1280px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="U9kDj9L7k2hs7mpzZh4AuW" name="coffee-loader-armoury-crate-zscaler" alt="A screenshot of a ZScaler's Cloud Sandbox detecting a malicious version of Asus' Armoury Crate software" src="https://cdn.mos.cms.futurecdn.net/U9kDj9L7k2hs7mpzZh4AuW.jpg" mos="" align="middle" fullscreen="" width="1280" height="720" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: ZScaler/Tom's Guide)</span></figcaption></figure><p>For example, it will run code on the infected systems GPU instead of on the computer’s CPU. Since most security programs and antivirus scanners don’t check the GPU, the malware stays hidden.</p><p>Another way it covers its tracks is by using a technique called Call Stack Spoofing. While most programs leave behind a trail of function calls, the CoffeeLoader malware can change its own trail in order to make it appear harmless. This keeps it from being recognized as suspicious or harmful by any security software or antivirus programs. </p><p>It can also “play dead” or use a technique called Sleep Obfuscation. Basically, when it’s not active, it will “lock” itself up into an encrypted form in the computer's memory; if an antivirus tool scans the memory it won’t find anything readable. </p><p>The CoffeeLoader malware also accesses unusual pathways, for example, Windows Fibers, in order to evade detection. Windows Fibers are a way in which programs handle multitasking which allows a program to switch between tasks on its own instead of relying on Windows. The CoffeeLoader can then use these fibers to evade detection since security tools may not monitor them.</p><h2 id="how-to-stay-safe-7">How to stay safe</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qnzrZD9FcrdWqGkgjkRQkH" name="TG_Asus-ROG-Strix-G18_15.jpg" alt="Asus ROG Strix G18 on desk" src="https://cdn.mos.cms.futurecdn.net/qnzrZD9FcrdWqGkgjkRQkH.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Tom's Guide)</span></figcaption></figure><p>In order to keep your data and your Asus gear safe from the CoffeeLoader malware, you want to ensure that you're downloading Armoury Crate from the company's official site and you can find the <a href="https://www.asus.com/us/supportonly/armoury%20crate/helpdesk_download/" target="_blank">download page</a> here.</p><p>Hackers often <a href="https://www.tomsguide.com/news/6000-sites-used-to-impersonate-100-top-brands-and-steal-your-banking-info-how-to-stay-safe">impersonate popular brands</a> and their software as a means to infect unsuspecting users with malware. This is why you always want to go directly to a company's site instead of trusting download links that appear online in forums or even as ads in search results.</p><p>Just like anyone else, hackers can easily purchase ad space online and then by crafting a convincing lookalike page, they can trick unsuspecting users into downloading malware onto their PCs through their <a href="https://www.tomsguide.com/news/you-should-think-twice-before-clicking-on-ads-even-on-google-search">malicious ads</a>.</p><p>Now that we've seen CoffeeLoader impersonate Asus, it's likely that the hackers behind this campaign will try to pose as other popular utilities to recreate this attack. This is why you need to practice good cyber hygiene and remain vigilant online, especially when downloading new software.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/ai-powered-tax-scams-are-here-how-to-stay-safe-from-deepfakes-phishing-and-more-this-tax-season">AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season</a></li><li><a href="https://www.tomsguide.com/computing/online-security/valve-just-pulled-a-malicious-game-demo-spreading-info-stealing-malware-from-steam">Valve just pulled a malicious game demo spreading info-stealing malware from Steam</a></li><li><a href="https://www.tomsguide.com/computing/online-security/new-mac-attack-is-tricking-users-into-thinking-their-computer-is-locked-how-to-stay-safe">New Mac attack is tricking users into thinking their computer is locked — how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/hundreds-of-malicious-android-apps-with-60-million-downloads-found-spamming-android-users-with-ads-and-stealing-credentials</link>
                                                                            <description>
                            <![CDATA[ Bitdefender found a total of 331 malicious apps hiding as simple utilities and other tools on the Google Play Store that were part of a massive ad fraud campaign. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xgvGJa5QkkkFT3YeKBeQRj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Mar 2025 19:35:50 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Mar 2025 16:09:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Green skull on smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Green skull on smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Green skull on smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Jzwhquu4gv5ZQF336dDbZE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>You can never be too careful when downloading new apps to one of the <a href="https://www.tomsguide.com/us/best-android-phones,review-6051.html">best Android phones</a>. Case in point: Bitdefender has discovered hundreds of <a href="https://www.tomsguide.com/computing/malware-adware/nearly-100-malicious-apps-with-55-million-installs-spreading-malware-on-play-store-protect-yourself-now">malicious apps</a> on the Google Play Store that were used in a massive ad fraud campaign.</p><p>While that QR code scanner, wallpaper app or simple game might look harmless at first glance, these types of apps are often used in campaigns like this one. Sure, the app may look and function properly, but behind the scenes it can put your data and privacy at risk or (in this case) spam your device with full-screen ads.