Data Breach

Google warns of legit VPN apps being used to infect devices with malware

Teilen:

So-called Playfulghost attackers use both SEO poisoning and phishing tactics

Attackers are reportedly using popular VPN applications as a backdoor to inject malware and gain remote control of infected devices.

This is the worrying finding coming from Google’s Managed Defense team, which shed light on how malicious actors employ SEO poisoning tactics to spread what’s known as Playfulghost malware.

“The malware is bundled with popular applications, like LetsVPN, and distributed through SEO poisoning,” wrote the expert. “This involves manipulating search engine results to make the bundled software appear at the top of searches, making it seem like a legitimate download.”

Phishing attacks, meaning malicious emails that trick users into clicking on dangerous links to download malware, are another known distribution method.

The dangers of the Playfulghost backdoor

As Google’s expert explains in a blog post, Playfulghost is “a backdoor that shares functionality with Gh0st RAT.” The latter is a remote administration tool that has been known among the security community since 2008.

Playfulghost, however, has distinct traffic patterns and encryption that differentiate it from the known threat.

Attackers use both phishing and SEO poisoning tactics to trick victims into downloading the malicious software on their devices. In one case, the Google expert explains, the victim was tricked into opening an infected image file to execute Playfulghost from a remote server.

Similarly, SEO poisoning tactics involved using trojanized virtual private network (VPN) apps to download Playfulghost components from a remote server into the victims’ devices (see the GIF below).

Playfulghost is a particularly dangerous strain of malware that enables attackers to remotely execute a range of activities once the device is infected. Data mining capabilities include keylogging, screenshot capture, and audio capture. Attackers can also carry on file management activities like opening, deleting, and writing new files, among other things.

Dangers of Playfulghost Malware

You can read all of Playfulghost’s technical details in Google’s blog post here.

(Image credit: Google)

The Playfulghost malware case is yet another reminder to remain on alert when downloading new software.

Sticking to reputable names, like the best VPN applications, on a search engine isn’t enough to stay safe. The same goes for App Stores, unfortunately, as copycat malicious applications may slip through the security checks.

I recommend going through reputable sources, like TechRadar, whenever possible and using the on-page links to download new software – whether this is a new VPN, antivirus, or password manager tool. Heading directly to the provider’s official website is another way to ensure your download is a legitimate and secure application.

If you notice your device acting oddly, I suggest looking for applications you don’t recognize and running a malware removal service if possible. You should also consider a system reboot to eradicate the potential threat.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:33 pm, März 27, 2025
Wetter-Symbol 13°C
L: 13° | H: 13°
klarer Himmel
Luftfeuchtigkeit: 69 %
Druck: 1017 mb
Wind: 11 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 5%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:46 am
Sonnenuntergang: 6:24 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
10° | 13°°C 0 mm 0% 7 mph 81 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 13°°C 0.38 mm 38% 13 mph 86 % 1016 mb 0 mm/h
Sa. März 29 9:00 pm
Wetter-Symbol
4° | 13°°C 0 mm 0% 9 mph 78 % 1022 mb 0 mm/h
So. März 30 9:00 pm
Wetter-Symbol
8° | 17°°C 0 mm 0% 11 mph 93 % 1025 mb 0 mm/h
Mo. März 31 9:00 pm
Wetter-Symbol
8° | 15°°C 0 mm 0% 9 mph 79 % 1027 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 69 % 1017 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 81 % 1017 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
7° | 7°°C 0 mm 0% 7 mph 85 % 1015 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 8 mph 84 % 1013 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 9 mph 86 % 1012 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
10° | 10°°C 0.28 mm 28% 9 mph 85 % 1011 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
13° | 13°°C 0.38 mm 38% 12 mph 49 % 1012 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
12° | 12°°C 0 mm 0% 13 mph 42 % 1012 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€80,621.17
0.34%
Ethereum(ETH)
€1,858.54
-0.25%
Fesseln(USDT)
€0.93
-0.01%
XRP(XRP)
€2.16
-2.33%
Solana(SOL)
€128.21
-0.13%
USDC(USDC)
€0.93
0.00%
Dogecoin(DOGE)
€0.176262
-2.44%
Shiba Inu(SHIB)
€0.000013
-2.83%
Pepe(PEPE)
€0.000007
-1.17%
Peanut das Eichhörnchen(PNUT)
€0.213778
7.85%
Nach oben scrollen