Oplichters klonen nu nieuwswebsites om je bankrekening te plunderen


If you downloaded the JDownloader installer during the compromise window (May 6-7), you are advised to verify the file.
JDownloader is a popular download management application, particularly favored for automated downloads from file-hosting services, video sites, and premium link generators.
The JDownloader website was confirmed to have been compromised on May 6-7, 2026. During that window, the Windows “Download Alternative Installer” links and the Linux shell installer were compromised. Other download options, including macOS, JAR files, Flatpak, Winget, and Snap packages remained safe.
Users that applied updates during that period were not affected. The malicious Windows installers deployed a Python-based remote access Trojan (RAT).
The developers confirmed the breach on May 7, immediately taking the website offline for investigation. After security patches were applied and server configurations hardened, the website was restored on May 8-9 with verified clean installer links. The attack vector was identified as an unpatched CMS security bug that allowed attackers to modify access control lists without authentication.
The developers advised users to verify that their installers have the proper digital signatures from “AppWork GmbH,” which compromised versions lacked.
A full system scan with a trusted anti-malware solution never hurts either.
Malwarebytes blocks the domains contacted by the RAT.
![Malwarebytes blocks parkspringhotel[.]com](../themes/icons/grey.gif)
We don’t just report on threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
If you downloaded the JDownloader installer during the compromise window (May 6-7), you are advised to verify the file.
JDownloader is a popular download management application, particularly favored for automated downloads from file-hosting services, video sites, and premium link generators.
The JDownloader website was confirmed to have been compromised on May 6-7, 2026. During that window, the Windows “Download Alternative Installer” links and the Linux shell installer were compromised. Other download options, including macOS, JAR files, Flatpak, Winget, and Snap packages remained safe.
Users that applied updates during that period were not affected. The malicious Windows installers deployed a Python-based remote access Trojan (RAT).
The developers confirmed the breach on May 7, immediately taking the website offline for investigation. After security patches were applied and server configurations hardened, the website was restored on May 8-9 with verified clean installer links. The attack vector was identified as an unpatched CMS security bug that allowed attackers to modify access control lists without authentication.
The developers advised users to verify that their installers have the proper digital signatures from “AppWork GmbH,” which compromised versions lacked.
A full system scan with a trusted anti-malware solution never hurts either.
Malwarebytes blocks the domains contacted by the RAT.
![Malwarebytes blocks parkspringhotel[.]com](../themes/icons/grey.gif)
We don’t just report on threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
| Figure 1 - Ransom message, part 1 |
| Figure 2 - Ransom message, part 2 |
JIGSAW RANSOMNIX 2018
I WANT TO PLAY A GAME!
Now Pay 0.2 BTC
OR
Payment will increase by
0.1
BTC each day after
00:00:00
Your Key Will Be Deleted
Your Bill till now 2.4000000000000004 BTC
Dear manager, on
Fri Apr 06 2018 02:08:34 GMT+0100 (GMT Summer Time)
your database server has been locked, your databases files are encrypted
and you have unfortunately "lost" all your data, Encryption was produced using
unique public key RSA-2048 generated for this server.
To decrypt files you need to obtain the private key.
All encrypted files ends with .Crypt
Your reference number: 4027
To obtain the program for this server, which will decrypt all files,
you need to pay 0.2 bitcoin on our bitcoin address 1VirusnmipsYSA5jMv8NKstL8FkVjNB9o (today 1 bitcoin was around 15000 $).
After payment send us your number on our mail crypter@cyberservices.com and we will send you decryption tool (you need only run it and all files will be decrypted during a few hours depending on your content size).
Before payment you can send us one small file (100..500 kilobytes) and we will decrypt it!
It's your guarantee that we have decryption tool. (use your reference number as a subject to your message)
We don't know who are you, All what we need is some money.
Don't panic if we don't answer you during 24 hours. It means that we didn't received your letter and write us again.
You can use one of that bitcoin exchangers for transfering bitcoin.
https://localbitcoins.com
https://www.kraken.com
You dont need install bitcoin programs - you need only use one of this exchangers or other exchanger that you can find in www.google.com for your country.
Please use english language in your letters. If you don't speak english then use https://translate.google.com to translate your letter on english language.
You do not have enough time to think each day payment will increase by
0.1 BTC and after one week your privite key will be deleted and your files will be locked for ever.
People use cryptocurrency for bad choices,
but today you will have to use it to pay for your files!
It's your choice!
| Figure 3 - JS function |