</p><p>In a new <a href="https://www.bitdefender.com/en-us/blog/labs/malicious-google-play-apps-bypassed-android-security" target="_blank">blog post</a>, <a href="https://www.tomsguide.com/reviews/bitdefender">Bitdefender</a> explains that its IAS Threat Lab initially uncovered part of this new campaign when it discovered more than 180 malicious apps. However, there are at least 331 bad apps in total and together, they’ve been downloaded over 60 million times right from Android’s official app store.</p><p>Here’s everything you need to know about this new campaign, what these malicious apps are capable of and some tips and tricks on how you can stay safe from bad apps found on the <a href="https://www.tomsguide.com/news/hackers-are-sneaking-malware-on-to-the-google-play-store-how-to-stay-safe">Google Play Store</a> and elsewhere.</p><h2 id="avoid-these-apps-at-all-costs">Avoid these apps at all costs</h2><p>As of now, the majority of the malicious apps used in this campaign have been pulled from the Play Store. However, in an email to Tom’s Guide, a Bitdefender spokesperson provided the list of malicious apps below that have yet to be taken down at the time of writing:</p><ul><li><strong>ShapeUp </strong>- 100k</li><li><strong>Beautiful Day</strong> - 5k</li><li><strong>Destiny Book</strong> - 10k</li><li><strong>Dropo </strong>- 10k</li><li><strong>Handset Locator</strong> - 50k</li><li><strong>Body Scale</strong> - 500k</li><li><strong>Cache Sweep TEL: Clean</strong> - 100k</li><li><strong>Five in a Row</strong> - 100k</li><li><strong>Massm BMI</strong> - 500k</li><li><strong>Water Note </strong>- 50k</li></ul><p>You should avoid downloading any of these apps in the meantime. If you have any of the other 300+ malicious apps installed on your Android devices, you’re going to have to find and delete them manually. </p><p>You can find the <a href="https://github.com/bitdefender/malware-ioc/blob/master/vapor_malware/urls.csv" target="_blank">full list of URLs</a> associated with them and their <a href="https://github.com/bitdefender/malware-ioc/blob/master/vapor_malware/packages.csv" target="_blank">package names</a> here or at the bottom of Bitdefender’s blog post, though you will have to do some guesswork to figure out their exact names. </p><p>If you have <a href="https://www.tomsguide.com/reviews/google-play-protect">Google Play Protect</a> enabled, the built-in security software that ships with most Android phones will warn you if you have one of these apps installed.</p><h2 id="bypassing-android-security">Bypassing Android security</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4865px;"><p class="vanilla-image-block" style="padding-top:57.06%;"><img id="b6kHN5w33oqtSXyNEacmve" name="Android malware on phone.jpg" alt="Android malware on phone" src="https://cdn.mos.cms.futurecdn.net/b6kHN5w33oqtSXyNEacmve.jpg" mos="" align="middle" fullscreen="" width="4865" height="2776" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>According to Bitdefender’s research, most of the malicious apps in question first became active on the Play Store during the third quarter of last year. However, upon further investigation, the cybersecurity firm’s researchers discovered that some were uploaded earlier than that but did not contain any malicious components at the time. </p><p>It’s worth noting that this is still an active campaign, with the latest batch of bad apps uploaded at the start of this month. These apps include Dropo as well as Handset Locator which are both still up on the Play Store at the time of writing, though they’ll likely be taken down soon.</p><p>What makes this latest collection of malicious apps so dangerous is that they were able to bypass the <a href="https://www.tomsguide.com/news/android-13-security-feature-designed-to-stop-malware-has-already-been-bypassed">security protections</a> built into <a href="https://www.tomsguide.com/reviews/android-13">Android 13</a>. For instance, they can start without any user interaction whatsoever even though this technically isn’t possible in that version of Android.</p><p>The cybercriminals behind this campaign have also figured out how to hide the icons of these apps in the operating system’s launcher which is restricted in newer versions of Android.</p><p>Once installed on a vulnerable Android phone, these malicious apps show out-of-context ads over other applications in the foreground. Surprisingly, they’re able to do this without requesting any <a href="https://www.tomsguide.com/news/these-predatory-loan-apps-have-been-installed-over-15-million-times-delete-them-now">unnecessary permissions</a> that would allow this behavior.</p><p>Besides spamming ads, some of these bad apps can also launch <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing attacks</a> which are designed to persuade potential victims to willingly hand over their passwords or worse, their credit card information. Meanwhile, others point users towards <a href="https://www.tomsguide.com/news/hackers-often-use-this-clever-trick-to-take-you-to-phishing-sites-can-you-spot-it">phishing sites</a> designed to do the exact same thing.</p><h2 id="how-to-stay-safe-from-malicious-apps-3">How to stay safe from malicious apps</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:910px;"><p class="vanilla-image-block" style="padding-top:56.26%;"><img id="MRUEsvBrdDnwpsDgw3GGzh" name="zaT2fiZB7dapNQNABNG7Yk.jpg" alt="A hand holding a phone securely logging in" src="https://cdn.mos.cms.futurecdn.net/MRUEsvBrdDnwpsDgw3GGzh.jpg" mos="" align="middle" fullscreen="" width="910" height="512" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Google)</span></figcaption></figure><p>Even if you’re extra careful online and only stick to <a href="https://www.tomsguide.com/computing/malware-adware/amazon-appstore-used-to-spread-android-malware-delete-this-malicious-app-right-now">official app stores</a>, you could end up downloading a malicious app accidentally like the millions of people caught up in the campaign described above.