Malware Bytes
Grok fooled into stealing user chat, location data, and more
A new type of prompt injection attack shows why giving AI assistants access to browsers, code tools, and private data deserves extra caution.
AI researchers describe “Cryptographic Context Injection”—an attack that hides malicious instructions inside encrypted data. The AI is then persuaded to decrypt that data using its own code-execution tool. As a result, the AI may treat the resulting text as if it were trustworthy internal information.
A prompt injection is a bit like leaving a fake instruction inside a document for an AI assistant to read. Instead of following only the user’s request, the assistant may be tricked into following an attacker’s instructions hidden in a webpage, email, or file.
As we reported months ago, experts have warned that prompt injection attacks are a problem that may never be fixed. Prompt injection works because AI models can’t reliably tell the difference between the legitimate instructions and an attacker’s instructions, so they sometimes obey the wrong ones.
To reduce this risk, AI providers set up their models with guardrails: protections designed to stop AI systems from doing things they shouldn’t, either intentionally or unintentionally.
What the researchers found was that malicious instructions could be hidden from some AI guardrails by encrypting them. The AI itself could then be tricked into decrypting those instructions using its coding tools.
By the time the instructions became readable, they had already made it past the initial security checks. The AI could then mistake them for legitimate instructions and follow them.
It’s a bit like hiding malicious instructions in a language the security system can’t understand. The AI translates them only after they’ve passed the security checks, then may follow what they say.
The researchers tested their method against two AI agents, with different results. In Grok, the researchers say the attack could steal information including the user’s name, approximate location, subscription tier, and conversation history. In Gemini, they used the technique to bypass safety controls and generate content the model would normally not do.
“In Grok, an ordinary ‘summarize this page’ steals the user’s chat data with no click or warning. In Gemini, it produces content the model normally refuses. Both are live production systems.”
The researchers did not provide full details because xAI had not taken action after the flaw in Grok was reported to it in June 2026. Gemini, on the other hand, has made improvements, but has still not fully closed the hole.
How to stay safeAn AI assistant may be helpful, but it should not automatically be trusted with sensitive data or powerful tools.
- Treat AI summaries of unfamiliar webpages, documents, and shared links with caution, especially when the assistant can browse or run code.
- Do not paste passwords, recovery codes, API keys, financial information, or sensitive health and work details into AI chats unless you understand how that information will be handled.
- Review an AI assistant’s connected tools and permissions. Remove access it doesn’t need, particularly email, cloud storage, source-code repositories, and external integrations.
- Be skeptical if an AI tool asks to decrypt, decode, run a script, open a new link, or upload data as part of a seemingly ordinary task.
- Keep browser and AI applications updated, and check vendor security advisories when using features such as browsing, autonomous agents, or code execution.
- Use an up-to-date, real-time anti-malware solution to detect and block malicious downloads and suspicious connections.
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
GTA 6 leak hunt could expose data belonging to thousands of Discord users
Someone leaked footage of the upcoming game Grand Theft Auto (GTA) 6 this month, and the game’s publisher badly wants to know who. It’s after a range of data about members of three Discord servers going back to June 1 this year in a bid to nail the perpetrator.
Take-Two Interactive, the publisher behind the GTA series, hit Microsoft and Discord with a subpoena on August 20. It’s demanding IP addresses, phone numbers, linked Google and Xbox accounts, and OneDrive contents of certain server members. It’s also after their MachineGuid values and Microsoft account device IDs, which identify individual Windows installations and devices that access Microsoft services, respectively.
An account calling itself CyberLeek started publishing game footage on August 17 and also revealed some of the game’s map. It claims ideological motives, publishing a manifesto with three commandments. In brief, it wants publishers to stop publishing digital-only versions of games, stop making players pay extra to unlock single-player content shipped with the base game, and guarantee to preserve single-player modes forever.
CyberLeek warned game publishers:
“Behave, or be the next target.”
Around the same time, CyberLeek also launched a cryptocurrency token called $CYBERLEEK on the Solana network, which it promoted as a way for users to vote on what game footage would be leaked next.
Online commentators accused CyberLeek of using the GTA 6 leaks to pump the value of its cryptocurrency token. However, rather than selling its large holding, the person or people behind CyberLeek “burned” it on Sunday, effectively erasing the tokens. However, they can still collect trading fees from the toke , which reportedly reached up to $60,000 last week.
Who the sweep catchesTake-Two’s Discord subpoena covers servers including one belonging to Australian GTA 5 streamer Matthew Judge, better known as DarkViperAU. He posted on X that he had nothing to do with the event and didn’t know anything about it.
Microsoft and Discord have until September 4 to hand over the data. If they comply, potentially hundreds or thousands of people with no known connection to the leaks could have identifying information handed over to Take-Two as part of its investigation.
Other attacks on Take-TwoThis isn’t the first hacking incident that Take-Two and its game studio subsidiary Rockstar have faced. In April, the ShinyHunters cybercrime crew stole 78.6 million Rockstar records without directly compromising any of the company’s internal systems.
Rather than compromising Rockstar, ShinyHunters targeted Anodot, a cloud analytics vendor that held persistent authentication tokens for its customers’ Snowflake cloud database environments.
Persistent authentication tokens are what some software gives you after you’ve proven your credentials once so that you don’t have to go through the login process again. They’re convenient, but the danger is that if someone gets hold of one, they can impersonate you without needing your password.
Gaining access to victims’ data by compromising third-party service providers holding that data is the ShinyHunters gang’s modus operandi.
Neither is this the first time that GTA material has been leaked. In September 2022, a hacker posted video footage of GTA 6 online.
What does all this mean to you? If you’re a gamer, then it means being diligent. GTA’s popularity tends to spawn scams online. The game’s popularity has attracted scammers fraudulently touting free in-game money, malware-filled mods, and more recently, offers of free early access designed to part you with the contents of your crypto wallet.
Real leaked footage can make scams more convincing to gamers who want to see more. Yesterday, Malwarebytes researchers found fake GTA 6 Extended Look and demo sites that lead visitors to password-stealing malware.
Don’t believe offers of early access or downloadable GTA 6 demos. The only safe bet is a direct pre-order from Rockstar. Otherwise, keep your powder dry (and your money safe) until the actual game lands on consoles in November. PC players will have to wait a little longer.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
TikTok phishing: How to spot fake login and verification pages
Phishing pages don’t need to be sophisticated. They just need to look convincing enough to make you trust them.
TikTok phishing often starts with an email or message designed to make you think you need to act on your account. It might claim your account has been suspended, reported, or hit with a copyright violation, or tell you that you’re eligible for verification.
The link might take you directly to a page made to look like TikTok’s login screen. If you enter your information, it can be sent straight to the scammers, including your phone number or email, password, and potentially a one-time authentication code.
With access to your account, scammers could impersonate you, target your contacts, or try to use the same password to break into your other accounts.
What to do if you get a suspicious TikTok messageIf you get an unexpected email or message telling you to log in to TikTok, don’t use the link it provides. Open the real TikTok app or go directly to tiktok.com instead and check your account there.
If you’ve already entered your login information on a suspicious page, change your TikTok password immediately and check for any devices or login activity you don’t recognize.
Fake warnings and verification offersNot every TikTok phishing link leads directly to a fake login screen. Some try to scare you with claims that your account has been suspended or reported, or that you’ve received a copyright or community-guidelines strike that needs “resolving.” Others offer something you might want, such as a verified badge, creator payout, or brand deal.
For example, a fake TikTok Verification Center might congratulate you on your performance and tell you that you’re eligible for a verified badge:
Another fake verification page asks for account information as part of a supposed verification request:
Whether the message threatens you with a problem or promises you a reward, the aim is the same: to persuade you to interact with a fake TikTok page and hand over information.
Why these TikTok scams workFake TikTok pages can look convincing because copying the appearance of a real website is relatively easy. But the story that gets you there is just as important.
Suspension and copyright warnings create urgency. Verification and monetization offers create an incentive. Both give you a reason to act quickly instead of stopping to check where the link has actually taken you.
How to protect your TikTok account- Don’t use links in unexpected emails or messages asking you to log in to TikTok. Open the TikTok app or go directly to tiktok.com instead
- Treat any message about a suspension, strike, or verification eligibility as unverified until you’ve confirmed it inside the TikTok app itself
- Check the address bar before entering your login information. Make sure you’re actually on tiktok.com—a fake page can look almost identical to the real thing
- Use a password manager where possible. It won’t auto-fill your TikTok password on a different domain, which is a useful warning sign
- Turn on two-factor authentication (2FA) on your real TikTok account so a stolen password alone isn’t enough to get in
- If you’ve already entered your login information on a page like this, change your TikTok password immediately and check for any login activity or devices you don’t recognize
- Use Malwarebytes Mobile Security to help block phishing and malicious websites on your phone
Whatever story the message tells you, don’t use its link to log in. Open TikTok yourself and check your account there.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
Fake GTA 6 Extended Look and demo sites deliver an infostealer
GTA 6 footage really has leaked online, and Rockstar has an official Extended Look coming to Netflix on August 27. But cybercriminals are exploiting the hype with fake Rockstar sites that lead visitors to password-stealing malware.
We identified a network of sites appearing in searches for a GTA 6 demo and impersonating Rockstar Games. One Google result advertises an “Official Download,” but visitors who follow the sites’ “Play Now” links can instead end up downloading gta6_installer.exe.
The sites are particularly convincing because they copy Rockstar’s genuine promotion for its August 27 extended look at GTA 6. But the executable they deliver isn’t a demo, game, or video. It’s an information stealer designed to take passwords stored in browsers, cookies, and authenticated sessions. And because stolen browser sessions can sometimes be reused without going through the normal login process, even two-factor authentication (2FA) may not be enough to stop them.
One of the fake GTA 6 demo websites impersonating Rockstar Games There is no GTA 6 demoRockstar has not announced or released a demo of Grand Theft Auto VI.
The game is scheduled for release on November 19, 2026, for PlayStation 5 and Xbox Series X|S. Rockstar has not announced a PC version.
Rockstar has announced an extended look at GTA 6 for August 27, premiering on Netflix before appearing on its YouTube channel later that day. That’s something to watch, not a playable demo or game download.
The scam sites copy this genuine announcement while using “Play Now” buttons that can lead visitors to the malicious executable.
The site copies Rockstar’s genuine Extended Look promo, but adds a fake “Play Now” buttonIn other words, there is no legitimate GTA 6 demo or PC build to download. This isn’t the first fake GTA 6 offer we’ve seen. Earlier this year, scammers were charging people hundreds of dollars for fake GTA 6 early access.
The file size should also immediately raise suspicion. The executable delivered by these sites is just 1.1 MB. That is nowhere near enough to contain a modern AAA game. In fact, the screenshot we took of one of the websites is larger than the file it was offering.
The supposed GTA 6 installer is just 1.1 MB The leak created the openingOn August 18, new GTA 6 gameplay footage and what appears to be a complete map of Leonida, the game’s setting, began circulating online. A person or group calling itself Cyberleek claimed responsibility.
Rockstar and Take-Two responded with takedowns, with Take-Two filing DMCA subpoenas seeking records from Microsoft and Discord that could help identify whoever is behind the leaks.
The malicious gta6_installer.exe sample was first spotted on August 19, just one day after the first Cyberleek material began circulating.
Apparently genuine unauthorized GTA 6 material was already circulating, giving people searching for leaked footage, maps, or unofficial builds reason to believe there might be more out there.
But genuine leaks weren’t the only thing competing for that attention. Leaked clips carried promotional material for a cryptocurrency token associated with Cyberleek, while Cyberleek’s website solicited cryptocurrency donations and offered paid advertising placements in future GTA 6 videos. AI-generated and recycled footage was also being presented on social media as fresh leaks.
One of the fake GTA 6 sites appearing in Google search results alongside legitimate GTA 6 coverageThis isn’t the first time GTA 6 has been caught up in a major leak. In 2022, Rockstar confirmed that an attacker had stolen and published development footage of the game.
Leaks create exactly the kind of environment malware operators can exploit: huge demand for unofficial material, mixed with fakes, promotions, scams, and genuine leaks that can all be made to look remarkably similar.
