• Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
Tutorial News Comments FAQ Related Articles

Vidar and CryptBot Trojans Spead Via Fake VPN Site

{{postValue.id}}

A fake VPN called Inter VPN website is found to have been distributing the Vidar and CryptBot password-stealing Trojans and steal the login credentials that are saved in the browser cache but can also tap into other parts of the system too.

Claiming to be the fastest VPN solution, protecting your privacy and anonymity online the fake VPN site uses an image from a legitimate VPN product (VPN Pro), to convince the victim to download and install it.

If the website visitor downloads the program, they’ll get a repackaged VPN Pro that is infected with a payload downloader. The “AutoHotKey” script connects to “iplogger.org” and downloads either the Vidar or the CryptBot executables from “bitbucket.org”. The choice between the two is up to the actor and the campaign that is running at the time of the infection. Once downloaded, the Trojans will begin looking in the saved browser credentials and the cookies. Besides these, they also look into text files, cryptocurrency wallets, and even take screenshots to hopefully grab the username or password, or both.

All of this nasty stuff is taking place in the background, so the victim is unlikely to realize anything. VPN Pro works as expected, and since it’s free, there is nothing to compel the user to replace it after the trial period ends, etc. That said, victims could be using “Inter VPN” for long, losing all their sensitive information to the malicious actors after allowing them multiple opportunities to grab it. These products are mainly promoted via forums and social media posts and attempt to persuade people to give them a try through fake reviews and various bold claims about their awesomeness.

Tags:
matthew
Author: 

Comments ( 0 )

No comments available

Add a comment
{{postCtrl.cmtErrMsg}}

Frequently asked questions ( 0 )

No questions available

Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Gibbson ?
How do i run both nginx and apache in same instance on centos

Hi...,

my server is based centos operating system and my webserver is already running on Apache.... i need to run both apache and nginx on same instance ... please help me to implement this concept...

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.