</p><p>This is why I highly recommend limiting the number of apps on your phone overall. If you have fewer apps installed, you’re less likely to install a bad one or as we’ve seen in the past, to be caught off guard when a <a href="https://www.tomsguide.com/news/popular-android-screen-recorder-app-went-from-legitimate-to-malicious-overnight-what-you-need-to-know">good app goes bad</a>. </p><p>Before installing a new app, you should ask yourself if you really need it first. Can another app you already use or even an online tool help you accomplish the exact same thing? If you do go ahead with installing a new app, you want to take a close look at its ratings and reviews as Android users are quite vocal in their reviews when an app carries out suspicious or even malicious activities in the background. Since ratings and reviews can be faked though, it’s always a good idea to look for an external review or better yet, a video review so you can see the app in question in action before installing it.</p><p>While your phone likely shipped with Google’s built-in Play Protect security software, you may also want to run one of the <a href="https://www.tomsguide.com/best-picks/best-android-antivirus">best Android antivirus apps</a> alongside it. These paid antivirus apps are updated more frequently and can sometimes catch things that Google Play Protect might miss.</p><p>Malicious apps are one of the easiest ways to gain access to the sensitive personal and financial information stored on your smartphone. However, if you’re very selective about which apps you install and keep the ones you do regularly updated, you’ll be less likely to fall for this kind of attack.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/new-massjacker-malware-is-hijacking-digital-wallets-to-steal-large-sums-from-users">New MassJacker malware is hijacking digital wallets to steal large sums from users</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/dangerous-new-password-stealing-trojan-automatically-reinstalls-itself-on-infected-pcs">Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-over-free-online-file-converters-that-infect-your-pc-with-malware">FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/dangerous-new-password-stealing-trojan-automatically-reinstalls-itself-on-infected-pcs</link>
                                                                            <description>
                            <![CDATA[ The StilachiRAT uses sophisticated techniques to hide on your PC while stealing crypto, passwords and sensitive data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c3GZZ9hUfJdx6iZBUtXLRf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Mar 2025 16:55:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rjvaLaDqTmZTLZ7RKhKSUB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft Incident Response has identified a new <a href="https://www.tomsguide.com/news/macs-under-attack-by-north-korean-spies-how-to-protect-yourself">remote access trojan</a> (RAT) that is capable of stealing a wide variety of information from your computer from passwords and cryptocurrency wallet information to operating system details, device identifiers, and even camera presence data. </p><p>The most sophisticated – and perhaps the most alarming – feature of this new malware is its ability to use watchdog threads to ensure self-reinstatement if removed. Basically, it can reinstall itself. </p><p>As reported by <a href="https://www.bleepingcomputer.com/news/security/microsoft-new-rat-malware-used-for-crypto-theft-reconnaissance/" target="_blank">BleepingComptuer</a>, the StilachiRAT is used to steal digital wallet data from multiple cryptocurrency wallets including Coinbase Wallet, Phantom, Trust Wallet, Metamask, OKX Wallet, Bitget Wallet and up to 20 others. </p><p>The malware also has sophisticated reconnaissance abilities and is able to steal information from an infected PC including credentials stored in your browser, <a href="https://www.tomsguide.com/computing/online-security/hackers-are-using-recaptcha-to-trick-users-into-infecting-their-own-pcs-with-malware-how-to-stay-safe">clipboard data</a>, system information, hardware identifiers, camera presence, active Remote Desktop Protocol (RDP) sessions, and running GUI-based applications.</p><p>StilachiRAT can extract credentials from Google Chrome's local state file using Windows APIs, monitor clipboard activity for password information and crypto keys and track active windows or applications. It uses the Windows service control manager (SCM) to maintain persistence and reinstalls it automatically when the malware notices its binaries are no longer active.</p><p>At the same time, StilachiRAT can monitor active RDP sessions by impersonating logged in users. It does this by capturing information from foreground windows then cloning security tokens. This allows attackers to move laterally through a victim’s network after the malware has been deployed on RDP servers that usually host admin sessions. </p><p>StilachiRAT can also evade detection and has anti-forensics features, such as the ability to clear event logs and check for signs that its running in a sandbox in order to block malware analysis attempts.  If its tricked into running in a sandbox, the RAT’s API calls are encoded to slow down further analysis. </p><p>The StilachiRAT malware was first discovered back in November of last year. In a new <a href="https://www.microsoft.com/en-us/security/blog/2025/03/17/stilachirat-analysis-from-system-reconnaissance-to-cryptocurrency-theft/" target="_blank">blog post</a> though, Microsoft says it has not yet reached widespread distribution, and that it doesn't have any information on a specific threat actor or a particular location of origin. </p><h2 id="how-to-stay-safe-from-stilachirat">How to stay safe from StilachiRAT </h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1600px;"><p class="vanilla-image-block" style="padding-top:56.31%;"><img id="36Uux48yxWqW5exmyt5mWk" name="online-scam-victims.jpg" alt="Man stressed at computer" src="https://cdn.mos.cms.futurecdn.net/36Uux48yxWqW5exmyt5mWk.jpg" mos="" align="middle" fullscreen="" width="1600" height="901" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: American Institute of Stress)</span></figcaption></figure><p>In order to avoid infection from this RAT, Microsoft’s advice is pretty simple: Make sure to only download software from