The fake GTA 6 demo is another part of that ecosystem, but one designed to steal passwords and logged-in browser sessions.
What the file actually doesThe installer belongs to the Vidar family, a well-established infostealer we’ve seen in other recent malware campaigns that is sold as a service to cybercriminals. Malwarebytes detects this sample, and blocks the websites and network infrastructure associated with the campaign.
Vidar is designed to steal the information browsers remember for you. That could give attackers access to accounts including your email, social media, gaming, and shopping accounts.
In this sample, it went looking for:
- Saved passwords and login details
- Session cookies
- Browsing and download history
- Autofill and other saved browser profile data
- Credentials stored by FTP clients
Our analysis showed 19 browser targets, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also searched Thunderbird profile directories and targeted Perplexity’s Comet browser and the WebView2 browser embedded inside Roblox Studio.
The behavior report showed no persistence mechanism designed to make the malware survive a reboot. We observed no startup entry, scheduled task, or installed service that would relaunch it automatically.
But an infostealer doesn’t need to remain on your computer to cause lasting damage. Once passwords or session tokens have been stolen, attackers can continue trying to use them after the malware itself is gone.
That is one reason an infection can be easy to miss. In our analysis, it produced no visible user-facing window and installed nothing that a user would normally notice. From the victim’s perspective, the supposed GTA 6 installer may simply appear to do nothing.
Why changing your password might not be enoughIf you use a password manager and unique passwords, you might assume there is little useful information for a stealer to take directly from your browser.
Session cookies change that.
When you sign in to a website, the site gives your browser a session token that tells it you have already authenticated. That is why you do not have to enter your password every time you open another page.
If an attacker steals a usable session token, they may be able to reuse that authenticated session without going through the normal login process again.
That matters for 2FA too. 2FA protects the login process, but a stolen session was created after that login had already succeeded. Depending on the service and its security controls, an attacker may therefore be able to reuse the session without being asked for your password or 2FA again.
This is why changing your password after a stealer infection may not be enough by itself. A password change does not necessarily invalidate every existing session.
You should also use the service’s option to sign out everywhere, revoke active sessions, or remove unfamiliar devices.
How to protect yourself- Check it’s official. Do not assume an unofficial “demo,” beta, early build, or leaked version is legitimate just because a game has not launched yet. Check the publisher’s official website and store pages first.
- Use official download sources. Download games and demos only from official sources such as Steam, the Epic Games Store, PlayStation Store, Xbox, or the publisher’s own website.
- Check the file size. A one-megabyte executable cannot contain a modern AAA game.
- Don’t trust search results. Attackers can buy advertisements and optimize malicious pages for exactly the terms people search during major news events.
- Don’t trust appearances. Official artwork, logos, screenshots, and page layouts are easy to copy.
- Be careful with leaked material. By definition, there is no official distribution channel to tell you which download is genuine. If what you want is GTA 6 footage, Rockstar’s official Extended Look arrives on August 27.
- Block malicious sites. Malwarebytes Browser Guard blocks malicious pages like these before they load, helping stop the attack before a download ever reaches your computer.
If you downloaded and ran a supposed GTA 6 demo installer, assume credentials and active browser sessions on that computer may have been compromised.
Work through the following steps:
- Scan the affected computer with Malwarebytes or another trusted security product and remove anything it detects.
- Use a clean device to change important passwords, starting with your primary email account, followed by banking, payment services, and accounts tied to your identity.
- Sign out of active sessions everywhere you can. Look for options such as “sign out everywhere,” “log out of all devices,” or “active sessions.” This is what deals with stolen session cookies and tokens.
- Check your accounts for changes you did not make, including new email forwarding rules, recovery addresses, phone numbers, authorised applications, and unfamiliar devices.
- Enable two-factor authentication on accounts that don’t already have it.
- Monitor important accounts closely for unusual activity over the following weeks.
Check gaming accounts as well. Steam, Epic, and similar accounts can contain saved payment methods, valuable inventories, and access to other services.
Technical details It uses your own browser to unlock your dataBrowsers increasingly use stronger encryption and application-level protections for saved passwords and cookies. In particular, Chromium-based browsers have made it harder for unrelated software to simply copy a database and decrypt everything directly.
This sample uses a different approach.
During our analysis, it launched the actual Chrome, Edge, and Firefox executables installed on the system. It started them in headless mode, disabled logging, and pointed each one at a temporary user-data directory.
In other words, it was not launching a fake browser. It was using legitimate browser binaries already trusted by the system.
The point is to work through a browser process that can access its own protected data rather than trying to defeat those protections from the outside.
Afterward, the malware issued commands to delete the temporary browser directories it had created.
The protection has not necessarily been broken. It has been approached through software that is already allowed to use it.
That is an important distinction, because browser-level encryption makes credential theft harder, but it cannot make running an unknown executable safe.
The delivery address can come from a social media profileVidar has a well-documented habit of using what researchers call dead-drop resolvers.
Instead of relying only on a command-and-control address permanently embedded in the malware, Vidar variants can retrieve the current destination from attacker-controlled profiles hosted on legitimate services such as Telegram and Steam.
This makes the infrastructure easier to rotate: operators can update a profile instead of rebuilding and redistributing the malware.
The activity we observed is consistent with that pattern.
The sample contained profile URLs for Telegram, Pinterest, and Steam Community, and network connections to all three services were observed during analysis.
It also communicated with attacker infrastructure. Most notably, it sent multipart POST requests to ses.1001gacor.org.
The sample also established a TLS connection to ket.sm188daftar.mom.
The important point is that traffic to a legitimate service such as Telegram, Pinterest, or Steam can blend in with ordinary network activity. Blocking one malicious server is also less useful when the malware has another place it can check for updated infrastructure.
The Telegram profile used by the malware Indicators of compromise (IOCs)Distribution sites
gta6demo[.]asia
gta6demo[.]eu
gta6demo[.]us
rockstar-gta-6[.]com
File hash (SHA-256)
a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0 (gta6_installer.exe)
Dead-drop resolver URLs
telegram[.]me/m1duus
t[.]me/m1duus
pinterest[.]com/m1duus
steamcommunity[.]com/profiles/76561198657426610
Network infrastructure observed in this sample
ses.1001gacor[.]org
ket.sm188daftar[.]mom
Additional Vidar infrastructure
ket.1001gacor[.]org
ljr.1001gacor[.]org
nhg.1001gacor[.]org
bob.1001gacor[.]org
kra.1001gacor[.]org
brr.1001gacor[.]org
sto.1001gacor[.]org
rex.1001gacor[.]org
bib.1001gacor[.]org
ges.1001gacor[.]org
tax.11gokil[.]org
sii.11gokil[.]org
zaf.11gokil[.]org
dez.11gokil[.]org
tax.sm188dnsx[.]top
sii.sm188dnsx[.]top
zaf.sm188dnsx[.]top
According to CNET. Read their review →
Fake Microsoft security scans trick victims into uninstalling their antivirus
A wave of websites is offering to check whether your antivirus is working. They call themselves SysScan, carry Microsoft branding, and all reach the same conclusion: Your computer has serious problems, and the cause is the antivirus software you installed.
Windows, they claim, no longer supports third-party antivirus. Uninstall it immediately.
That is false, and it is the first step in a refund scam designed to get victims onto the phone, remove their security software, and ultimately hand over personal, banking, and remote-access information.
We found eleven of these sites on a single host. Although the names vary, the sites work in essentially the same way: Run a convincing-looking but fake security scan, tell the victim their antivirus is causing problems, collect their information, and prepare them for a supposed refund call.
What to know if you see one of these scansA website cannot run a real security scan. It can only read basic browser data like your operating system, screen size, and approximate location—not check for malware, memory issues, or missing security patches.
Microsoft still supports third-party antivirus software, and legitimate refunds never require you to uninstall security tools or install remote-access software.
If a site tells you to do any of that, close it immediately.
Technical analysis The scan reads real data and draws invented conclusionsPart of what makes the scam convincing is that the page does measure some real things.
It reads information that a browser legitimately exposes—your user agent, screen dimensions, device memory, processor count, permission states, network information, available web features, and some page performance timings. That allows the results to appear specific to your machine.
But the security conclusions aren’t connected to those measurements.
Fifty of the findings are fixed text written into the page, grouped in blocks that the developer labelled as fake checks.
Among them are claims that your browser sandbox is compromised, kernel page-table isolation is inactive, your memory is vulnerable to Rowhammer, no Trusted Platform Module was found, WebRTC is leaking your local IP address, and your processor is thermally throttled.
A web page cannot determine those things.
One finding even reports how many days behind your security patches are, using a random number generated whenever that check runs. Run the scan again and you get a different answer.
Even checks that use genuine information are twisted into warnings. An encrypted connection becomes a downgrade risk. Cookies enabled is a warning; cookies disabled is a failure. Ordinary features found in modern browsers are flagged as ways to identify you.
Our fully updated test browser was reported as possibly outdated.
Most tellingly, the score is constrained in the code to between 13 and 30 out of 100. It cannot report anything above 30, regardless of the computer being tested.
Passing is not a possible outcome.
Why the scam tells you to uninstall your antivirusTelling someone to remove their antivirus is the most consequential thing these pages do, and it serves the scammers in two ways.
First, it removes software that could interfere with what comes next, including remote-access software and anything installed during the session.
Second, it tells the scammers which security product the victim uses.
The site records which antivirus was removed from a list of 28 named products, plus an Other option. Enterprise security software also appears on the list, suggesting the scam is also prepared for people using work computers.
The claim is made more believable by distorting something that is true. Windows includes its own antivirus protection, Microsoft Defender Antivirus. When a compatible third-party antivirus product is installed, Defender can move into a passive state because the other product is providing protection.
That does not mean Windows no longer supports third-party antivirus.
The form appears built for the scammer, not the victimAfter the scan, the site presents a customer information form.
It collects a name, address, phone numbers, email address, refund amount and reason, bank name, cryptocurrency username, antivirus product, and the ID and password for a remote-access session. Users can choose from 30 different remote-access tools.
It also requires an Agent ID, Agent Name, and Company.
Those fields strongly suggest the form is designed to be filled in by an operator during a call, potentially while they can see the victim’s screen. The code does not prove who types the information, but there is little reason for agent details to appear on a form intended solely for a customer.
One field even asks whether explicit content is involved. Embarrassment and shame can be powerful tools for scammers because victims may become less willing to discuss what happened with a partner, family member, or bank.
When the form is submitted, the browser bundles the customer, agent, remote-access, antivirus, and banking details into a single message and sends it directly to Telegram’s bot API.
There is no application backend involved, making the sites cheap to host and easy to abandon when they attract attention.
It also exposes another lie. The site states in several places that no data is sent and nothing is collected. Even before the form is submitted, it contacts external IP and geolocation services. Once the form is submitted, the information entered is sent to a Telegram group chat.
Then comes the supposed refund callAfter submitting the form, the victim is sent to a page saying a refund manager will call within three to five minutes.
The page plays a looping video of a man in an office and prevents the victim from pausing it, switching it to full screen, or opening the right-click menu.
