Antivirus

Spyware found stealing Iranian user data via infected VPN installer

Audio player loading… Spyware has been discovered stealing Iranian users data via an infected VPN installer, antivirus provider Bitdefender has revealed. The company’s joint-research with cybersecurity firm Blackpoint found components of Iranian-made EyeSpy malware to be injected “through Trojanized installers of VPN software (also developed in Iran).”  The majority of targets were within the country’s borders,…

Audio player loading…

Spyware has been discovered stealing Iranian users data via an infected VPN installer, antivirus provider Bitdefender has revealed. 

The company’s joint-research with cybersecurity firm Blackpoint found components of Iranian-made EyeSpy malware to be injected “through Trojanized installers of VPN software (also developed in Iran).”  

The majority of targets were within the country’s borders, only a few victims were found to be based in Germany and the US. 

This is particularly concerning in a country like Iran, where using one the best VPN services has increasingly become a necessity. Whether this is for bypassing its strict online censorship, or preserving anonymity to avoid dangerous government surveillance. Most likely, a mix of both.  

At the same time, a harsh crackdown on Iranian VPN services might push people towards unsecure third-party vendor sites. This makes such a spyware campaign even more dangerous for Iranians’ privacy and security.    

Anti-dissident spware?

“In light of the recent events, it’s possible that the targets are Iranians who want to access the internet via a VPN to bypass the country’s digital lockdown. Such malicious installers could plant spyware on people who pose a threat to the regime,” Bitdefender’s report (opens in new tab) noted. 

Developed by Iranian-based firm SecondEye, EyeSpy is a legit monitoring software sold to businesses as a way to monitor employees’ activities working remotely.  

The attackers were observed using components of the legit application in a malicious way to infect users’ downloading the Iranian-based VPN service 20Speed and spy on their activities.     

Once injected into a device, the malware can virtually spy on every activity and collect a tons of sensitive data. These include stored passwords, crypto-wallet data, documents and images, contents from clipboard, and logs key presses. 

“The components of the malware are scripts that steal sensitive information from the system and upload them to an FTP server belonging to SecondEye,” Bitdefender explained.

Read more

> State-backed Iranian hackers spread malware through links to fake VPN apps (opens in new

Read More

Be the first to write a comment.

Leave a Reply

Antivirus

Feds bust two fake antivirus sellers for millions in fraud

If you frequent certain portions of the internet, you’ve almost certainly seen pop-ups warning you that your PC is infested with all manner of creepy-crawly viruses. The ad is fake, and so is the software that it asks you to pay for, according to a new Federal Trade Commission lawsuit against a pair of phony

If you frequent certain portions of the internet, you’ve almost certainly seen pop-ups warning you that your PC is infested with all manner of creepy-crawly viruses. The ad is fake, and so is the software that it asks you to pay for, according to a new Federal Trade Commission lawsuit against a pair of phony antivirus sellers…
Read More

Continue Reading
Antivirus

Protect your computer from viruses for just $25

The 2024 edition of the ESET NOD32 Antivirus software features anti-phishing protection, malware blocking, and more…

The 2024 edition of the ESET NOD32 Antivirus software features anti-phishing protection, malware blocking, and more…
Read More

Continue Reading
Antivirus

Avast One review: Well-priced PC security with excellent protection

At a glanceExpert’s Rating ProsClean, uncluttered interfaceExcellent antivirus protectionWell-priced for its feature setConsFull scans affect PC performance when using Microsoft Office appsNo included password managerOur VerdictAvast One expands upon the company’s free security suite, with upgraded defenses against online threats and additional features. You don’t get just excellent antivirus protection…

At a glanceExpert’s Rating
ProsClean, uncluttered interfaceExcellent antivirus protectionWell-priced for its feature setConsFull scans affect PC performance when using Microsoft Office appsNo included password managerOur VerdictAvast One expands upon the company’s free security suite, with upgraded defenses against online threats and additional features. You don’t get just excellent antivirus protection…
Read More

Continue Reading
Antivirus

DeFi Exploits in February Cause Losses of $82 Million With Just $1.3 Million Recovered: Report

A report sent to Cryptonews by web3 app and antivirus solution De.Fi noted that $82,287,101 was lost in February 2024 from security incidents, with just $1,325,932 recovered. The post DeFi Exploits in February Cause Losses of $82 Million With Just $1.3 Million Recovered: Report appeared first on Cryptonews…

A report sent to Cryptonews by web3 app and antivirus solution De.Fi noted that $82,287,101 was lost in February 2024 from security incidents, with just $1,325,932 recovered.
The post DeFi Exploits in February Cause Losses of $82 Million With Just $1.3 Million Recovered: Report appeared first on Cryptonews…
Read More

Continue Reading