official websites and use security software that can block malicious domains and email attachments. </p><p>That means you should install the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> on your PC and make sure you're keeping it up to date. You also want to know the common signs of <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing attacks</a> such as <a href="https://www.tomsguide.com/news/these-misspelled-websites-are-spreading-nasty-malware-how-to-stay-safe">misspelled domain names</a> or email signatures, attachments from unknown senders, or messages that contain a <a href="https://www.tomsguide.com/news/unpaid-invoices-are-one-of-the-easiest-ways-scammers-try-and-trick-you-what-to-look-out-for">sense of urgency</a> or even <a href="https://www.tomsguide.com/news/this-fake-copyright-scam-is-infecting-pcs-with-ransomware-what-to-know">threats of a legal nature</a> that encourage you to click or download something. </p><p>Never click on something that you aren't expecting or don't know what it is or who sent it and when in doubt, contact the sender in a separate message or email. If a domain name or URL seems suspicious then go to it directly by typing it into the browser window instead of by clicking on a link. You can also use a <a href="https://www.tomsguide.com/best-picks/best-vpn">VPN</a> to protect your privacy further and a <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">password manager</a> to keep your passwords safe.</p><p>New malware strains like this one are created everyday but by practicing good cyber hygiene and staying up to date on the latest attack methods, you can avoid falling victim to StilachiRAT and other online threats.  </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/online-security/5-iphone-settings-you-should-always-shut-off-because-theyre-a-security-nightmare">5 iPhone settings you should always shut off — because they’re a security nightmare</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/new-massjacker-malware-is-hijacking-digital-wallets-to-steal-large-sums-from-users">New MassJacker malware is hijacking digital wallets to steal large sums from users</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-over-free-online-file-converters-that-infect-your-pc-with-malware">FBI issues warning over free online file converters that infect your PC with malware</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/fbi-issues-warning-over-free-online-file-converters-that-infect-your-pc-with-malware</link>
                                                                            <description>
                            <![CDATA[ Online file converters may seem harmless, but hackers are now using them to infect vulnerable PCs with malware. Here's what to look out for and how to stay safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pgPo2njgmPY2gDPiKvMAyH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MQWbdrwdGwvNx6xsEAq7rP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Mar 2025 18:24:38 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Mar 2025 18:41:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ anthony.spadafora@futurenet.com (Anthony Spadafora) ]]></author>                    <dc:creator><![CDATA[ Anthony Spadafora ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z73LEoj7FkUjNG85GcWHtH.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches and malware to password managers and the best way to cover your whole home or business with a strong Wi-Fi signal.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Before joining the team, he spent three years covering cybersecurity and B2B tech for ITProPortal while living in South Korea. After moving back to the US. Anthony joined the TechRadar Pro team where he covered these topics along with VPNs, web hosting, online collaboration software and video conferencing for four years. Anthony also has his ears to the ground and is on the lookout for the next major cyberattack or data breach.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Based in Houston, Texas, Anthony also handles VPN testing for both Tom’s Guide and TechRadar. As someone who has worked from home exclusively since 2018, he has reviewed dozens of standing desks as well as office chairs and has taken a closer look at other essential remote working accessories. As part of these reviews, Anthony frequently builds intricate desk setups which is why he’s such a big advocate for cable management and keeping things organized. When he’s not writing, he can be found tinkering with PCs and game consoles, managing cables and making upgrades to his smart home.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MQWbdrwdGwvNx6xsEAq7rP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An FBI agent typing on a computer]]></media:description>                                                            <media:text><![CDATA[An FBI agent typing on a computer]]></media:text>
                                <media:title type="plain"><![CDATA[An FBI agent typing on a computer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MQWbdrwdGwvNx6xsEAq7rP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Regardless of how tech savvy you may be, chances are you’ve likely turned to a free online file converter for help with quickly changing a file from one type to another. However, you may want to think twice before doing so, as the FBI is now warning that hackers are using these free tools to spread <a href="https://www.tomsguide.com/computing/malware-adware/dont-click-this-malicious-ads-impersonating-google-chrome-spreading-dangerous-malware">dangerous malware</a> to vulnerable PCs.</p><p>Whether you want to change a PDF to a DOC or a WebP image to a JPEG, it’s easy to get stumped on the best way to convert one popular file type to another. Sure, <a href="https://www.tomsguide.com/deals/where-to-buy-microsoft-office">Microsoft Office</a> and other writing tools have this functionality built in, but in the heat of the moment, it’s easy to open up your browser and search for a free file converter online.