Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Elon Musk’s last co-founder reportedly leaves xAI

    March 28, 2026

    From Moon hotels to cattle herding: 8 startups investors chased at YC Demo Day

    March 28, 2026

    Aetherflux reportedly raising Series B at $2 billion valuation

    March 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Elon Musk’s last co-founder reportedly leaves xAI
    • From Moon hotels to cattle herding: 8 startups investors chased at YC Demo Day
    • Aetherflux reportedly raising Series B at $2 billion valuation
    • OpenAI shuts down Sora while Meta gets shut out in court
    • VCs are betting billions on AI’s next wave, so why is OpenAI killing Sora?
    • 16 of the most interesting startups from YC W’26 Demo Day
    • Defense startup Shield AI lands $12.7B valuation, up 140%, after US Air Force deal
    • Silicon Valley’s two biggest dramas have intersected: LiteLLM and Delve
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Apps»Hackers are hiding powerful info-stealing malware in fake free VPNs downloaded from GitHub, don’t get tricked
    Apps

    Hackers are hiding powerful info-stealing malware in fake free VPNs downloaded from GitHub, don’t get tricked

    TechurzBy TechurzJuly 13, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Malware
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • GitHub repositories host malware disguised as tools that gamers, and privacy-seekers are likely to download
    • The fake VPN campaign drops malware straight into AppData and hides it from plain view
    • Process injection through MSBuild.exe allows this malware to operate without triggering obvious alarms

    Security experts have warned of an emerging new cyber threat involving fake VPN software hosted on GitHub.

    A report from Cyfirma outlines how malware disguises itself as a “Free VPN for PC” and lures users into downloading what is, in fact, a sophisticated dropper for the Lumma Stealer.

    The same malware also appeared under the name “Minecraft Skin Changer,” targeting gamers and casual users in search of free tools.


    You may like

    Sophisticated malware chain hides behind familiar software bait

    Once executed, the dropper uses a multi-stage attack chain involving obfuscation, dynamic DLL loading, memory injection, and abuse of legitimate Windows tools like MSBuild.exe and aspnet_regiis.exe to maintain stealth and persistence.

    The campaign’s success hinges on its use of GitHub for distribution. The repository github[.]com/SAMAIOEC hosted password-protected ZIP files and detailed usage instructions, giving the malware an appearance of legitimacy.

    Inside, the payload is obfuscated with French text and encoded in Base64.

    “What begins with a deceptive free VPN download ends with a memory-injected Lumma Stealer operating through trusted system processes,” Cyfirma reports.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Upon execution, Launch.exe performs a sophisticated extraction process, decoding and altering a Base64-encoded string to drop a DLL file, msvcp110.dll, in the user’s AppData folder.

    This particular DLL remains concealed. It is loaded dynamically during runtime and calls a function, GetGameData(), to invoke the last stage of the payload.

    Reverse engineering the software is challenging because of anti-debugging strategies like IsDebuggerPresent() checks and control flow obfuscation.

    This attack uses MITRE ATT&CK strategies like DLL side-loading, sandbox evasion, and in-memory execution.

    How to stay safe

    To stay protected from attacks like this, users should avoid unofficial software, especially anything promoted as a free VPN or game mod.

    The risks increase when running unknown programs from repositories, even if they appear on reputable platforms.

    Files downloaded from GitHub or similar platforms should never be trusted by default, particularly if they come as password-protected ZIP archives or include obscure installation steps.

    Users should never run executables from unverified sources, no matter how useful the tool may seem.

    Ensure that you activate extra protection by disabling the ability for executables to run from folders like AppData, which attackers often use to hide their payloads.

    In addition, DLL files found in roaming or temporary folders should be flagged for further investigation.

    Watch out for strange file activity on your computer, and monitor for MSBuild.exe and other tasks in the task manager or system tools that behave out of the ordinary to prevent early infections.

    On a technical level, use best antivirus that offer behavior-based detection instead of relying solely on traditional scans, along with tools which provide DDoS protection and endpoint protection to cover a broader range of threats, including memory injection, stealthy process creation, and API abuse.

    You might also like

    dont Downloaded Fake free GitHub Hackers hiding infostealing malware powerful tricked VPNs
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article10 AI-Proof Jobs With Highest Pay, Fastest Growth
    Next Article Grok team apologizes for the chatbot’s ‘horrific behavior’ and blames ‘MechaHitler’ on a bad update
    Techurz
    • Website

    Related Posts

    Opinion

    Delve did the security compliance on LiteLLM, an AI project hit by malware

    March 26, 2026
    Opinion

    Insight Partners scrubs investment post about Delve amid ‘fake compliance’ allegations

    March 24, 2026
    Opinion

    Delve halts demos, Insight Partners scrubs investment post amid ‘fake compliance’ allegations

    March 24, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Elon Musk’s last co-founder reportedly leaves xAI

    March 28, 2026

    From Moon hotels to cattle herding: 8 startups investors chased at YC Demo Day

    March 28, 2026

    Aetherflux reportedly raising Series B at $2 billion valuation

    March 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.