.kadence-column455177_36c2bb-be{max-width:700px;margin-left:auto;margin-right:auto;}.wp-block-kadence-column.kb-section-dir-horizontal:not(.kb-section-md-dir-vertical)>.kt-inside-inner-col>.kadence-column455177_36c2bb-be{-webkit-flex:0 1 700px;flex:0 1 700px;max-width:unset;margin-left:unset;margin-right:unset;}.kadence-column455177_36c2bb-be > .kt-inside-inner-col,.kadence-column455177_36c2bb-be > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-column455177_36c2bb-be > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-column455177_36c2bb-be > .kt-inside-inner-col{flex-direction:column;}.kadence-column455177_36c2bb-be > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-column455177_36c2bb-be > .kt-inside-inner-col:before{opacity:0.3;}.kadence-column455177_36c2bb-be{position:relative;}@media all and (min-width: 1025px){.wp-block-kadence-column.kb-section-dir-horizontal>.kt-inside-inner-col>.kadence-column455177_36c2bb-be{-webkit-flex:0 1 700px;flex:0 1 700px;max-width:unset;margin-left:unset;margin-right:unset;}}@media all and (max-width: 1024px){.kadence-column455177_36c2bb-be > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}@media all and (max-width: 767px){.wp-block-kadence-column.kb-section-sm-dir-vertical:not(.kb-section-sm-dir-horizontal):not(.kb-section-sm-dir-specificity)>.kt-inside-inner-col>.kadence-column455177_36c2bb-be{max-width:700px;-webkit-flex:1;flex:1;margin-left:auto;margin-right:auto;}.kadence-column455177_36c2bb-be > .kt-inside-inner-col{flex-direction:column;justify-content:center;}} .kadence-column455177_e97529-df > .kt-inside-inner-col{padding-top:var(--global-kb-spacing-xs, 1rem);padding-right:var(--global-kb-spacing-xs, 1rem);padding-bottom:var(--global-kb-spacing-xs, 1rem);padding-left:var(--global-kb-spacing-xs, 1rem);}.kadence-column455177_e97529-df > .kt-inside-inner-col,.kadence-column455177_e97529-df > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-column455177_e97529-df > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-column455177_e97529-df > .kt-inside-inner-col{flex-direction:column;}.kadence-column455177_e97529-df > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-column455177_e97529-df > .kt-inside-inner-col{background-color:#f8f4f4;}.kadence-column455177_e97529-df > .kt-inside-inner-col:before{opacity:0.3;}.kadence-column455177_e97529-df{position:relative;}@media all and (max-width: 1024px){.kadence-column455177_e97529-df > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}@media all and (max-width: 767px){.kadence-column455177_e97529-df > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}TRANSCRIPT
==========
Thank you for completing the form.
Your request has been successfully received and is now being reviewed.
A refund manager will be contacting you shortly to verify your information and assist with the next steps.
Please remain available to answer your phone.
We appreciate your patience.
Please keep your phone nearby and be prepared to answer the call so we can process your request as quickly as possible.
Thank you for choosing our services.
The apparent purpose is to keep the victim on the page while contact is arranged and reassure them that an official process is underway.
Whether the caller is a different scammer is not something the code can tell us, but the structure creates a clear handover point.
By the time anyone starts asking about bank details, the victim has already seen a Microsoft-branded security scan, been told their computer has serious problems, removed their antivirus, and entered information into what appears to be an official refund process.
The site shows signs of AI-generated codeThe video on the waiting page is synthetic, and the clip is zoomed and cropped inside its frame.
The code points in a similar direction. It is heavily commented in the explanatory, self-narrating style often produced by AI coding tools, including notes explaining why the scan is deliberately paced and why spoken lines use a terse security-console tone.
Some comments describe the deception directly. Eight blocks of invented findings are labelled as fake, while around 20 checks that read genuine values are described as exaggerated.
One comment near the top of the file even states that no data leaves the device, a few hundred lines before the function that sends the form to Telegram.
Source code cannot prove how it was created. But the fraud-specific elements—including the US bank list, agent identifiers, and explicit-content field—appear to have been fitted into a broader scanner template.
How to spot a fake computer security scanThere are several warning signs that give scams like this away:
- A website claims to find deep problems with your computer. A web page can see some information your browser provides, but it cannot inspect things such as your firmware settings, antivirus status, memory vulnerabilities, or exact Windows patch level.
- Every result is bad. A diagnostic that cannot produce a passing result isn’t really diagnosing anything.
- You’re told to uninstall your antivirus. Microsoft continues to support third-party security software on Windows.
- You’re asked to install remote-access software. Legitimate refunds do not require someone to take control of your computer.
- You’re asked for banking or cryptocurrency information. A legitimate company should not need remote access or cryptocurrency to process a refund.
- The page relies on a familiar logo. A Microsoft or Apple logo on a website does not mean the company operates it. These sites can switch branding depending on the operating system they detect.
If you’ve installed remote-access software or allowed someone to control your computer, disconnect the computer from the internet and remove the remote-access tool.
Reinstall the antivirus software you were told to remove, update it, and run a full scan.
If you gave the scammers banking information or allowed them to access your online banking, contact your bank immediately using a phone number you look up yourself. Tell them you may have been targeted by a refund scam.
Change your email and banking passwords from a different, trusted device.
If money was taken, report the scam to the Federal Trade Commission (FTC) at reportfraud.ftc.gov and the FBI’s Internet Crime Complaint Center (IC3) at ic3.gov.
And don’t let embarrassment stop you from telling your bank or someone you trust what happened. Creating that embarrassment can be part of the scam because it makes victims less likely to ask for help. Acting quickly gives you the best chance of limiting any loss.
Indicators of compromise (IOCs)Hosting: 157.230.180.90
Domains:
detectsysscanner[.]at
detectsysscanner[.]com
detectsysscanner[.]de
detectsysscanner[.]in[.]net
detectsysscanner[.]xn--q9jyb4c
detsysscanner[.]com
detsysscanner[.]de
detsysscanner[.]xn--q9jyb4c
techsysscanner[.]com
techsysscanner[.]lol
tlcscanner[.]com
What happens to your data when you die? (Lock and Code S07E17)
This week on the Lock and Code podcast…
You will die. Your data will not.
The afterlife of our information is a recent phenomenon, and some of the companies with the most to sort through are still just figuring it out.
As far back as 2007, Facebook was forced to reckon with mass grief when users asked the company to maintain the profile pages of the 32 victims killed by a school shooter at Virginia Tech that year. Those pages became de facto memorials for loved ones to fill with comments, and today, memorialization has become a full-fledged feature on both Facebook and Instagram. Platforms like YouTube, Pinterest, and LinkedIn—launched with likely zero strategy for a user’s death—now have procedures for next-of-kin to request that a deceased person’s account be deactivated.
Now, think about all the other ways your data can linger after death.
Every year, people accumulate more and digital stuff—email addresses, social media profiles, contact lists, domain names, subscription services, online banking accounts, and the phones, laptops, and tablets that hold it all—and every year, as that digital stuff accumulates, it compounds into ever more problems for someone else to sort out. Here, a small industry of digital estate planners have cropped up, helping families retrieve and preserve anything valuable, no matter how digital, from Spotify playlists, to poignant social media posts that mattered, to the photos stored on a phone.
And where retrieval fails, artificial intelligence has offered an attempt at comfort. The chatbot service Replika launched in 2015 after its founder uploaded a dead friend’s text messages. HereAfter AI reportedly let users upload voice recordings to power a chatbot that sounded and spoke like the deceased. Film studios have pursued the same idea for entertainment, seeking to portray deceased actors in future films.
Surprisingly, almost none of this activity is governed by law, said Tamara Kneese, author of the 2023 book “Death Glitch: How Techno-Solutionism Fails Us in This Life and Beyond.”
“By and large, there is not a great legal mechanism for protecting the privacy rights of the dead,” said Kneese. “It may not be just that a grieving loved one decides to use a bunch of your data from all of your podcasts to create a chatbot to simulate interacting with you after you’re dead, but it may be that a company chooses, in some way, to use an aspect of your personality, of your demeanor, of your voice, of your likeness after your death without anyone really being aware.”
Today, on the Lock and Code podcast with host David Ruiz, we speak with Kneese—Senior Research Scientist at Partnership on AI—about who owns a person’s data after they die, why every platform has invented its own private policy for the dead, and how the technology built to keep the dead close can vanish just as suddenly as they did.
Or worse yet, as Kneese warned for those relying heavily on certain technologies in grief:
“The company gets sold to someone else or disappears, goes bankrupt, and you no longer have that outlet or place for interaction when you’re mourning another time.”
Tune in today to listen to the full conversation.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Further reading:
Fartein Hauan Nilsen, “Caring for the Algorithm: Care, Love, and the Relational Personhood of Chatbots,” Somatosphere, February 26, 2026
Fartein Hauan Nilsen, “Therapeutic ideology and AI personhood: an anthropological inquiry into AI companionship,” a chapter from “Handbook on Anthropology and Artificial Intelligence,” Edward Elgar Publishing, July 21, 2026
University of Birmingham, “New Model Rules mark meaningful step towards digital inheritance laws,” July 16, 2026
Edina Harbinja, “Governing Digital Immortality: Artificial Intelligence, Deadbots and the Law,” Edward Elgar Publishing, to be published September 2026
Lilian Edwards and Edina Harbinja, “Protecting Post-Mortem Privacy: Reconsidering the Privacy Interests of the Deceased in a Digital World,” May 2013, revised November 2013
Lilian Edwards, Edina Harbinja, and Marisa McVey, “Governing Ghostbots,” Computer Law & Security Review, November 2023
SAG-AFTRA, “SAG-AFTRA Statement on Today’s Passing of California Assembly Bill 1836,” August 31, 2024
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.
AliExpress caught using silent audio to fingerprint visitors’ browsers
AliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave reported finding silent Web Audio processing on the site that could help fingerprint visitors’ devices.
The audio processing did not record people through their microphones. Instead, it generated and processed an inaudible signal, then measured small, repeatable differences in the way a browser and device handled it.
Browser fingerprinting is a way for websites to identify devices and recognize returning visitors without relying on conventional cookies. It works by using information about a device and browser to create a unique signature.
The AliExpress website was found processing a fixed audio waveform and examining the resulting numerical values. Tiny differences can arise from the browser, operating system, CPU behavior, audio hardware, and drivers. When combined with other signals, they become another input that can contribute to a browser or device identifier.
Investigation of the page’s code reportedly found audio-processing graphs that were set to zero volume but remained connected to the system audio output. That explains why a user could hear nothing, and why muting a browser tab would not necessarily prevent the processing. All the relevant work was occurring within the Web Audio graph rather than through a conventional media player.
And audio measurements were only one part of the reported data collection. The scripts also gathered information tied to canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior and user interactions. Together, those signals can create a more detailed profile of a device than any one signal would provide on its own.
Fingerprinting can be used for legitimate purposes such as fraud prevention, bot detection, and risk assessment. It can help companies spot suspicious transactions or automated activity even when cookies have been deleted or accounts have changed. But it also raises privacy concerns because users may not know the tracking is happening and have limited control over it.
Safer. Cleaner. Ad-free browsing.Earlier studies have shown that visitors’ choices about allowing cookies were ignored in more than half the cases studied. Fingerprinting adds another privacy concern because it can allow websites to recognize visitors without relying on cookies at all.
How to protect yourselfThe alleged AliExpress implementation is a useful example of how modern tracking can be both silent and technically legitimate at the API level while still raising privacy concerns.
Brave says its browser blocks the AliExpress scripts responsible for the audio-based tracking. Other steps you can take include:
- Use content blockers and anti-tracking extensions to limit the information websites can collect about your browser and device.
- Keep your browser up to date since browser vendors continually change privacy defenses as fingerprinting methods evolve.
- Use a separate browser or browser profile for shopping, ideally without signing in to other services in the same profile.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
ToxicPanda 2.0 can take over your Android phone and banking apps
Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.”
Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging automation. Together, those functions can help operators turn a compromised phone into a platform for account takeover, financial fraud, and longer-term device control.
The core objective is on-device fraud. That means that rather than logging in from an attacker-controlled machine, the operator can carry out actions from the victim’s infected phone, taking over the device, IP address, app session, and behavioral context that banks may use when deciding whether a transaction is fraudulent.
ToxicPanda 2.0 is built around abusing Android’s Accessibility Service, a legitimate feature intended to help people interact with their devices. When a victim grants this permission to a malicious app, the malware can inspect interface elements, observe app activity, automate interactions, and place deceptive content over legitimate apps, known as overlays.
ToxicPanda has historically relied on social engineering to persuade users to sideload a malicious Android application rather than install it through Google Play. The latest campaign uses Amazon AWS-hosted buckets to deliver ToxicPanda 2.0 samples.
After installation, the dropper presents a fake installation flow, requests VPN privileges, blocks certain Google Play and Google Play Services network communications, decrypts an embedded payload, and then seeks Accessibility Service permission for the installed payload.
The consequences can include stolen banking usernames and passwords, intercepted or captured PINs, fraudulent transactions, loss of access to the device, and exposure of the phone’s screen-lock secret. An attacker that can operate inside an active banking session from the victim’s device may have a better chance of evading controls designed to identify unfamiliar devices or unusual login locations.