</p><p>In a <a href="https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam" target="_blank">new post</a>, though, the FBI Denver Field Office explains that cybercriminals have seized this opportunity to create <a href="https://www.tomsguide.com/computing/online-security/hackers-have-created-hundreds-of-fake-reddit-sites-to-spread-info-stealing-malware">malicious sites</a> that instead of converting one file type to another actually install malware on your computer.</p><p>Here’s everything you need to know about this new <a href="https://www.tomsguide.com/news/worst-online-scams-avoid">online scam</a>, including some tips and tricks to help you stay safe from hackers and the malware they use in their attacks.</p><h2 id="from-converting-files-to-malware-infection">From converting files to malware infection</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:6240px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zU8gpvFte2AdkMPrdadx2a" name="shutterstock_2404720713" alt="A person on a laptop converting a PDF to a DOC" src="https://cdn.mos.cms.futurecdn.net/zU8gpvFte2AdkMPrdadx2a.jpg" mos="" align="middle" fullscreen="" width="6240" height="3510" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>From converting one file type to another to combining multiple images into a single PDF file, cybercriminals are now using all of these different kinds of online tools as a lure in their attacks. It’s also easy to get people to click on them too by using <a href="https://www.tomsguide.com/news/you-should-think-twice-before-clicking-on-ads-even-on-google-search">malicious ads</a> which show up at the top of search results.</p><p>While many of these tools do exactly what they say they do, the FBI points out that along with your converted files, you could also be downloading malware to your PC or Mac. This isn’t the only scenario used in this new campaign, though. </p><p>Unsuspecting users might be coerced into downloading a tool to their computer to do the conversion which is actually malware, or they could be tricked into installing a <a href="https://www.tomsguide.com/computing/malware-adware/chrome-and-edge-users-infected-with-malicious-browser-extensions-that-steal-your-personal-data-what-to-do-now">malicious browser extension</a> that can hijack their search history and steal their browser data.</p><p>Once installed on a victim’s computer, the malware used in this campaign can steal personal information and even Social Security numbers (SSNs), financial data like banking passwords, session tokens that can be used to bypass multi-factor-authentication (<a href="https://www.tomsguide.com/how-to/protect-online-passwords">MFA</a>) and more.</p><p>The biggest problem with this new online file converter scam is that many victims don’t realize their computers have been infected until it’s too late. Such an infection can lead to you being locked out of your computer by <a href="https://www.tomsguide.com/news/this-ransomware-makes-you-sign-up-for-roblox-to-get-your-files-back">ransomware</a> or you could even fall victim to <a href="https://www.tomsguide.com/computing/online-security/hackers-are-levelling-up-identity-theft-attacks-with-ai-heres-what-you-need-to-look-out-for">identity theft</a>.</p><h2 id="malicious-domains-to-avoid">Malicious domains to avoid</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1000px;"><p class="vanilla-image-block" style="padding-top:56.30%;"><img id="d3EL9cAmnGNKaUXy75LbeK" name="yQxZoZN8n8Q8j2JF8nEHq.jpg" alt="web URL displayed at angle on screen" src="https://cdn.mos.cms.futurecdn.net/d3EL9cAmnGNKaUXy75LbeK.jpg" mos="" align="middle" fullscreen="" width="1000" height="563" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>In a <a href="https://www.malwarebytes.com/blog/news/2025/03/warning-over-free-online-file-converters-that-actually-install-malware">blog post</a> covering this new threat, the team at <a href="https://www.tomsguide.com/computing/malware-adware/dont-click-this-malicious-ads-impersonating-google-chrome-spreading-dangerous-malware">MalwareBytes Labs</a> has put together a list of malicious domains used recently in these attacks and the specific threat they pose. These are all sites you want to actively avoid:</p><ul><li><strong>Imageconvertors[.]com</strong> - Phishing</li><li><strong>convertitoremp3[.]it</strong> - Riskware</li><li><strong>convertisseurs-pdf[.]com</strong> - Riskware</li><li><strong>convertscloud[.]com</strong> - Phishing</li><li><strong>convertix-api[.]xyz</strong> - Trojan</li><li><strong>convertallfiles[.]com</strong> - Adware</li><li><strong>freejpgtopdfconverter[.]com</strong> - Riskware</li><li><strong>primeconvertapp[.]com</strong> - Riskware</li><li><strong>9convert[.]com</strong> - Riskware</li><li><strong>Convertpro[.]org</strong> - Riskware</li></ul><p>Since hackers have a large number of domains at their disposal, the sites listed above will likely be moved to a new domain soon. Still, it’s worth looking out for these ones in particular as they have previously been used in attacks.</p><h2 id="how-to-stay-safe-from-malware-3">How to stay safe from malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wbnnjnFdxfHUZGiSFXky2S" name="computer smartphone security.jpg" alt="Best antivirus software" src="https://cdn.mos.cms.futurecdn.net/wbnnjnFdxfHUZGiSFXky2S.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>When it comes to avoiding this new threat, the FBI recommends keeping a level head and stopping to think before you click. I know this can be hard to do when someone sends you a document with the wrong file type and you need to quickly convert it, but the end result can be catastrophic if you end up at the wrong website.</p><p>Likewise, instead of searching for free file converters online, you'll want to stop and see if any of the software you already have installed has this same functionality. As I mentioned before, Microsoft Office can be used to convert files, but so can its open-source alternative OpenOffice. When it comes to PDFs, many of the <a href="https://www.tomsguide.com/best-picks/best-pdf-editors">best PDF editors</a> have this functionality built in and if you do want to go the online route, <a href="https://www.adobe.com/acrobat/online/convert-pdf.html" target="_blank">Adobe Acrobat</a> can convert a wide variety of file types to and from PDFs for free.