Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Gladinet file sharing zero-day brings patched flaw back from the dead

    October 13, 2025

    Buying an Android smartwatch? I found a model that’s highly functional and affordable

    October 13, 2025

    WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More

    October 13, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Gladinet file sharing zero-day brings patched flaw back from the dead
    • Buying an Android smartwatch? I found a model that’s highly functional and affordable
    • WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More
    • Aisuru’s 30 Tbps botnet traffic crashes through major US ISPs
    • See It Here First at TechCrunch Disrupt 2025
    • Final Flash Sale: Save up to $624 on Disrupt 2025 Passes
    • I tested a Windows laptop with a tandem OLED, and it’s spoiled working on other displays for me
    • Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Apps»Hackers are hiding powerful info-stealing malware in fake free VPNs downloaded from GitHub, don’t get tricked
    Apps

    Hackers are hiding powerful info-stealing malware in fake free VPNs downloaded from GitHub, don’t get tricked

    TechurzBy TechurzJuly 13, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Malware
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • GitHub repositories host malware disguised as tools that gamers, and privacy-seekers are likely to download
    • The fake VPN campaign drops malware straight into AppData and hides it from plain view
    • Process injection through MSBuild.exe allows this malware to operate without triggering obvious alarms

    Security experts have warned of an emerging new cyber threat involving fake VPN software hosted on GitHub.

    A report from Cyfirma outlines how malware disguises itself as a “Free VPN for PC” and lures users into downloading what is, in fact, a sophisticated dropper for the Lumma Stealer.

    The same malware also appeared under the name “Minecraft Skin Changer,” targeting gamers and casual users in search of free tools.


    You may like

    Sophisticated malware chain hides behind familiar software bait

    Once executed, the dropper uses a multi-stage attack chain involving obfuscation, dynamic DLL loading, memory injection, and abuse of legitimate Windows tools like MSBuild.exe and aspnet_regiis.exe to maintain stealth and persistence.

    The campaign’s success hinges on its use of GitHub for distribution. The repository github[.]com/SAMAIOEC hosted password-protected ZIP files and detailed usage instructions, giving the malware an appearance of legitimacy.

    Inside, the payload is obfuscated with French text and encoded in Base64.

    “What begins with a deceptive free VPN download ends with a memory-injected Lumma Stealer operating through trusted system processes,” Cyfirma reports.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Upon execution, Launch.exe performs a sophisticated extraction process, decoding and altering a Base64-encoded string to drop a DLL file, msvcp110.dll, in the user’s AppData folder.

    This particular DLL remains concealed. It is loaded dynamically during runtime and calls a function, GetGameData(), to invoke the last stage of the payload.

    Reverse engineering the software is challenging because of anti-debugging strategies like IsDebuggerPresent() checks and control flow obfuscation.

    This attack uses MITRE ATT&CK strategies like DLL side-loading, sandbox evasion, and in-memory execution.

    How to stay safe

    To stay protected from attacks like this, users should avoid unofficial software, especially anything promoted as a free VPN or game mod.

    The risks increase when running unknown programs from repositories, even if they appear on reputable platforms.

    Files downloaded from GitHub or similar platforms should never be trusted by default, particularly if they come as password-protected ZIP archives or include obscure installation steps.

    Users should never run executables from unverified sources, no matter how useful the tool may seem.

    Ensure that you activate extra protection by disabling the ability for executables to run from folders like AppData, which attackers often use to hide their payloads.

    In addition, DLL files found in roaming or temporary folders should be flagged for further investigation.

    Watch out for strange file activity on your computer, and monitor for MSBuild.exe and other tasks in the task manager or system tools that behave out of the ordinary to prevent early infections.

    On a technical level, use best antivirus that offer behavior-based detection instead of relying solely on traditional scans, along with tools which provide DDoS protection and endpoint protection to cover a broader range of threats, including memory injection, stealthy process creation, and API abuse.

    You might also like

    dont Downloaded Fake free GitHub Hackers hiding infostealing malware powerful tricked VPNs
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article10 AI-Proof Jobs With Highest Pay, Fastest Growth
    Next Article Grok team apologizes for the chatbot’s ‘horrific behavior’ and blames ‘MechaHitler’ on a bad update
    Techurz
    • Website

    Related Posts

    Security

    Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns

    October 13, 2025
    Security

    New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login

    October 12, 2025
    Security

    Ready to ditch your Windows PC? I found a powerful mini PC that’s optimized for Linux

    October 12, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    CNET’s Daily Tariff Price Tracker: I’m Keeping Tabs on Changes as Trump’s Trade Policies Shift

    May 27, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    The Reason Murderbot’s Tone Feels Off

    May 14, 20259 Views

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    CNET’s Daily Tariff Price Tracker: I’m Keeping Tabs on Changes as Trump’s Trade Policies Shift

    May 27, 20258 Views
    Our Picks

    Gladinet file sharing zero-day brings patched flaw back from the dead

    October 13, 2025

    Buying an Android smartwatch? I found a model that’s highly functional and affordable

    October 13, 2025

    WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More

    October 13, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.