Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Toobit kicks off win the world tournament, offering 1 million USDT and gold world cup trophy

June 1, 2026

Cango Posts $261.1M Q1 Loss as Bitcoin Price Slump Hits Mining Operations

June 1, 2026

‘Extraordinarily unusual’ for CFTC to reverse Gemini settlement deal: Ex-chair

June 1, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Fake Bitdefender Site Spreads Trio of Malware Tools
Fake Bitdefender Site Spreads Trio of Malware Tools
Security and Privacy

Fake Bitdefender Site Spreads Trio of Malware Tools

July 24, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A spoofed Bitdefender website has been used in a malicious campaign to distribute VenomRAT and two other malware tools, giving attackers deep access to victims’ systems.

The fake site, titled DOWNLOAD FOR WINDOWS, mimics Bitdefender’s legitimate antivirus download page but redirects visitors to malicious files hosted on Bitbucket and Amazon S3.

The downloaded package contains an executable named StoreInstaller.exe, which initiates the infection process. Researchers found this file bundled with code from three separate malware families: VenomRAT, StormKitty and SilentTrinity.

Modular Malware for Maximum Exploitation

According to DomainTools, who uncovered the campaign, it demonstrates a layered approach to compromise with each tool playing a distinct role:

  • VenomRAT ensures remote and persistent access

  • StormKitty gathers credentials and crypto wallet data

  • SilentTrinity facilitates stealthy exfiltration and long-term control

Together, these components allow attackers to move swiftly while remaining hidden.

The use of SilentTrinity and StormKitty, both open-source frameworks, suggests the attackers are targeting users not just for immediate gain but for prolonged exploitation or resale of access.

VenomRAT has roots in the Quasar RAT project and supports keylogging, credential theft and remote command execution (RCE).

The malware samples tied to this campaign share consistent configurations, particularly the reuse of command-and-control (C2) IPs like 67.217.228[.]160:4449 and 157.20.182[.]72:4449.

Analysts traced additional VenomRAT samples and IPs through matching RDP configurations, revealing further infrastructure likely managed by the same threat actor.

Read more on phishing attacks using spoofed antivirus platforms: Cybercriminals Exploit CheckPoint Antivirus Driver in Malicious Campaign

Fake Login Pages Pose Additional Risks

In addition to the spoofed antivirus site, researchers identified related phishing domains impersonating banks and IT services. These include:

  • idram-secure[.]live, spoofing Armenian IDBank

  • royalbanksecure[.]online, mimicking Royal Bank of Canada

  • dataops-tracxn[.]com, posing as a Microsoft login portal

See also  Online Thieves Steal $320m from Crypto Firm Wormhole

The infrastructure behind these domains overlaps in timing and setup, reinforcing the assessment of a coordinated, financially motivated campaign.

Growing Use of Open-Source Malware

The attackers’ reliance on open-source tools shows how accessible cybercrime has become. By repurposing existing frameworks, they can quickly assemble flexible, effective malware kits. While this can help defenders recognize patterns, it also increases the speed and scale of potential attacks.

DomainTools researchers emphasize vigilance and encourage users to verify download sources, avoid entering credentials on untrusted sites and remain cautious with email links or attachments.

Image credit: T. Schneider / Shutterstock.com

Source link

Bitdefender fake Malware Site Spreads Tools Trio
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Ads3 and MarsCat Merge AI Growth Tools with Privacy-First Web3 Socials

May 31, 2026

SEC sues Texas man over $12.3 million alleged crypto scheme built on fake AI trading bots

May 30, 2026

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026

Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

May 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Here’s How High The Ethereum Price Would Be if It Matches The Market Cap Of Gold

May 20, 2026

Positive Net Profit Amid Current Market Conditions

June 3, 2023

Binance denies claims of dumping Ethereum and Solana

February 26, 2025

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Toobit kicks off win the world tournament, offering 1 million USDT and gold world cup trophy

June 1, 2026

Cango Posts $261.1M Q1 Loss as Bitcoin Price Slump Hits Mining Operations

June 1, 2026

‘Extraordinarily unusual’ for CFTC to reverse Gemini settlement deal: Ex-chair

June 1, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$71,443.00-2.82%
  • ethereumEthereum(ETH)$1,966.41-1.99%
  • tetherTether(USDT)$1.00-0.02%
  • binancecoinBNB(BNB)$677.57-5.85%
  • rippleXRP(XRP)$1.28-3.47%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$79.52-2.89%
  • tronTRON(TRX)$0.346877-0.47%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.052.42%
  • HyperliquidHyperliquid(HYPE)$70.904.17%