</p><p>As for staying safe from malware downloaded accidentally online, you'll want to make sure that you’re using the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> on your PC or the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> on your Apple computer. <a href="https://www.tomsguide.com/computing/antivirus/how-does-antivirus-software-work">Antivirus software</a> scans all of your existing files for malware and can warn you when you’re about to download a file that contains malware. <br><br>For additional protection from online scams like this one, it might also be worth signing up for the <a href="https://www.tomsguide.com/us/best-identity-theft-protection,review-2083.html">best identity theft protection</a> as these services can help you recover your identity as well as any funds lost to fraud.</p><p>Hackers love to go after low-hanging fruit and online file converters are their latest way to lure unsuspecting users into infecting their own computers with malware. This is why you have to practice good cyber hygiene and educate yourself when it comes to the latest online scams. That way, you can stay safe from avoidable ones like this and teach those around you how to spot a scam before they too fall victim to one.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/new-massjacker-malware-is-hijacking-digital-wallets-to-steal-large-sums-from-users">MassJacker malware is hijacking digital wallets to steal large sums from users</a></li><li><a href="https://www.tomsguide.com/computing/antivirus/5-common-mistakes-people-make-when-shopping-for-antivirus-software">5 common mistakes people make when shopping for antivirus software</a></li><li><a href="https://www.tomsguide.com/computing/online-security/ftc-says-americans-lost-usd12-billion-to-scams-last-year-and-these-were-the-worst-ones-heres-how-to-stay-safe">FTC says Americans lost $12 billion to scams last year and these were the worst ones</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New MassJacker malware is hijacking digital wallets to steal large sums from users ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/new-massjacker-malware-is-hijacking-digital-wallets-to-steal-large-sums-from-users</link>
                                                                            <description>
                            <![CDATA[ Cryptocurrency transactions are being hijacked by a new clipper malware strain called MassJacker. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m6u7NrcbkzWb9TZCvAgVbZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Mar 2025 15:39:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker typing quickly on a keyboard]]></media:description>                                                            <media:text><![CDATA[A hacker typing quickly on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker typing quickly on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YwKRVzwvLwup6hDGh5bVNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new malware campaign is rerouting thousands of dollars from cryptocurrency transactions into the accounts of hackers. </p><p>As reported by <a href="https://thehackernews.com/2025/03/new-massjacker-malware-targets-piracy.html" target="_blank">The Hacker News</a>, the malware, called MassJacker, is a type of cryware known as <a href="https://www.tomsguide.com/computing/online-security/hackers-are-using-recaptcha-to-trick-users-into-infecting-their-own-pcs-with-malware-how-to-stay-safe">clipper malware</a> which is targeting users searching for <a href="https://www.tomsguide.com/news/nullmixer-malware-spies-on-you-and-steals-your-online-accounts-what-you-need-to-know">pirated software</a> online. </p><p>Instead of the pirated software though, they actually end up downloading clipper malware which is designed to steal cryptocurrency by watching an infected machine’s clipboard and switching out copied cryptocurrency wallet addresses for one controlled by the attackers behind this campaign.</p><p>According to a <a href="https://www.cyberark.com/resources/threat-research-blog/captain-massjacker-sparrow-uncovering-the-malwares-buried-treasure" target="_blank">new report</a> from CyberArk, the infection chain starts at pesktop[.]com which is a site commonly used to acquire pirated software that also tries to infect systems with multiple types of malware. The initial MassJacker executable acts as a conduit to run a <a href="https://www.tomsguide.com/computing/malware-adware/hackers-are-using-fake-chrome-word-and-onedrive-errors-to-trick-people-into-installing-malware-how-to-stay-safe">PowerShell script</a> for the Amadey botnet malware and two .NET binaries including one codenamed PackerE. </p><p>PackerE downloads an encrypted DLL file which then loads a second <a href="https://www.tomsguide.com/news/hackers-are-now-hiding-malicious-word-documents-in-pdfs-how-to-stay-safe">malicious file</a> that launches the MassJacker payload by injecting it into a legitimate Windows process called InstalUtil.exe. This encrypted DLL incorporates features to evade and avoid analysis including Just-In-Time (JIT) hooking, metadata token mapping, and a custom virtual machine.</p><p>MassJacker also has debugging checks and a configuration which retrieves regular expression patterns for flagging cryptocurrency wallet addresses in the clipboard; it contacts a remote server to download files containing the threat actors lists of wallets. Then, according to CyberArk's security researchers, it creates an event handler to run whenever the infected system copies anything. The handler checks the regexes, and when it finds a match it simply replaces the copied content with a wallet belonging to the hackers. </p><p>CyberArk says it has identified over 778,531 addresses belonging to the threat actors responsible for MassJacker; however, 423 of these wallets currently contain funds totaling roughly $95,300. The digital assets previously held in those wallets prior to them being transferred stands at approximately $336,700. Cryptocurrency worth $87,000 has been found being held in a single wallet, with over 350 transactions funneling money into the wallet from different addresses. </p><p>No information is available yet on who is behind MassJacker though the source code shows that it overlaps with the <a href="https://www.tomsguide.com/news/masslogger-password-stealer">MassLogger malware</a> which also used JIT hooking to resist analysis efforts.