How to stay safeHowever sophisticated it is, ToxicPanda 2.0 still relies heavily on social engineering to get targets to install the malicious app and give it the permissions it needs. So our main recommendations are:
- Avoid sideloading apps, especially from links in unsolicited messages, ads, or alleged support communications.
- Treat requests for Accessibility access, Device Administrator privileges, developer settings, and VPN permissions with particular caution, especially if it’s not clear why the app needs those permissions or if you don’t fully trust it.
- Use an up-to-date, real-time anti-malware solution for your device that can detect and block the malicious payload. Malwarebytes for Android detects apps in the ToxicPanda 2.0 campaign as Android/Trojan.Dropper.agent and Android/Trojan.FakeApp.ACR2401245FC11.
Although it may require a factory reset to regain control of an infected device, there are some things you can try first:
- First, put the phone in airplane mode and turn off Wi-Fi and Bluetooth. This can cut off command-and-control communications and ongoing credential theft while you investigate.
- Use another device to freeze or closely monitor transactions, revoke active sessions, and reset your banking credentials.
- Do not interact with fake “system update” screens or unexpected prompts for Accessibility, VPN, Device Administrator, Developer Options, or Wireless Debugging.
- Start Android Safe Mode. Google recommends Safe Mode to help identify problems caused by downloaded apps. Remove recently installed or suspicious apps one at a time, reboot normally, and see whether the problem returns.
- Remove Accessibility access first. In Settings > Accessibility > Installed apps/Downloaded apps, disable any service you do not recognize. Focus on recently installed apps or anything pretending to be an update, system component, security tool, document viewer, or bank helper.
- Next, check Device Administrator rights. Go to Security & privacy > More security settings > Device admin apps and disable any unrecognized administrator before attempting removal. An app with Device Administrator privileges can make the Uninstall control unavailable.
- Then check your VPNs. Go to Settings > Network & internet > VPN or search Settings for “VPN,” and delete any VPN profile you did not deliberately install. The ToxicPanda dropper uses VPN permission as part of its reported Google Play and Google Play Services blocking process.
- Disable dangerous developer functionality. Search Settings for Developer options, turn it off entirely, and make sure Wireless debugging and USB debugging are off.
- Remove all the suspicious apps you found. Go to Settings > Apps > See all apps, enable Show system apps if necessary, then locate recently installed or unfamiliar apps. Force stop the suspicious app, clear its storage, and select Uninstall. If an app has a generic name, blank icon, odd install date, or was installed outside Google Play, treat it as suspicious.
- Reboot normally after removal, then re-check Accessibility, Device Administrator, VPN, and Developer Options. Also review the installed-app list for a second suspicious package, since the reported campaign uses a dropper to decrypt and install its payload.
Please note: The given paths in Settings may differ depending on your device manufacturer or Android version.
If you’re having trouble removing ToxicPanda manually and you can’t install or update Malwarebytes, please reach out to our Support team. They can walk you through the process.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
Tracking PavinLoader across ClickFix and fake download campaigns
In our previous analysis of the malicious RenPy campaigns, we identified a multi-stage loader deployed as part of the infection chain.
Further threat hunting has since shown that the same loader, which we track as PavinLoader, is being used across several different campaigns, including ClickFix attacks and fake software downloads.
Despite differences in how these campaigns reach victims, we found several common elements. These include multi-stage infection chains involving heavily obfuscated and trojanized .NET DLLs; abuse of MSBuild, .csproj, and .bat files to execute them; and EtherHiding to retrieve the command-and-control (C2) domain.
What an attack looks likeThe campaigns don’t all start the same way. A victim might encounter a fake CAPTCHA that tells them to run a command, download what appears to be legitimate software, or install a malicious game.
What happens next is much more consistent. PavinLoader uses legitimate Windows tools alongside malicious .NET files to run several stages of malware. It also uses EtherHiding, a technique that uses a blockchain to hide information about its infrastructure, to find the server from which it should retrieve additional malware.
In the RenPy campaign we analyzed, that process ultimately led to Amatera Stealer, malware designed to steal information from an infected computer. We also observed PavinLoader infections delivering additional malware.
PavinLoader appears across multiple campaignsWe have identified PavinLoader in several campaign clusters:
- Malicious RenPy campaigns, as analyzed in our earlier blog post
- Several ClickFix campaigns, including recent activity from the operator(s) covered in our previous analysis
- Fake software campaigns that used Dropbox to download PavinLoader.
The loader’s use across multiple campaigns raises the possibility that PavinLoader is offered as a Loader-as-a-Service.
We also found several artifacts that support this possibility, although they are not enough to confirm it. One specific artifact on VirusTotal is shared by more than 200 files associated with PavinLoader, suggesting it may be a compilation artifact of the build process.
We also found a PowerShell script uploaded to VirusTotal containing comments such as EDIT HERE and REPLACE with a real direct link to your .bat. The associated BAT file contains the string Automated builder helper.
However, we haven’t found a build panel or sales channels that would confirm PavinLoader is being offered commercially.
The PowerShell script. Click to enlarge Part of the BAT file. Click to enlargeAlthough PavinLoader has changed over time, the campaigns we analyzed share several characteristics:
- Inno Setup or MSI installers generated with different builders that run the .bat and/or .csproj files
- Trojanized .NET DLLs, including DotNetZip, Nancy, Renci.SshNet, and OpenXML. In most of the cases analyzed, the inserted malicious methods follow a TwoWords or TwoWordsNumber naming pattern, such as DefaultEvaluator5, and FallbackFactory5
- A common obfuscation technique used across the .NET DLLs
- A naming convention based on two random words, such as GollopDevest, UnbrandRunover, and PavinWide, for DLL names, functions, strings, C2 paths, and other artifacts
- EtherHiding to obtain the C2 domain, followed by HTTP requests using paths such as assets/{two random words}.json to retrieve subsequent stages. C2 domains commonly use the .lat, .icu, .shop, and .cfd top-level domains
- MSBuild mechanisms for loading and executing code from DLLs, including property functions such as [System.Reflection.Assembly]::Load(...) and UsingTask
- Recurring filename patterns such as name_4characters.cmd/bat/msi/exe—for example, prefetch_9a59.cmd, telemetry_55db.cmd, and bootstrap_64be.cmd—or random nine-character names such as aegZpQ4C7.bat. We also observed short names including Small.msi, small.bat, and small.cmd
PavinLoader consists of several .NET DLLs, and in the cases analyzed we identified the following stages:
- Loader DLL: A trojanized DLL—such as the Nancy one analyzed in our previous RenPy article—or a custom DLL. It performs anti-forensics and anti-analysis operations, changes network settings needed for the next operations, and loads the EtherHiding Loader
- EtherHiding Loader DLL: Obtains the C2 through EtherHiding and downloads the next stages from it
- Anti-Analysis DLL: Performs extensive anti-analysis checks to detect virtualized environments.
- PE Loader DLL: Loads the final PE payload.
Intermediate payloads can vary depending on the campaign configuration. First, we’ll look at some of the methods used to distribute the initial PavinLoader stages. We’ll then return to the RenPy loader campaign we analyzed in our previous article to examine the loader’s later stages.
Technical analysisThe rest of this article takes a closer look at how PavinLoader is distributed and how each stage of the loader works.
How PavinLoader is deliveredWe have observed PavinLoader being delivered through several ClickFix campaigns.
In particular, we detected that the ClickFix cluster analyzed in a previous article has recently started using PavinLoader. Abuse of MSBuild and the use of .csproj and .bat files remain common across the infection chains we observed.
We covered one example in our previous RenPy analysis. Here, we’ll look at several other distribution methods.
The ClickFix Cloudflare page associated with this campaign. Click to enlargeAs we saw in our previous analysis of these ClickFix campaigns, the associated PowerShell scripts change frequently. We found several versions in this activity, including both obfuscated and unobfuscated scripts.
The PowerShell script associated with the ClickFix campaign. Click to enlargeIn this example, the downloaded MSI from the Cloudflare bucket is called Installer_57be78.msi.
MSI content. Click to enlargeThe package contains:
- prefetch_2f76.exe: The legitimate MSBuild executable
- prefetch_2f76.csproj: Used to execute the Loader DLL through UsingTask
- DotNetZip.dll: The Loader DLL
The .csproj file is executed with:
"C:\Users\{USER}\AppData\Local\Logitech\Device Configuration Helper\prefetch_2f76.exe" /nologo "C:\Users\{USER}\AppData\Local\Logitech\Device Configuration Helper\prefetch_2f76.csproj" /nr:falseThe Loader DLL is a trojanized version of DotNetZip and is executed using the UsingTask element.
“UsingTask” used to execute the DLL. Click to enlarge The malicious method inserted in the trojanized DLL. Click to enlarge.Unlike the RenPy example discussed in our previous article, the EtherHiding Loader is extracted from the DLL itself. An embedded resource is used as an index to extract bytes directly from the DLL, rather than obtaining those indexes from the .csproj file.
We detected another campaign that uses BAT files containing fake BUILD VERIFICATION REPORT comments, apparently intended to make analysis and detection more difficult.
In this case, the MSI CustomAction executes the BAT script with:
cmd.exe /c C:\Users\{USER}\AppData\Local\Conexant\lite_bootstrap_2.1.7\updater_8219.cmd /launched Fake comments inserted in the updater_8219.cmd. Click to enlargeThe obfuscated code appears below the fake comments. It concatenates multiple strings and uses indices generated through simple mathematical operations to reconstruct them. We found this type of obfuscation in most of the BAT files we analyzed.
The obfuscated part of the .cmd file. Click to enlargeThe BAT file locates conhost.exe and relaunches itself with:
"C:\WINDOWS\System32\conhost.exe" --headless cmd.exe /c "C:\Users\{USER}\AppData\Local\Conexant\lite_bootstrap_2.1.7\updater_8219.cmd" /launchedIt then sets the MSBUILDENABLEALLPROPERTYFUNCTIONS=1 environment variable, locates MSBuild.exe, and executes it using the same file as input:
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe" "C:\Users\{USER}\AppData\Local\Conexant\lite_bootstrap_2.1.7\updater_8219.cmd"In this case, the Loader DLL is reconstructed by concatenating and decoding four Base64-encoded variables.
Part of the CMD file showing the loading process. Click to enlargeThe Loader DLL has a random name and appears to be an older version because it does not contain the custom bytecode and encrypted strings in its resources.
As in the RenPy campaign analyzed previously, this stage retrieves the EtherHiding Loader stored between a Build-... marker in the CMD file through the _vezr environment variable, then decodes it using XOR with a 32-byte key.
The extracted Loader DLL. Click to enlargeHaving looked at several methods used to distribute PavinLoader’s first two stages, we will now return to the RenPy infection chain from our previous analysis and examine the loader itself in more detail.
Analyzing PavinLoaderThe .NET DLLs associated with PavinLoader are heavily obfuscated using control-flow flattening, custom bytecode, indirect calls through calli/ldftn, string encryption with different algorithms, API hashing and delegates, redundant methods, and junk code and strings.
We did not identify a known obfuscator associated with the samples, so to the best of our knowledge, PavinLoader uses a custom obfuscator.
Because fully deobfuscating the samples would be complex, we used a hybrid approach combining dynamic analysis with method invocation through reflection. We identified important methods based on their imports and parameters, invoked them, and analyzed the resulting output.
This approach does not provide complete coverage of the execution flow, but it allowed us to identify the loader’s core functionality and extract its intermediate stages. Because different functions frequently share the same names, we use metadata tokens to identify methods throughout the analysis.
Nancy trojanized DLL: Loader DLLWe covered this stage in detail in our previous blog post, so we’ll provide only an overview here.
In most of the cases analyzed, the Loader DLL is a trojanized legitimate DLL. The malicious method typically uses a {RandomWord} or {RandomWord_Number} naming convention.
