Cybersecurity researchers have disclosed a new malicious campaign that uses a fake website advertising antivirus software from Bitdefender to dupe victims into downloading a remote access trojan called Venom RAT.
The website in question, "bitdefender-download[.]com," advertises site visitors to download a Windows version of the Antivirus software. Clicking on the prominent "Download for Windows" button initiates a file download from a Bitbucket repository that redirects to an Amazon S3 bucket. The Bitbucket account is no longer active.
DomainTools said the decoy website masquerading as Bitdefender shares temporal and infrastructure overlaps with other malicious domains spoofing banks and generic IT services that have been used as part of phishing activity to harvest login credentials associated with Royal Bank of Canada and Microsoft .
Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets
Fake Bitdefender site spreads Venom RAT via Bitbucket and Amazon S3, targeting crypto wallets and 2FA codes.
thehackernews.com
Last edited by a moderator: