
Fake SSMS on GitHub Spreads Crypto-Stealing OkoBot
Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…
Researchers found real-world campaigns that trick people into downloading fake games, mods, cracks, or software installers. The download looks legitimate and shows an installer screen, but it silently runs a multi-stage infection that ultimately installs the Amatera Stealer to steal passwords and other sensitive data. The lures are delivered through fake download sites, itch.io pages, and common file-sharing services.
This campaign relies on fake downloads of games, mods, cracks, and software to get victims to run malware. The lure is delivered through fake download websites, itch.io pages, and common file-sharing services such as Wormhole, GoFile, Google Drive, and MEGA. Once a victim downloads the archive, it contains a file named Setup.exe. Opening that file starts a multi-stage infection chain. The victim typically sees what looks like a normal installer or loading screen while malicious code runs silently in the background, eventually deploying Amatera Stealer to collect passwords, wallet data, browser data, and other sensitive information.
In several observed cases, clicking a download link redirected the user through another fake download website before the final file was served, adding extra layers meant to obscure the true source of the malware. The infection chain also used techniques such as MSBuild abuse and EtherHiding, a method of retrieving command-and-control details from a public blockchain, to help the malware evade detection.
The attack works because it exploits normal user behavior around downloading free or unofficial software. People searching for game mods, cracks, or free versions of paid software are often willing to bypass official sources, and a convincing installer screen reinforces the illusion that the download is legitimate. The use of well-known, generally trusted file-sharing platforms for hosting the malicious files adds a false sense of safety, since the platform itself is not inherently suspicious, even though the file it hosts is malicious.
Employees and personal device users should be encouraged to download games and software only from official websites, trusted app stores, or established distribution platforms, and to treat cracked software, unofficial mods, and free versions of paid games with caution. Redirect-heavy download flows should be treated as a stopping point rather than something to click through. Before running any installer, it helps to check the contents of a downloaded archive for unexpected executables like Setup.exe. Finally, it is worth reinforcing that neither a professional-looking installer nor a familiar file-sharing service guarantees that a download is safe, since both appearances can be used to mask a malicious payload running in the background.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A user downloads what looks like a game, mod, crack, or software installer, often from a fake download site, itch.io page, or file-sharing service. Opening the archive runs a file named Setup.exe, which starts a multi-stage infection that eventually deploys Amatera Stealer while the victim sees a normal-looking installer screen.
According to the findings, Amatera Stealer is used to steal passwords, wallet data, browser data, and other sensitive information after the infection chain completes.
Warning signs include downloads from unofficial or unfamiliar sites, an archive that contains an unexpected executable like Setup.exe, and multiple redirects through different websites or file-sharing services before the file appears.
A familiar hosting service does not guarantee safety. The malicious files were distributed through services such as Wormhole, GoFile, Google Drive, and MEGA, so the source and legitimacy of the file itself still matter.
You search for a free game mod, click a download, and get a file called Setup.exe. Looks normal, right? Behind that Setup.exe, a multi-stage infection quietly drops Amatera Stealer. You see a legit-looking installer; in the background it abuses MSBuild and even uses EtherHiding on a public blockchain to fetch its command server. These campaigns use fake download sites, itch.io pages, and links that bounce through Wormhole, GoFile, Google Drive, or MEGA. A polished installer or familiar file-sharing logo does NOT mean the download is safe. If a download for a game, mod, or crack comes from unofficial sites or redirect-heavy links and drops a random Setup.exe, stop. Close it and get the software only from the official site or trusted store.

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

Researchers reported that scammers set up cloned piracy sites within hours of Christopher Nolan’s The Odyssey release to trick people looking for pirated…

Scammers quickly set up fake piracy pages for Christopher Nolan’s “The Odyssey” to trick people into either clicking a fake browser “Fix It Now” warning or…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…