The DLL contains a resource associated with the custom bytecode interpreted by the main method, two resources containing encrypted strings, and, in some cases, additional resources used as an index for extracting the next stage. Other resources appear to be decoys designed to slow analysis. In the samples we analyzed, this DLL typically:
- Decrypts strings from resources using multi-key XOR
- Resolves APIs using API hashing and GetDelegateForFunctionPointer()
- Changes network settings, including disabling TLS certificate validation and setting the default system proxy
- Performs an anti-analysis timing check using CreateEventW(), GetTickCount(), and WaitForSingleObject()
- Performs anti-forensics operations
- Loads the EtherHiding Loader either by extracting it from a marker inside .csproj or BAT files, or by using a resource as an index to retrieve bytes directly from the DLL
The EtherHiding Loader has two main functions: obtaining the C2 domain through EtherHiding, and downloading and loading subsequent stages from that C2.
Class 0x02000762 is responsible for decrypting strings associated with blockchain and network communication.
The strings are decrypted by 0x060027BD as follows:
- Function 0x060027BB initializes the S-box using the XOR of the master key activeValues and the Base64-decoded optionsCollection string
- Function 0x060027BE takes childSyncObject as input and returns index bytes using XOR and permutations based on header values encoded in the first two characters of the string
- Function 0x060027B9 returns the decrypted string using the indexes and the previously generated S-box
This was the only class we found with encryption parameters encoded in this format.
For the remaining strings, we identified functions that returned decrypted data based on their parameter signatures—for example, methods returning strings or bytes—and invoked them through reflection. This allowed us to recover more than 1,300 strings.
Part of the decrypted strings. Click to enlargeAmong them were strings associated with AMSI and ETW patching:
AmsiScanString
System.Management.Automation.AmsiUtils
System.Management.Automation.AmsiUtils+AmsiNativeMethods
ntdll
EtwEventWrite
NtQueryInformationProcess
NtSetInformationThread
VirtualProtect
More than 100 URLs belonging to legitimate services are also decrypted and used to generate HTTP requests and network noise. We did not observe this behavior in every sample, suggesting it may be build-specific.
The Server class (0x02000052) generates the X-Timestamp, X-Nonce, and X-Signature HTTP headers and makes requests used to retrieve subsequent stages.
Two HTTP requests are made to synchronize parameters and obtain the payload, with HMAC used to validate the requests. Using reflection, we executed method 0x06000A77 to obtain the header values needed to retrieve the subsequent stages.
The C2 domain is obtained by making an ETH RPC (Remote Procedure Call) to bsc-dataseed.binance.org with the following JSON-RPC body:
{"jsonrpc":"2.0","method":"eth_call","params":[{"to":"0x328a1fadff154290f0ce1389a4e633698cdfdaa7","data":"0x06fdde03"},"latest"],"id":1783436775}The next stages are downloaded from the resulting C2 domain. The XOR-encoded payload is stored in the JSON response under cache.content:
{"type":"cache-binary","meta":{"version":"2.3.1","timestamp":"…","platform":"win32-x64"},"cache":{"id":"e2b69…","content":"1c.."}}In this case, the C2 paths and XOR keys decrypted from this stage and the anti-analysis DLL are:
Path XOR key Type/Function /assets/ExponeAboard.json QBBBfWow4lb PavinWride .NET DLL, Anti-analysis /assets/MailersKogasin.json WjcsVTKmuoBRqe GollopDevest .NET DLL, PE Loader /assets/LanoseThrip.json WwUX66Br WPA.exe PE executable, Amatera StealerThe next stage executed is the anti-analysis DLL.
PavinWride: Anti-analysis DLLThis DLL is responsible for performing several anti-analysis checks.
The anti-analysis DLL executes system calls in different ways:
- Standard .NET Base Class Library (BCL) calls, including for registry and network operations
- Win32 P/Invoke calls, including GetCurrentThread, NtQueryInformationThread, NtQueryInformationProcess, and NtCurrentTeb
- Win32 APIs resolved through API hashing and a Process Environment Block (PEB) export table walk
The function MenuItemService.ProcessDirectory (0x06000151) is the main method responsible for delegate caching and Win32 API resolution:
- It checks if the delegate is already resolved using managerMap.TryGetValue()
- If not, it calls ProcessDirectory (0x06000150) to obtain the HMODULE handle
- It calls ProcessDirectory (0x0600003A) that performs the PE export table walk and matches the hash. We detected that the same hashing output is obtained in several other methods (e.g., 0x06000039, 0x0600003B, 0x0600004E)
- It obtains the delegate with GetDelegateForFunctionPointer() and saves it in the dictionary
We used the same reflection approach to get the strings. Many strings are encrypted with the XOR key 4B729A1F5CE387D6.
Part of decrypted strings. Click to enlargeThe loader obtains the system’s LCID using GetKeyboardLayoutList() and compares it against more than 17 languages, including Russian, Ukrainian, Belarusian, and Armenian.
It also performs extensive system reconnaissance, including enumerating registry keys and calling Win32 APIs such as GetSystemFirmwareTable() and EnumSystemFirmwareTables() to identify virtualized environments.
Category Value PCI vendor / device IDs VEN_80EE, VEN_15AD, VEN_1AB8, VEN_5853, VEN_1AF4, VEN_1234&DEV_111, …SMBIOS/ACPI OEM IDs VMWARE, VBOX, BOCHS, VRTUAL, MSFTVM, MSHYPR, Xen, Parall, BHYVE, AMAZON, GoogleACPI table signatures VBOX, BXPC, VMW, Xen, PRLS, AMZN, MICRBIOS/manufacturer/product strings vmware, vmw, innotek, virtualbox, vbox, qemu, seabios, bochs, standard pc, kvm virtual machine, xen, hvm domu, parallelsStrings associated with anti-analysis checks Part of the registry key enumeration. Click to enlargeWe also observed decrypted references to APIs including GetCurrentProcess(), CreateToolhelp32Snapshot(), Process32First(), Process32Next(), and OpenMutex(), although we did not observe these functions being called during our execution flow.
An HTTP request is also made to one of these services:
- https://ipv4[.]ipleak[.]net/json/
- https://get[.]geojs[.]io/v1/ip/geo[.]json
- https://ipapi[.]co/json/
- https://api[.]ipapi[.]is/
- https://ipinfo[.]io/json
It also checks the returned data against 96 hosting or infrastructure providers and tests whether the region code is one of: RU, UA, BY, AM, KZ, KG, TJ, UZ, GE, AZ, or MD.
Decrypted strings associated with providers. Click to enlargeIf the anti-analysis checks pass, the next two stages are downloaded and decrypted using XOR keys.
We patched SelectionScope.ProcessDirectory (0x06000014) to recover the C2 paths and XOR keys for those stages:
/assets/MailersKogasin.json|WjcsVTKmuoBRqe|/assets/LanoseThrip.json|WwUX66Br GollopDevest: PE Loader DLL and Amatera StealerThe third DLL has the same name as the second, GollopDevest, but performs PE loading.
Among its decrypted strings are:
'GollopMailers LDR DllBase VeneryCondole EdiyaFoully=0x{0:X} EdiyaStelae=0x{1:X}' 'GollopMailers LDR Flags missing IMAGE_DLL 0x{0:X8}' 'GollopMailers LDR SaranPisco invalid 0x{0:X}' 'GollopMailers LDR TlsIndex invalid {0}' 'GollopMailers LDR sanity exception: ' 'HIGHLOW relocation' 'Import DLL name' 'Import FunctusAurata' 'Import INT' 'Import descriptor' 'Import hint/name' 'Import thunk' 'LdrpHandleTlsData outside ntdll .text' 'LdrpReleaseTlsEntry outside ntdll .text' 'LoadConfig32' 'OK' 'PE headers' 'Required API resolve failed: type={0}, FreshBubals={1}, module=0x{2:X}' 'TLS32' 'TLS64' 'x86 disabled until ABI proof' ntdll.dll kernel32.dll LdrpInitializeTls "STATUS_SUCCESS" UNKNOWN(0x00000001) UNKNOWN(0x00000002) UNKNOWN(0x00000003)The ServerEditor.SortMemory method (0x06000014) checks the PE structure and flags before loading the payload.
To confirm this behavior, we invoked the method through reflection using the downloaded WPA.exe file as input. The PE loaded successfully.
The C++-compiled PE disguises itself as WPA.exe (Windows Performance Analyzer). We identified the payload as an obfuscated version of Amatera Stealer 4.2.3-alpha1.
It uses control-flow flattening, API hashing, anti-debugging checks, and opaque predicates to complicate analysis. We also detected use of the Heaven’s Gate technique, DNS-over-HTTPS (DoH) resolution through Google DNS, and raw sockets using \Device\Afd\Endpoint for network communication.
Part of the decrypted strings associated with Amatera. Click to enlargeAfter this stage executes, we also observed additional payloads being downloaded and run from C2 IP addresses.
In some cases, WiX Burn bundles downloaded another payload associated with PavinLoader. In others, we detected HijackLoader. This gives the campaign operators the ability to deploy multiple payloads on a compromised machine.
IOCsSHA-256 hashes
bdf313a019e025ebf58ccef4619444ee70e661bd444e0644ebeabd8f5caad14c
e3830f5747e3f46537d217124d80c9f3bb4d89f8d4f5138dce69ee54ea4fb6b9
a4f03272cf96732dc9f58bb466d16f358e7f50d46dba30526a9fbebfec11717b
bf04160dd1ce3571e0eb6d6dda1713c788797b5599399d4a93665a757eec376e
54fa8083c05334aa360256fbbb0ca901ce7e244a0359dd664cae78977371ec91
c1ea6d169565c70ac5d812e73483814929e9b3548ead6633595937e71a334adb
001337488c32d8610c2aef6f9330acca825f0afacd071bf6ebfc06b5a1a69f09
2837099af431e9afee76ce5e6ab5cb86bedce06e31c22be46250cb453cfdb978
252c5a3d150275013f52b4820097d7163ced4aa2f1be0fca032f8a5017673816
0c9c64b7383ec249bcf6271a4b73206d94de130ca401d16ab77fe01e5193a312
6700f62e1a3b33340cd678c388ecc8bac2e5943c0627df5d1b99b879c3ca42c9
IP addresses
93.152.224[.]75: downloads PavinLoader
65.21.80[.]170: downloads PavinLoader
195.63.142[.]49: downloads PavinLoader
Domains
perfectverified[.]com: ClickFix
PavinLoader C2
catalyst-pro[.]lat
twigoamwu[.]cfd
trusaifi[.]cfd
stellar-minds[.]cfd
pinnacle-labs[.]lat
nexahub[.]lat
fimwoglea[.]shop
velodium[.]lat
rpcsecnoweb[.]pro
more-arpc[.]icu
echo-systems[.]cfd
kelemet[.]shop
zarwieciv[.]cfd
URLs
telegra[.]ph/Project-PySynth-06-28: Amatera dead drop
Acknowledgements- Previous analysis of the loader: https://www.derp.ca/research/hellsuchecker-clickfix-etherhiding/#26-anti-sandbox-checks-and-a-nintendo-bypass
- Possible related activity: https://cyberowi.pl/lumma-stealer-renpy-fitgirl-osmiowarstwowy-loader/
- Possible related activity: https://medium.com/@djordje.brankovic/from-fake-captcha-to-in-memory-execution-unraveling-a-multi-stage-malware-chain-part-1-496c603f3641
- Analysis of a forum user: https://forums.malwarebytes.com/topic/338102-solution-of-gollopdevestdll-renpy-loader-malware-from-malwarebytes-blog/
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
A week in security (August 17 – August 23)
Last week on Malwarebytes Labs:
- Zombie Card: An expired Visa credit card can be used for purchases
- Medical records, SSNs, and bank details exposed in CareCloud data breach
- ChatGPT for Teens tackles risky chats and homework shortcuts
- Twitch wants your content for Amazon AI training. Here’s how to opt out
- Your Mac already has a built-in firewall. Here’s how to get more from it
- 9 million images of people’s faces exposed by reverse lookup service
- 41 deceptive download sites show a real link, then send you somewhere else
- Sideloading on Android: What it is, why it’s risky, and how to do it more safely
- Scammers are using fake crypto AML checkers to drain your wallet
- Update Chrome now: Two critical vulnerabilities fixed
- Your polite reply to that text is worth $2 on the dark web
- Apple fixes another image-processing flaw that could allow code execution
- Be careful what you put in “anyone with the link” Google Docs
- Heights Finance data breach: What customers need to know
- ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw
- Fake TikTok rewards promise cash you’ll never get
- Update your Mac: Screen Sharing vulnerability exploited in the wild
- Why Facebook’s war on ad blockers could help scammers
Stay safe!
