Google warns of legit VPN apps being used to infect devices with malware

Teilen:

So-called Playfulghost attackers use both SEO poisoning and phishing tactics

Attackers are reportedly using popular VPN applications as a backdoor to inject malware and gain remote control of infected devices.

This is the worrying finding coming from Google’s Managed Defense team, which shed light on how malicious actors employ SEO poisoning tactics to spread what’s known as Playfulghost malware.

“The malware is bundled with popular applications, like LetsVPN, and distributed through SEO poisoning,” wrote the expert. “This involves manipulating search engine results to make the bundled software appear at the top of searches, making it seem like a legitimate download.”

Phishing attacks, meaning malicious emails that trick users into clicking on dangerous links to download malware, are another known distribution method.

The dangers of the Playfulghost backdoor

As Google’s expert explains in a blog post, Playfulghost is “a backdoor that shares functionality with Gh0st RAT.” The latter is a remote administration tool that has been known among the security community since 2008.

Playfulghost, however, has distinct traffic patterns and encryption that differentiate it from the known threat.

Attackers use both phishing and SEO poisoning tactics to trick victims into downloading the malicious software on their devices. In one case, the Google expert explains, the victim was tricked into opening an infected image file to execute Playfulghost from a remote server.

Similarly, SEO poisoning tactics involved using trojanized virtual private network (VPN) apps to download Playfulghost components from a remote server into the victims’ devices (see the GIF below).

Playfulghost is a particularly dangerous strain of malware that enables attackers to remotely execute a range of activities once the device is infected. Data mining capabilities include keylogging, screenshot capture, and audio capture. Attackers can also carry on file management activities like opening, deleting, and writing new files, among other things.

You can read all of Playfulghost’s technical details in Google’s blog post here.

(Image credit: Google)

The Playfulghost malware case is yet another reminder to remain on alert when downloading new software.

Sticking to reputable names, like the best VPN applications, on a search engine isn’t enough to stay safe. The same goes for App Stores, unfortunately, as copycat malicious applications may slip through the security checks.

I recommend going through reputable sources, like TechRadar, whenever possible and using the on-page links to download new software – whether this is a new VPN, antivirus, or password manager tool. Heading directly to the provider’s official website is another way to ensure your download is a legitimate and secure application.

If you notice your device acting oddly, I suggest looking for applications you don’t recognize and running a malware removal service if possible. You should also consider a system reboot to eradicate the potential threat.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:20 am, Jan. 15, 2025
Wetter-Symbol 9°C
L: 9° | H: 10°
overcast clouds
Luftfeuchtigkeit: 93 %
Druck: 1035 mb
Wind: 2 mph
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 9 km
Sonnenaufgang: 7:59 am
Sonnenuntergang: 4:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
9° | 10°°C 0 mm 0% 3 mph 98 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
5° | 9°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Fr. Jan. 17 9:00 pm
Wetter-Symbol
3° | 7°°C 0 mm 0% 4 mph 93 % 1036 mb 0 mm/h
Sa. Jan. 18 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 3 mph 89 % 1033 mb 0 mm/h
So. Jan. 19 9:00 pm
Wetter-Symbol
2° | 6°°C 0 mm 0% 4 mph 89 % 1024 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 2 mph 90 % 1034 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 3 mph 90 % 1033 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 3 mph 97 % 1034 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 3 mph 98 % 1034 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 95 % 1033 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 96 % 1034 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€94,004.74
0.26%
Ethereum(ETH)
€3,112.99
-0.51%
XRP(XRP)
€2.74
9.92%
Fesseln(USDT)
€0.97
-0.01%
Solana(SOL)
€181.50
-0.49%
Dogecoin(DOGE)
€0.343767
1.08%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000020
-1.10%
Pepe(PEPE)
€0.000016
-1.62%
Peanut das Eichhörnchen(PNUT)
€0.54
-8.70%
Nach oben scrollen