</p><h2 id="how-to-stay-safe-from-clipper-malware">How to stay safe from clipper malware</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="D8JxHKmGbugi82MYYGGRNE" name="shutterstock_1964563111-2" alt="A woman using her laptop securely with a cup of coffee in hand" src="https://cdn.mos.cms.futurecdn.net/D8JxHKmGbugi82MYYGGRNE.jpg" mos="" align="middle" fullscreen="" width="2000" height="1125" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>Just like with some other malware strains, getting infected by MassJacker is completely avoidable. As long as you're not <a href="https://www.tomsguide.com/news/look-out-those-ai-generated-youtube-tutorials-are-actually-spreading-dangerous-malware">downloading pirated software</a>, you should have nothing to worry about at least for now.</p><p>To keep your devices protected from malware that can slip through the cracks though, you should be using the <a href="https://www.tomsguide.com/us/best-antivirus,review-2588.html">best antivirus software</a> on your Windows PC or the <a href="https://www.tomsguide.com/best-picks/best-mac-antivirus">best Mac antivirus software</a> on your Apple computer. These security programs continually scan all of your existing files and any new ones you try to download for malware.</p><p>As for keeping your cryptocurrency transactions safe, it might be worth investing in one of the <a href="https://www.tomsguide.com/best-picks/best-laptops">best laptops</a> or even one of the <a href="https://www.tomsguide.com/best-picks/best-computers">best computers</a> and using that machine solely for crypto. This might sound a bit drastic but by keeping the rest of your online activity separate from your crypto transactions, you can avoid having your funds stolen by malware like MassJacker or by <a href="https://www.tomsguide.com/reference/what-are-phishing-scams">phishing attacks</a> designed to steal your <a href="https://www.tomsguide.com/computing/malware-adware/malicious-iphone-apps-are-spreading-screenshot-reading-malware-on-the-apple-app-store-how-to-stay-safe">recovery phrase</a> which you should save the old fashioned way on a piece of paper in a secure location as opposed to on your computer or in one of the <a href="https://www.tomsguide.com/us/best-password-managers,review-3785.html">best password managers</a>.</p><p>Since recovering lost cryptocurrency is almost impossible, hackers will likely continue to target crypto users online. This is why you need to be extra careful and practice excellent cyber hygiene when dealing with digital currencies.</p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/antivirus/5-common-mistakes-people-make-when-shopping-for-antivirus-software">5 common mistakes people make when shopping for antivirus software</a></li><li><a href="https://www.tomsguide.com/computing/online-security/240-million-windows-users-under-attack-update-your-pc-now-before-hackers-strike">240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now</a></li><li><a href="https://www.tomsguide.com/computing/online-security/ftc-says-americans-lost-usd12-billion-to-scams-last-year-and-these-were-the-worst-ones-heres-how-to-stay-safe">FTC says Americans lost $12 billion to scams last year and these were the worst ones — here's how to stay safe</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of TP-Link routers have been infected by a botnet to spread malware ]]></title>
                                                                                                                                                                                                <link>https://www.tomsguide.com/computing/malware-adware/thousands-of-tp-link-routers-have-been-infected-by-a-botnet-to-spread-malware</link>
                                                                            <description>
                            <![CDATA[ The Ballista botnet has infected thousands of TP-Link routers with malware. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yzA7BzoUN3sU4d3JbqWGkf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4yMSsLX6mnBnQdtmWDpokE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Mar 2025 18:15:24 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Mar 2025 13:36:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware &amp; Adware]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                    <category><![CDATA[Online Security]]></category>
                                                                                                <author><![CDATA[ amber.bouman@futurenet.com (Amber Bouman) ]]></author>                    <dc:creator><![CDATA[ Amber Bouman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/KmvVweDrSFNc52AnqCJzR.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Amber Bouman is the senior editor for security at Tom&#039;s Guide where she covers everything from home security cameras and identity theft to password breaches, password managers and antivirus software.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Previous to joining the Tom&#039;s Guide team, Amber spent two years covering parenting technology at Reviewed. She also spent five years as a parenting editor and community manager at Engadget, and has worked at TechHive, Wirecutter, Maximum PC and PC World covering smartphones, parenting tech, B2B, PC builds, tech accessories, apps and more.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;A California native, Amber currently lives in rural New England and has been testing apps and products for over fifteen years. She has worked as a consumer advocate, helping find resolutions for common customer problems. As a former comment moderator and community editor, she became invested in the topics of internet security and safety, identity theft, online disinformation and the safety of women and marginalized communities online.&amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4yMSsLX6mnBnQdtmWDpokE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person trying to set up a new Wi-Fi router]]></media:description>                                                            <media:text><![CDATA[A person trying to set up a new Wi-Fi router]]></media:text>
                                <media:title type="plain"><![CDATA[A person trying to set up a new Wi-Fi router]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4yMSsLX6mnBnQdtmWDpokE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new <a href="https://www.tomsguide.com/computing/online-security/massive-mikrotik-router-botnet-has-been-spreading-malware-heres-how-to-stay-safe">botnet</a> campaign is exploiting a high-severity security flaw in unpatched <a href="https://www.tomsguide.com/computing/routers/this-chinese-router-company-with-65-percent-market-share-in-the-us-could-be-banned-what-you-need-to-know">TP-Link routers</a> and has already spread to more than 6,000 devices. </p><p>According to a <a href="https://www.catonetworks.com/blog/cato-ctrl-ballista-new-iot-botnet-targeting-thousands-of-tp-link-archer-routers/" target="_blank">new report</a> from the Cato CTRL team, the Ballista botnet exploits a remote code execution vulnerability that directly impacts the TP-Link Archer AX-21 router. </p><p>The botnet can lead to command injection which then makes remote code execution (RCE) possible so that the malware can spread itself across the internet automatically. This high severity security flaw (tracked as <a href="https://nvd.nist.gov/vuln/detail/cve-2023-1389" target="_blank">CVE-2023-1389</a>) has also been used to spread other malware families as far back as April 2023 when it was used in the <a href="https://www.tomsguide.com/news/android-adb-matryosh-botnet">Mirai botnet</a> malware attacks. The flaw also linked to the Condi and AndroxGh0st malware attacks. </p><p>Ballista’s most recent exploitation attempt was February 17, 2025 and Cato CTRL first detected it on January 10, 2025. </p><p>Of the thousands of infected devices, the majority of them are concentrated in Brazil, Poland, the United Kingdom, Bulgaria and Turkey; with the botnet targeting manufacturing, medical/healthcare, services and technology organizations in the United States, Australia, China and Mexico. </p><h2 id="how-does-ballista-attack">How does Ballista attack</h2><p>The attack sequence is as follows: it starts with a <a href="https://www.tomsguide.com/news/new-android-malware-dropper-sneaks-past-google-protect-yourself-now">malware dropper</a>, then a shell script designed to fetch and execute the main binary on the target system for various system architectures. When executed, the malware establishes a command-and-control (C2) channel on port 82 to take control of the device. </p><p>This allows the malware to run shell commands to conduct further remote code execution and Denial of Service (DoS) attacks; it will also attempt to read sensitive files on the system. </p><p>Supported commands include flooder (triggers a flood attack), exploiter (which exploits CVE-2023-1389), start (an optional parameter used with the exploiter to start the module), close (stops the module triggering function), shell (runs a Linux shell command on the local system) and killall (used to terminate the service).</p><p>The Ballista malware is additionally capable of terminating previous instances of itself – and erasing its own presence once execution begins. It’s designed to spread to other routers by attempting to exploit the flaw. </p><p>Since both the IP address and language used have an Italian base, the cybersecurity researchers have suggested that the threat actor is of an unknown Italian origin. However, the initial IP address used is no longer functional having been replaced by a new variant utilizing <a href="https://www.tomsguide.com/computing/online-security/tor-project-releases-tor-browser-14-0-what-you-need-to-know">TOR</a> network domains. This all indicates that the malware is under active development. </p><h2 id="how-to-patch-your-tp-link-router">How to patch your TP-Link router</h2><p>Since updating your router is every bit as important as updating the apps and operating system on your phone, you should make sure to install the <a href="https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware">recommended patch</a> for your TP-Link Archer AX-21 router immediately. Regularly patching your router and making sure the firmware is up-to-date will keep your device as secure as possible which is important as routers are often one of the most frequently hacked technologies in the home. </p><p>You can see all the details about the firmware download on the <a href="https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware">TP-Link page </a>which provides full details about how to upgrade including an FAQ and a setup video. </p><h3 class="article-body__section" id="section-more-from-tom-s-guide"><span>More from Tom's Guide</span></h3><ul><li><a href="https://www.tomsguide.com/computing/malware-adware/over-one-million-android-devices-infected-with-password-stealing-pre-installed-botnet-malware-how-to-stay-safe">Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/online-security/hackers-are-using-recaptcha-to-trick-users-into-infecting-their-own-pcs-with-malware-how-to-stay-safe">Hackers are using reCAPTCHA to trick users into infecting their own PCs with malware — how to stay safe</a></li><li><a href="https://www.tomsguide.com/computing/malware-adware/fake-google-play-store-pages-are-spreading-trojan-malware-that-can-steal-your-financial-data">Fake Google Play Store pages are spreading Trojan malware that can steal your financial data</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>