AUTO-UPDATED

'This creates a misleading impression of safety': Experts warn of hackers hijacking legitimate news websites and reviews to drum up publicity

Check Point Research has identified a sophisticated malware campaign using fake press releases and social media manipulation to distribute a Rust-based clipboard hijacker targeting cryptocurrency users on Windows and macOS.

Key Points

  • Attackers use phishing sites, GitHub, and SourceForge to distribute malware disguised as legitimate software.
  • The clipboard hijacker monitors for cryptocurrency wallet addresses and replaces them with attacker-controlled strings during transactions.
  • Fake YouTube channels featuring AI-generated narrators and coordinated comments are used to build false credibility.
  • Threat actors exploit newswire services to publish press releases, lending an appearance of legitimacy to their malicious projects.
  • "Ghost Networks" of fake accounts manipulate reputation-based security platforms like VirusTotal to prevent the malware from being flagged.

Why it Matters

This campaign demonstrates a shift toward sophisticated social engineering and reputation manipulation that can bypass traditional security due diligence. By weaponizing trusted platforms and news distribution channels, attackers are successfully lowering user suspicion and increasing the effectiveness of their infostealing operations.
TechRadar Published by Sead Fadilpašić
Read original