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Zombie Card: An expired Visa credit card can be used for purchases
Did you know there is still a good reason to physically destroy your expired credit card?
Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering.
University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza tested contactless cards across Visa, Mastercard, Discover, and American Express, using multiple terminals and merchants, and cards from five major US banks.
They found that a payment terminal could be tricked into seeing a future expiry date. Basically, they were able to modify the expiration date sent to the terminal to a future date. This allowed them to revive expired Visa contactless credit cards for real in-store purchases. Hence the name “Zombie Card.”
The result was not universal. The tested Mastercard, American Express, and Discover configurations rejected the altered expiry data, while issuer behavior differed even among the tested Visa cards: Some transactions were declined or prompted for a replacement card, while others were approved.
The flaw lies in the Visa Kernel 3 contactless flow, where the terminal-facing Application Expiration Date was not effectively bound to the card’s data. In the tested Mastercard, American Express, and Discover kernels, consistency checks or authenticated-data coverage caused modified expiry data to be detected and the transaction to be declined.
How this could be abusedThe most credible abuse case is theft or recovery of an expired or replaced card which the owner regards as harmless. Consider cards left in household waste, a drawer, a lost wallet, or an unsecured corporate disposal stream. If the underlying account remains open and issuer-side controls do not validate the exact card lifecycle state, an attacker could attempt contactless purchases using a relay setup.
Less likely is a scenario that uses a proximity relay attack against a card still held by its owner. That requires sustained NFC (Near Field Communication) proximity and a live relay during the transaction, making it materially harder than merely scanning a card from a passing distance.
How to stay safeFor cardholders, the practical advice is simple:
- Destroy expired and replacement cards. Cut through the chip several times. Make further cuts through the card body to disrupt the contactless antenna, and damage the magnetic stripe before disposing of the pieces.
- Report a lost expired card rather than treating it as inert.
These are sensible precautions, but the primary responsibility lies with payment networks, terminal implementations, and issuers to ensure expiry data is integrity-protected and that authorization systems reject retired card credentials.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Medical records, SSNs, and bank details exposed in CareCloud data breach
Healthcare technology giant CareCloud has confirmed that a data breach earlier this year impacted more than 3.75 million people, making it one of the largest healthcare data incidents disclosed this year.
The New Jersey-based company, which provides electronic health record (EHR) and practice management services, first flagged the intrusion in an SEC filing back in March, but the true scope only became clear this month when the Department of Health and Human Services (HHS) breach tracker updated the affected total from roughly 345,000 to 3,756,469 individuals.
CareCloud says an unauthorized third party accessed one of its Amazon Web Services (AWS) environments between March 10 and March 16, 2026. The intrusion caused an eight-hour disruption to one of the company’s six EHR environments before systems were restored that same evening. During a forensic investigation, CareCloud determined that the attacker claimed to have exfiltrated data from databases within that environment.
The stolen data reportedly includes both identity and medical information:
- Full names, postal addresses, and dates of birth
- Social Security numbers (SSNs) and driver’s license or passport numbers
- Medical records and health insurance information
- Bank account and financial details, plus full credit card data (including CVV) for a limited subset of victims
Anyone receiving a breach notification letter should take it seriously, given the combination of medical, identity, and financial data involved.
If you think you’ve been affected by a data breach, here are steps you can take to protect yourself:
- Check the company’s advice. Every breach is different, so check with the company to find out what’s happened and follow any specific advice it offers.
- Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
- Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop, or phone as your second factor. Some forms of 2FA can be phished just as easily as a password, but 2FA that relies on a FIDO2 device can’t be phished.
- Watch out for impersonators. Cybercriminals may contact you posing as the breached company. Check its official website to see if it’s contacting victims, and verify the identity of anyone who contacts you using a different communication channel.
- Take your time. Phishing attacks often impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
- Consider not storing your card details. It’s definitely more convenient to let sites remember your card details, but it increases the risk if a company suffers a breach.
- Set up identity monitoring. This can alert you if your personal information is found being traded illegally online and help you recover afterward.
What do cybercriminals know about you?
Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.
ChatGPT for Teens tackles risky chats and homework shortcuts
OpenAI has addressed complaints around teens’ use of its ChatGPT system by introducing ChatGPT for Teens, a version of the AI assistant designed specifically for users aged 13 to 17. But will it prevent determined kids from bucking the system?
It brings together several protections OpenAI has introduced over the past year, along with new features intended to encourage healthier and safer use.
What ChatGPT for Teens doesThe system brings together various protections that OpenAI has built into ChatGPT over the last year into a more unified experience. For example, last September it added parental controls that enabled parents to set Quiet Hours, when kids couldn’t use the chat system, and turn off memory so it won’t use previous conversations when responding. It also built a notification system to warn parents if chats with teens took a bad turn. ChatGPT for Teens adds extra notifications for parents around eating disorders.
Study Mode, one of the main features, is designed to stop teens simply using ChatGPT to do their homework for them. Instead of giving direct, easy answers, it uses guiding questions and step-by-step prompts to encourage them to think through the problem themselves. OpenAI introduced Study Mode in July 2025.
What is new is the ability to set specific hours for Study Mode, along with responsible homework reminders. The system will spot when a teen appears to be using AI answers to shortcut an assignment and redirect them towards Study Mode.
OpenAI also says ChatGPT won’t use romantic language or encourage emotional dependence, and neither will it pretend to have feelings or to be conscious. It is introducing reminders not to upload sensitive images, and there will be an onboarding user interface for teens.
The record that forced the changesThat all seems positive, if long overdue. The parents of 16-year-old Adam Raine filed a lawsuit claiming that ChatGPT walked their son through suicide methods and offered to draft his goodbye letter before he took his own life.
Families in Tumbler Ridge, British Columbia, sued OpenAI in April this year after a school shooting there. The teenage shooter had allegedly held extensive gun-violence conversations with ChatGPT after reopening a banned account. In a controlled test where researchers posed as 13-year-old boys planning attacks, ChatGPT offered help 61% of the time, including specific advice on which shrapnel would be most lethal in a synagogue attack.
The lawsuits are stacking up. Florida Attorney General James Uthmeier sued OpenAI in June 2026, alleging that the company knowingly released an unsafe product.
The gap the launch does not closeOur Head of Consumer, Mark Beare, says ChatGPT for Teens is a positive step, but parents need to understand where the controls begin and end.
“[This is] directionally a good move, and more proactive than most social platforms were at a comparable stage. There is a clear adjacency to the parental controls space here. The controls are useful, but only when a parent configures them correctly, and only on a linked account.
“This is a bigger deal when you factor in how tech-savvy kids of this age are. The default teen protections lean on age prediction, and the stronger parent-set controls like Quiet Hours and safety notifications only apply once accounts are linked. Kids in this band are smart and tech-savvy, and they will look for the seams.”
The simplest loophole is an account that isn’t linked to a parent. OpenAI’s age-prediction system may still identify the user as under 18 and apply teen protections automatically, but parent-set controls such as Quiet Hours and parental safety notifications only work once the accounts are linked.
Last November, testers from the Family Online Safety Institute concluded that account protections in ChatGPT were “optional, easy to bypass, and inconsistent in blocking harmful content.”
Since then, OpenAI has rolled out age prediction on ChatGPT, which will check a user’s behavior to try and guess whether they are under 18. It will then move them to a ChatGPT for Teens account.
Adults will be able to present proof of their identity if they think they have been incorrectly categorized.
Beare says that still leaves parents with something to think about:
“Age verification exists as a backstop, but it runs on ID and selfie checks that carry their own privacy questions, and a teen who confirms as an adult moves out of teen mode entirely.”
As OpenAI acknowledged in its parental controls announcement, “guardrails help, but they’re not foolproof and can be bypassed if someone is intentionally trying to get around them.”
Safeguards around what content ChatGPT delivers to teens are also unlikely to be foolproof. OpenAI has admitted that its safety guardrails become less reliable the longer a conversation runs and says it is working to improve them.
What parents can doBy all means use ChatGPT for Teens as an assistive technology in a broader effort to protect your kids. Link their account to yours and set the Quiet Hours schedule. You can also set Study Mode as the default for new conversations to encourage children to use it responsibly. Make it your job to understand what the alerts do and don’t cover.
But be aware that parental controls need configuring and only apply while the parent and teen accounts are linked.
Most importantly, keep talking to your kids about how they use AI and what they use it for. No parental-control system can cover every account, conversation, or AI service they might encounter.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Twitch wants your content for Amazon AI training. Here’s how to opt out
The Dutch Autoriteit Persoonsgegevens (AP) has advised Twitch users to opt out of sharing data with Amazon AI.
Twitch launched as a live-video platform and is currently owned by Amazon. Its core product is live broadcasting with a built-in chat culture: streamers broadcast gameplay, commentary, performances or other live content while viewers interact in real time.
Twitch is one of the world’s largest livestreaming platforms, with millions of people broadcasting and watching content every month.
Last week we learned that Twitch allows Amazon to use content from its platform to train generative AI models, with the setting enabled by default. Chief Product Officer Mike Minton said during an interview:
“If it’s opt-in, nobody would opt in. That’s the honest answer. So, it’s going to be on by default.”
So, to get this straight: they know users don’t want it, yet users are opted in by default and they make it difficult to opt out.
The AP argues that:
“Live streams on Twitch show the gamer’s face, voice and name, and often include images of a private space, such as a bedroom. This constitutes personal data. In the case of facial images, this even involves sensitive personal data. Once these data are stored in Amazon’s AI systems, they cannot simply be removed. As a result, users lose control over their data. Users’ chats and text messages also serve as training material for Amazon.”
Obviously, Twitch users were outraged when they learned about the assumed consent. The setting is in the Streamer Dashboard under Settings > Security and Privacy, near the bottom of the page. That is the basis for reporting that it was difficult to find.
Wait, it gets worse. Ars Technica says the AI training itself isn’t new. What’s new is the option to opt out. That setting arrived more than two years after a company executive confirmed that Amazon was using Twitch content for AI training.
In April 2024, Minton said Amazon was using Twitch content to prototype AI models, although not yet at “production scale.”
How to turn it offThe setting is enabled by default. To turn it off, go to: Settings > Security and Privacy > scroll down to Training for Generative AI, and turn the setting off.
“Allow your channel content to train generative AI content models of Amazon. Turning this off does not opt you out of Twitch and Amazon using your channel content for other purposes described in the Twitch Privacy Notice, including using AI-supported Twitch features that benefit the community by facilitating streamer growth and monetization (such as real-time sponsorship campaign assistance), viewer discovery (such as recommendations), and community safety (such as AutoMod).”
Note that if you post in another streamer’s chat, whether that chat can be used for AI training depends on that streamer’s setting, not yours. So turning off the option on your own channel does not necessarily stop everything you write on Twitch from becoming training material.
There’s an old saying that “if you’re not a paying customer, you’re the product,” but that shouldn’t be an excuse to disregard users’ privacy or assume consent. We agree with the AP: If you have a Twitch channel and don’t want your content used to train Amazon’s generative AI models, turn the setting off.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
Your Mac already has a built-in firewall. Here’s how to get more from it
Your Mac comes with a built-in firewall, but it’s probably not something you’ve given much thought to.
A firewall helps control incoming connections—requests from apps and other devices that want to connect to your Mac—giving you an extra layer of protection whenever you’re online.
For most people, the default settings work just fine. But if you ever want more control over how your firewall works, whether you’re on public Wi-Fi or want to adjust which apps can connect, those settings aren’t always easy to navigate.
That’s where Malwarebytes Firewall comes in. It builds on the firewall already included with macOS, giving you a clearer, more intuitive way to view and manage your firewall settings.
