
Fake Advisors, ClickFix, and Chrome Sync Spying
This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…
Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to trick people into installing credential and crypto-stealing malware, and another uses hundreds of imposter GitHub repositories to lure developers into downloading an infostealer. Both attacks rely on victims trusting familiar brands or “free” tools and then clicking a download and running what looks like legitimate software.
Two separate but related campaigns relied on victims trusting familiar software brands. In the first, a financially motivated actor tracked as UAT-11795 disguised malicious installers as legitimate tools such as WebEx, Zoom, MobaXterm, DBeaver, and FaceIT. Researchers believe the group likely used ClickFix-style social engineering to convince victims to run a malicious HTA file, which then triggered an altered installer that deployed a remote access trojan capable of stealing browser and cryptocurrency data.
In the second campaign, attackers built nearly 300 fake GitHub repositories that impersonated premium security products, crypto tools, and developer utilities. These repos targeted people searching for free versions of paid software. Victims who clicked the download link received a rotating ZIP archive containing a legitimate, signed WinGUP updater paired with a trojanized DLL, a technique that let the malware side-load without triggering obvious suspicion.
Both campaigns exploited trust in recognizable names and the appeal of free tools. The fake GitHub landing pages went further than a simple link: they used client-side scripts to render customized branding and spoofed trust badges, making the download pages look more credible to developers who might otherwise be cautious. Pairing a legitimate signed updater with a malicious DLL also helped the payload blend in, since the visible executable was genuine software.
The most durable defense is a habit of downloading software only from confirmed official vendor sources rather than search results, forum links, or repository mirrors. Developers and engineering teams in particular should treat “free” offers of paid tools on code-sharing platforms as a red flag and verify publisher identity and project history before running anything. Because these campaigns specifically targeted browser data, crypto wallets, and platform tokens for services like Discord, Steam, and Telegram, teams should also reinforce that testing unfamiliar tools happens in isolated, controlled environments, and that suspicious repositories or download links get reported quickly so they can be taken down, as GitHub has already done for many of the identified fake repos in this case.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A Russian financially motivated actor, UAT-11795, disguised malicious installers as legitimate software including WebEx, Zoom, MobaXterm, DBeaver, and FaceIT, likely relying on ClickFix-style social engineering to get victims to execute a malicious HTA file before deploying a RAT that stole browser and crypto data.
Threat actors published nearly 300 fake GitHub repositories impersonating premium security products, crypto tools, and developer utilities, then used spoofed landing pages with fake trust badges to convince victims to download a rotating ZIP containing a legitimate signed WinGUP updater paired with a trojanized DLL.
The infostealer distributed through the fake repos targeted passwords, payment data, session cookies, and tokens for services like Discord, Steam, and Telegram, sending the data to a Russian-based command-and-control server.
Only download software from official vendor sources, treat unsolicited free versions of premium tools as high risk, and be skeptical of polished landing pages with trust badges since these can be faked.
You search GitHub for a free premium dev or crypto tool… find a repo that looks perfect… and it quietly steals every password you’ve got. One campaign uses trojan installers disguised as WebEx, Zoom, MobaXterm, DBeaver, even FaceIT. Another plants nearly 300 fake GitHub repos for 'free' premium tools. You click download, run the updater, and a hidden infostealer grabs passwords, payment data, and Discord or Steam tokens. Here’s the trick: the page looks official, with logos and fake trust badges. But the download isn’t from zoom.us or the real vendor site, and the GitHub repo is pushing you to an off-platform ZIP with an 'updater' plus random DLLs. That combo is the aha moment: legit brand, sketchy source. If a download isn’t coming straight from the official vendor site or our approved software portal, stop. Don’t run it, send the link or repo to security and let us check it first.

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools…

Cisco Talos reports a real, financially motivated campaign by a Russian-speaking group (UAT-11795) targeting organizations in the US and Europe. The attackers…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Researchers found thousands of malicious GitHub repositories designed to look like real developer tools, including hundreds posing as AI “Skills” and Model…