What does your Mac’s firewall do?Your Mac sometimes receives connection requests from apps and other devices. For example, someone might send you a file using AirDrop or connect to your Mac using screen-sharing. Your firewall decides which requests are allowed and which should be blocked. That helps trusted apps and features work as expected while blocking connections you don’t want.
Customize your firewall with MalwarebytesMalwarebytes Firewall includes four controls that make it easier to adjust your Mac’s built-in firewall.
Stealth ModeWhen you’re connected to public Wi-Fi, whether at a hotel, a coffee shop, or the airport, Stealth Mode helps make your Mac harder to discover by other devices on the network.
Strict ModeAllows only core services, such as web browsing and email. It provides the highest level of control, but it may block features like AirDrop or screen-sharing.
Trust Apple appsAutomatically allows built-in apps like FaceTime, Messages, Notes, and other Apple apps to work without requiring you to approve them individually.
Trust verified downloaded appsAutomatically allows incoming connections for apps you’ve downloaded and chosen to trust, like Zoom, Dropbox, or Outlook, so you don’t have to approve each one manually.
Which settings should you use?Using your home Wi-Fi? You may be happy to leave Trust Apple apps and Trust verified downloaded apps turned on.
Connecting to public Wi-Fi while on the go? Turn on Stealth Mode for extra privacy. If you want tighter control over incoming connections, Strict Mode can help too.
You can switch settings whenever your network changes, and you’ll always know which options are turned on.
Get more from your Mac’s built-in firewallYour Mac already includes firewall protection. Malwarebytes Firewall gives you an easier way to manage it, with clear controls that help you adjust your settings without digging through system menus.
Update to the latest version of Malwarebytes for Mac to start using Malwarebytes Firewall.
“One of the best cybersecurity suites on the planet.”According to CNET. Read their review →
9 million images of people’s faces exposed by reverse lookup service
Researcher Jeremiah Fowler found a cloud database containing more than 9 million image files accessible without authentication, WIRED reports.
The leaky bucket, containing some 450 GB of images, was traced back to a US-registered company called ClarityCheck.
In their own words, ClarityCheck says:
“Use reverse image search to identify anyone in a photo. Find names, social profiles, and online presence in seconds.”
While ClarityCheck says it does not use facial recognition, it does describe its image function as a way to identify people and find their names and social profiles.
Granted, there’s a difference.
- An image search looks for identical or visually similar images, often using image embeddings, metadata, or indexed pages.
- Facial recognition detects a face, derives face-specific features, and compares them to a structured, face-indexed collection of digital images.
But does that difference matter when your face gets uploaded and stored in an unsecured cloud environment?
It is important to remember here that faces are persistent identifiers. A leaked password can be reset, whereas a person cannot easily replace their face. When an image of someone is linked with names, social profiles, addresses, emails, or phone numbers, that information could potentially be misused for impersonation, targeted phishing, doxxing, or catfishing.
ClarityCheck disputed that the data was publicly exposed because accessing it required an unindexed URL. However, the images didn’t require authentication, and Fowler was able to discover the URLs through the site’s code.
It is unknown how long the bucket was exposed before Fowler found it. Despite earlier alerts from Fowler, ClarityCheck did not restrict access to the database until WIRED contacted the service in July.
People finder toolsPeople finder tools are online services that aggregate public records, contact data, and social footprints to help locate individuals using names, phone numbers, emails, or addresses.
If you want to check whether someone on social media is using a fake or stolen profile picture because you’re worried they might be a scammer, a conventional reverse image search can help you see where else that picture appears online. You don’t need a people finder tool.
ClarityCheck, along with many others like it, requires users to confirm that they own the image, appear in it, or otherwise have the necessary rights and permission to upload it. Of course, a checkbox cannot prevent someone from lying.
There are a few pointers we want to give people who use ClarityCheck or similar tools:
- Do not upload a photo of someone else unless you have their permission or another clear legal right to do so.
- Think twice before uploading your own photo if you’re not sure how it’s going to be used, how long it will be stored, and how secure that storage is.
- Before using any service, check its policies on image retention, deletion, AI model-training use, storage, third-party sharing, and removing images.
- If you find yourself in a search result, save the URL and screenshots, request delisting from the search service, and seek removal from the original site or platform hosting the image.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
41 deceptive download sites show a real link, then send you somewhere else
We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer.
The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF.
They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links.
But the link you see isn’t the link you follow.
One site promises Counter-Strike. Hover over its download button and the browser displays a genuine Steam Store address. Click the button, however, and Steam never opens.
The link looks safe when you hover, but the click says otherwise.One of the oldest web-safety tips is to hover over a link before clicking it and inspect the destination shown by your browser. We even recommend doing this when checking emails for phishing links and scams.
But it isn’t foolproof. This campaign shows how a site can display a legitimate destination when you hover over a link, then send you somewhere completely different when you click it.
On the Counter-Strike page, the download button contains a legitimate Steam Store URL. That is the address the browser displays when you hover over it.
But JavaScript on the page handles the click separately. Instead of following the Steam link, the script cancels the expected navigation and sends the visitor through an affiliate redirect.
The legitimate Steam URL provides reassurance, but isn’t the actual destination.
The page goes further by linking to genuine Steam resources in its footer and presenting itself as a straightforward source of technical information. That veneer disappears the moment the download button is pressed.
41 sites, one destinationThe Counter-Strike site isn’t an isolated example.
Across the 41 sites we identified, the branding and advertised downloads change, but visitors are ultimately pushed towards the same software: Download Studio.
One site, GTA 6 PLAY, claims to offer a PC download of Grand Theft Auto VI. It provides installation instructions, system requirements, and everything else you might expect from a real game-download page.
There is one rather significant problem: There is no announced PC version to download.
Rockstar currently lists Grand Theft Auto VI for PlayStation 5 and Xbox Series X|S, with a release date of November 19, 2026. It has not announced a PC release.
After visitors follow the download process, they’re shown instructions telling them to install Download Studio. Here’s an example of that screen from the Counter-Strike site:
In other words, the advertised software is the lure. Installing Download Studio is the destination.
The software lures are even more convincingThe same technique appears on pages advertising ordinary Windows applications.
A fake VLC Media Player page, for example, places a genuine VideoLAN download address inside its download button. It also identifies VideoLAN’s servers as the source of the file.
At the time of our research, VLC 3.0.23 was VideoLAN’s current release.
So the information shown to the visitor can be completely accurate. The link can be real. The version can be real. The developer can be correctly identified.
Then the click handler overrides all of it. Instead of allowing the browser to retrieve VLC from VideoLAN, the page sends the visitor toward Download Studio.
Even the signature advice can mislead youThe VLC lure also recommends checking the installer’s digital signature before running it.
A digital signature allows Windows to verify who signed a piece of software and whether the signed file has been changed since it was signed.
To check one, right-click the downloaded file, select Properties, then open the Digital Signatures tab. You can select the signature and click Details to see whether Windows considers it valid and who signed it.
Normally, that’s a useful check. But the Download Studio installer passes it.
The sample we examined is validly signed by Grand Media, TOV. So you could follow the page’s advice, see that Windows considers the signature valid, and still have downloaded something completely different from what you intended.
That’s because a valid signature tells you who signed a file and whether the signed content has been altered. It doesn’t tell you that you’ve downloaded the program you intended to.
Microsoft’s own Authenticode documentation makes the same distinction. Code signing provides information about the publisher and integrity of a file. It does not guarantee that signed software is trustworthy.
The lures include everyday softwareThis campaign isn’t limited to people looking for unreleased games.
VLC, 7-Zip, Paint.NET, and AIMP are legitimate applications people routinely download. Someone searching for one of them is doing nothing unusual.
Other lures target security, backup, and recovery products, including Avast, Acronis, and Recuva.
Someone looking for everyday software, or even software to protect or recover their computer, can be pushed into installing a program they never asked for.
What the sites actually deliverThe sample delivered during our research is a roughly 73 MB Windows installer for Download Studio.
It is signed by Grand Media, TOV, and the signature validates successfully. Our analysis found Download Studio installing and launching its own interface and torrent components. The program registers torrent and magnet associations, and its installer includes an option to make Download Studio the default torrent client.
The installation also enables its automatic updater.
Importantly, our analysis did not establish that Download Studio itself is malware. What this campaign clearly demonstrates is that people looking for one piece of software are being deceptively funneled into installing another.
The redirect includes affiliate tracking, suggesting there may be a commercial incentive.
Download Studio has relevant historyThere is another reason Download Studio’s automatic updater caught our attention.
In 2020, researchers at Avast found that Download Studio’s automatic updates had been used to silently distribute FakeMBAM, a backdoor disguised as a Malwarebytes installer.
Avast monitored Download Studio’s updates and observed the fake Malwarebytes installers being delivered and executed in the same way as legitimate updates, silently in the background and without users knowingly initiating the installation.
The backdoor could download additional malware, and the persistent payloads Avast observed were cryptocurrency miners.
When the researchers contacted Download Studio’s developers, they said they had detected a security incident involving their continuous-integration server, investigated it, and added additional security measures. Avast said the developers did not answer follow-up questions about how many users were affected or whether they had been notified.
The research also named Grand Media, TOV among the companies associated with the applications involved. The Download Studio installer we examined in this campaign is also signed by Grand Media, TOV.
There is no evidence that the Download Studio installer in this campaign is malicious or that the same attack is happening again. But its automatic-update mechanism has previously been abused to distribute malware, making the fact that the current installer enables automatic updates relevant.
Check what you actually downloadedThere is another simple check that exposes the bait-and-switch used by these sites.
Right-click the downloaded executable, select Properties, and open the Details tab.
For the sample we examined, File description and Product name identify Download Studio, Original filename is DS-Setup.exe, and the copyright information names Grand Media.
If you clicked a button labelled “Download VLC” and those fields say “Download Studio,” you have an immediate and obvious mismatch.
The Details tab isn’t proof that a file is safe, however. The software publisher controls that information, so a malicious program could use convincing product names and descriptions.
Instead, look at the whole download: Did it come from the developer or a trusted store? Is it signed by the publisher you expected? And does the file identify itself as the program you meant to download?
How to protect yourselfThere are a few simple ways to avoid getting caught by this kind of download bait-and-switch:
- Get software directly from the developer’s website or a trusted app store. For games, use a legitimate store such as Steam or the publisher’s own store.
- Don’t rely on hovering over a link alone. As this campaign shows, a page can display a legitimate destination and then send you somewhere else when you click.
- A valid digital signature doesn’t mean you got the right program. Check Properties > Details and confirm the product name matches what you wanted.
- If a download page says you need to install a separate download manager first, close it.
- If a game hasn’t been released for your platform, a site claiming to offer an official download cannot have it.
- If Download Studio is already installed and you didn’t choose it, remove it through Settings > Apps and run a full virus scan.
- Malwarebytes Browser Guard blocks pages like these before they load, which stops the problem before you’ve downloaded anything.
File hashes (SHA-256)
9a3f6e69c12cb814c45862219ecb17e9ab7744877c9da1c49f3ea046437f8fca (DS-Setup.exe)
Network indicators
r.byteengineering[.]net
apis.downloadstud[.]io
downloadstudio[.]net
dstudio[.]app
getdownloadstudio[.]net
4kvideodownloader[.]ru
acronisportal[.]ru
cristalixmine[.]ru,
crystaldisk24[.]ru
csgodownload[.]ru
cupheadplay[.]ru
fallout24[.]ru
farcryplay[.]ru
faststoneportal[.]ru
formatf[.]ru
foxitpdf[.]ru
get7zip[.]ru
getaf[.]ru
getaimp[.]ru
getavast[.]ru
getbandicam[.]ru
getbluestacks[.]ru
getmovavi[.]ru
getrecuva[.]ru
getultraiso[.]ru
getvmware[.]ru
getvuescan[.]ru
gogetter24[.]ru
gta6-play[.]ru
halflife-play[.]ru
memuemulator[.]ru
paintdotnet[.]ru
pdfxchange[.]ru
poppyplaytimeplay[.]ru
pubgplay[.]ru
rdrplay[.]ru
regorganize[.]ru
roblox-play[.]ru
rust-play[.]ru
tcommander[.]ru
tf2play[.]ru
thewitcherplay[.]ru
uninstalltooll[.]ru
vlcmp[.]ru
windowsmp[.]ru
yandereplay[.]ru
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Sideloading on Android: What it is, why it’s risky, and how to do it more safely
A Google spokesperson announced on Reddit that it has started rolling out the first version of its Advanced Flow, designed to make installing apps from unverified developers safer.
Let us explain what sideloading is, why Google Play is not 100% safe, what to look for when you’re sideloading so you can do it more safely, and how Google’s Advanced Flow helps with that.
What is sideloading?Sideloading lets Android users install apps from outside Google Play. It can be useful, but it also creates opportunities for scams and malware.
Android’s openness is one of its enduring strengths. You are not limited to a single app store: You can install apps from a developer’s website, an alternative marketplace, an enterprise portal, or a file shared directly with you.
That is called sideloading. It is not automatically dangerous, but it removes some of the guardrails that come with conventional app-store distribution. Getting apps from the Google Play Store itself is no guarantee of safety, but there is at least some vetting. Google says it blocked more than 1.75 million policy-violating apps from being published in 2025 and banned more than 80,000 developer accounts associated with harmful apps.
There are several reasons for sideloading:
- The developer distributes an app directly from its own website
- An app is unavailable in your country or on Google Play
- An alternative app repository offers what you’re after, for example open-source software
- You need an enterprise, beta, or specialized app
- You want to install a version that is not currently offered through Google Play
But malware authors and online scammers use the same flexibility. They may impersonate banks, delivery services, government agencies, crypto platforms, news readers, or job recruiters, then urge victims to install an app to “secure” an account, receive a payment, or resolve an invented problem.
Google Play is not a free passGoogle Play has review processes, policy enforcement, developer controls, and Google Play Protect. It also runs ongoing checks after an app is published. Those measures meaningfully reduce risk, but they do not make every listing harmless or every developer trustworthy.
Threats that can still surface through official channels include:
- Trojans disguised as useful utilities, games, or financial apps
- Adware and apps that misrepresent their behavior
- Subscription traps and deceptive billing practices
- Data-harvesting apps that request more access than they need
- Sleeper apps that change behavior after passing an initial review
Google Play Protect checks Play Store apps before download and also scans apps from other sources. It can warn about, disable, or remove potentially harmful apps, but it should be viewed as one layer of security, not a substitute for scrutinizing an app before installing it.
Mobile protection, anywhere, anytime.In short, “available on Google Play” is a positive signal, not a security verdict.
Why sideloading requires attentionThe main difference between installing from a recognized store and downloading an APK from elsewhere is not simply the file format. It is the trust chain.
When you sideload, you may have fewer assurances about:
- Who created the app
- Whether the file has been altered or repackaged
- Whether the download site is impersonating a legitimate developer
- Whether you will receive genuine updates
- Whether a scammer is manipulating you into disabling security protections
Social engineering is often the decisive factor. A convincing caller, pop-up, text, or chat message may insist that installing an app is urgent. The attacker’s goal is often to make the victim bypass warnings before they have time to question the request.
Treat any unexpected request to install an app as suspicious, especially when it comes with urgency, secrecy, a promise of money, or a claim that your bank, government, employer, or device provider requires it.
A legitimate bank, government agency, law-enforcement organization, or technical-support provider should not call or message you and instruct you to install an APK or weaken Android security settings.
How to sideload more safelySideload only when you have a specific reason for it, and make sure the decision came from you rather than an unexpected message or phone call.
- Start at the developer’s official site. Don’t use sponsored search results, random download portals, links sent by strangers, or lookalike domains.
- Verify the developer independently. Check the publisher’s official website, documentation, public code repository, and trusted community channels. The information supplied on the download page alone is not enough.
- Prefer established repositories. If an app is distributed outside Google Play, use a source with a strong reputation for provenance and signature verification where possible. For advanced users, it can be useful to compare an APK’s signing certificate or cryptographic hash against a value published by the developer. That is not practical for everyone, but it can help detect fakes.
- Do not install apps under pressure. End the call, close the chat, and independently research the claimed organization using contact details you find yourself.
- Keep Google Play Protect enabled. It scans apps during installation and periodically afterward, including apps installed from outside Google Play.
- Review permissions before and after installation. Be especially cautious if a simple app wants access to accessibility services, SMS messages, notifications, device administration, contacts, or screen recording.
- Keep Android and apps updated. Security fixes can protect against both operating-system flaws and known malicious app behavior.
- Use reputable mobile security software. A separate security layer can help identify risky behavior and provide additional visibility into potentially unwanted or malicious apps.
- Remove permissions and uninstall apps you no longer trust or use. An app that seemed harmless at installation can become a liability if its developer abandons it or changes direction.
Google is rolling out Advanced Flow for installing apps from developers that have not completed Android’s new identity-verification process. The feature is intended for users who understand the risks of installing unverified software but still need that flexibility.
The design is notable because it targets social-engineering attacks as well as malware. Instead of allowing an immediate, one-tap override, the flow requires users to:
- Enable developer mode in system settings. This is easy enough and helps prevent accidental or one-tap bypasses often used in high-pressure scams.
- Complete a quick safety check to make sure that no one is talking you into turning off your security. Scammers often pressure victims into disabling protections.
- Restart your device, which cuts off any remote access or active phone calls a scammer might be using to guide you.
- Wait one day, then confirm the change using biometrics, such as fingerprint or face unlock, or your device PIN. This one-time, one-day delay breaks the urgency scammers rely on, giving you time to think.
Once you have completed the process, you can choose to allow installs from unverified developers for seven days or indefinitely.
Advanced Flow does not mean Google Play is risk-free, nor does it make unverified apps inherently malicious. Developer verification establishes accountability: It connects an app to a verified developer identity, but it does not establish that every app is benign or suitable for every user.
At the end of the day, it’s up to you. Install apps because you chose them after checking the source, not because someone else manufactured an emergency.
Whether an app comes from Google Play or an external source, pause before installing. Check who made it, why it needs the permissions it asks for, whether the download route is trustworthy, and refuse when a stranger is trying to rush you. That little friction is a feature, not just a nuisance.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
Scammers are using fake crypto AML checkers to drain your wallet
Scammers are creating fake crypto wallet-checking sites that promise to tell you whether a wallet is linked to suspicious activity. Instead, they try to trick you into giving them access to your crypto.
What real AML checking looks likeAML stands for anti-money laundering. These are rules that require banks and other regulated businesses to screen customers for ties to crime. It’s designed to prevent cybercriminals from hiding or moving illegally obtained money.
In the crypto world, this usually means checking whether a wallet address has links to hacks, scams, sanctioned entities, or other suspicious activity based on its transaction history.
For a basic wallet check, the service only needs the wallet’s public address. You don’t need to connect your wallet, approve anything, or sign a transaction. It’s just a lookup.
If an AML checker asks you to connect your wallet rather than simply enter its public address, treat that as a warning sign.
How the scam worksThese sites look professional. Many pretend to be the legitimate service, AMLBot, or use names such as “AML Check,” copying the logo, layout, and language of legitimate wallet-screening services.
Fake AMLBot siteReal AMLBot siteYou’re invited to choose your cryptocurrency, click Check Wallet, and connect your wallet to get your results.
Connecting a wallet by itself isn’t enough to steal your crypto. It reveals your public wallet address, which the scammers use to create a transaction specifically for your wallet. That transaction is then sent to your wallet for you to approve.
The site is designed to get the victim to approve a transaction generated by the scammers. You should never approve a transaction you don’t understand or weren’t expecting.
Once the site knows your public address, it can also see the assets associated with it and tailor the scam accordingly.
One version we reviewed makes the process look like a genuine security check. A progress bar displays messages such as “Checking wallet history…” and “Verifying compliance…”
Partway through, the site shows a fake error claiming the wallet needs a small top-up to “cover the fee” before the check can finish. Clicking Retry plays the same progress animation again before producing a reassuring “Clean, Low Risk” result and offering a report to download, regardless of whether a genuine check took place.
The progress bars, error messages, and final result are all designed to make the process feel legitimate.
Why the scam worksPeople using an AML checker are already trying to protect themselves. The scam takes advantage of that caution by making each step look like part of a normal security check.
The fake progress bar suggests that something is being analyzed. The supposed fee makes the interruption seem plausible. And the “Clean, Low Risk” result makes it appear that the check worked.
We’ve also seen the same basic design and process appear under several different names and logos, suggesting the same scam template is being reused and rebranded.
What to do if you connected a walletWhat you need to do depends on what happened.
- If you only connected your wallet: Disconnect the suspicious site from your wallet. Simply connecting shouldn’t give the site permission to move your crypto.
- If you approved access to your tokens: Check your wallet for token permissions you don’t recognize and revoke them. Your wallet provider may have an approval checker that shows which apps or smart contracts have permission to access your tokens.
- If you confirmed a transaction or signed something you didn’t understand: Check your recent wallet activity. If you think your assets may be at risk, move your remaining funds to a new wallet.
- If you entered your recovery phrase or private key: Treat the wallet as compromised and move your assets to a new wallet with a new recovery phrase.
- If you downloaded something from the site: Don’t open it. Delete it and run a malware scan.
- If you’ve already lost money: Be wary of anyone who contacts you offering to recover it for a fee. Recovery scams commonly target people who have already had crypto stolen.
Crypto transactions generally can’t be reversed once they’re confirmed, so acting quickly matters if you’ve approved something suspicious.
How to spot a fake AML checkerBefore using a wallet-checking service, check the website address carefully, especially if you reached it through an ad, social media post, message, or search result.
Be particularly cautious if an AML checker asks you to connect your wallet, approve unexpected access to your tokens, confirm a transaction, send crypto to complete a check, or share your recovery phrase or private key.
A basic wallet screening only needs the public wallet address. It shouldn’t require access to your crypto.
Pro tip: Malwarebytes Browser Guard can block known scam, phishing, and malicious websites before you interact with them.
Indicators of Compromise (IOCs)Domains
amlbot-clear[.]com
audittrust[.]shop
bitget-aml[.]com
search-aml[.]net
swapstoken[.]app
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Update Chrome now: Two critical vulnerabilities fixed
Chrome is rolling out an update for its desktop versions. The update includes 15 security fixes, two of which address critical buffer overflow vulnerabilities.
The stable channel has been updated to 151.0.7922.169/.170 for Windows and Mac, and 151.0.7922.169 for Linux.
How to update ChromeIf you don’t want to wait for the rollout to reach you, manually updating is easy.
The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or if something goes wrong, such as an extension preventing the update.
To update manually, click the More menu (three dots), then go to Settings > About Chrome. If an update is available, Chrome will start downloading it automatically. Restart Chrome to complete the update, and you’ll be protected against these vulnerabilities.
Chrome 151.0.7922.170 is up to dateYou can find an explanation of the version numbering system and step-by-step instructions in our guide: How to update Chrome on every operating system.
Technical detailsAs mentioned earlier, the two vulnerabilities rated critical in this update are both buffer overflow flaws.
A buffer overflow is a type of software vulnerability that exists when an area of memory within a software application reaches its address boundary and writes into an adjacent memory region. In software exploit code, two common areas that are targeted for overflows are the stack and the heap.
The first one is tracked as CVE-2026-76034 and was found in WebGL (Web Graphics Library). WebGL is a JavaScript application programming interface (API) that allows web browsers to render interactive 2D and 3D graphics smoothly. A remote attacker can exploit this vulnerability to execute arbitrary code outside the sandbox via a crafted HTML page.
The second critical vulnerability is tracked as CVE-2026-76036 and sits in Dawn, the underlying open-source library that implements the WebGPU standard. It acts as a bridge, allowing web apps to talk directly to computer graphics hardware. This vulnerability also allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Chrome vulnerabilities that enable remote code execution outside the browser sandbox are particularly valuable to attackers because they can turn a visit to a malicious or compromised website into direct code execution on the underlying operating system, often without requiring additional exploitation steps.
The sandbox normally limits a compromised renderer process’s access to files, devices, and other sensitive system resources. Bypassing it substantially expands an attacker’s ability to steal data, establish persistence, deploy malware, or move further through an enterprise environment.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
