Skip to main content

Spyware found stealing Iranian user data via infected VPN installer





Spyware has been discovered stealing Iranian users data via an infected VPN installer, antivirus provider Bitdefender has revealed. 

The company's joint-research with cybersecurity firm Blackpoint found components of Iranian-made EyeSpy malware to be injected "through Trojanized installers of VPN software (also developed in Iran)."  

The majority of targets were within the country's borders, only a few victims were found to be based in Germany and the US. 

This is particularly concerning in a country like Iran, where using one the best VPN services has increasingly become a necessity. Whether this is for bypassing its strict online censorship, or preserving anonymity to avoid dangerous government surveillance. Most likely, a mix of both.  

At the same time, a harsh crackdown on Iranian VPN services might push people towards unsecure third-party vendor sites. This makes such a spyware campaign even more dangerous for Iranians' privacy and security.    

Anti-dissident spware?

"In light of the recent events, it’s possible that the targets are Iranians who want to access the internet via a VPN to bypass the country’s digital lockdown. Such malicious installers could plant spyware on people who pose a threat to the regime," Bitdefender's report noted. 

Developed by Iranian-based firm SecondEye, EyeSpy is a legit monitoring software sold to businesses as a way to monitor employees' activities working remotely.  

The attackers were observed using components of the legit application in a malicious way to infect users' downloading the Iranian-based VPN service 20Speed and spy on their activities.     

Once injected into a device, the malware can virtually spy on every activity and collect a tons of sensitive data. These include stored passwords, crypto-wallet data, documents and images, contents from clipboard, and logs key presses. 

"The components of the malware are scripts that steal sensitive information from the system and upload them to an FTP server belonging to SecondEye," Bitdefender explained.

"This can lead to complete account takeovers, identity theft and financial loss. Moreover, by logging keypresses, attackers can obtain messages typed by the victim on social media or e-mail, and this information can be used to blackmail the victims." 

The campaign appears to be active since May 2022, with a growing number of attacks following the wave of anti government protests began in September.  

VPN downloads in Iran skyrocketed following this, reaching a peak of more than 3,000% increase by the end of the month. 

A VPN is largely used by Iranian citizens to access restricted apps like Instagram and WhatsApp. But, as the government increasingly charges dissidents with harsh sentences even reaching the death penalty, extra security software is also a necessity to safeguard sensitive data.

While more and more Iranians download a virtual private network on their devices, authorities are hardly cracking down on reliable VPN services as a result. 

Many providers are currently blocked in Iran, meaning that third-party VPN installers are increasingly in popularity. According to Iran International, 20Speed VPN is actually one of the most popular websites where Iranians head to buy their VPN subscriptions. Over 100,000 are the active installations of its Android VPN app.

To fight against such malware campaigns, Bitdefender's experts recommend "using well-known VPN solutions downloaded from legitimate sources. Also, a security solution, like Bitdefender, can protect against information stealers."



Comments

Popular posts from this blog

Windows Copilot leak suggests deeper assimilation with Windows 11 features

Key Windows 11 features may soon be customizable as Microsoft further integrates its Windows Copilot AI assistant into the operating system. This tidbit comes from tech news site Windows Latest , which claims to have discovered new .json (JavaScript Object Notation) files within recent preview builds of Windows 11. These files apparently hint at future upgrades for the desktop AI assistant. For example, a “TaskManagerService-ai-plugin.json” was found which is supposedly a “plugin for Task Manager integration”. If this ever comes out, it could give users the ability to “monitor or close running apps using” Copilot. In total, six are currently tested and they affect various aspects of Windows 11. Next, there is an “AccessbilityTools-ai-plugin.json” that gives Copilot a way to “control accessibility [tools]. This would make it "easier for those with [a] disability to navigate through the system.” Third is “ai-plugin-WindowsSettings.json” for controlling important Windows 11 set...

Google Chrome releases security fix for this major flaw, so update now

Google says it has fixed a high-severity flaw in its Chrome browser which is currently being exploited by threat actors in the wild.  In a security advisory , the company described the flaw being abused and urged the users to apply the fix immediately.  "Google is aware that an exploit for CVE-2023-2033 exists in the wild," the advisory reads. Automatic updates The zero-day in question is a confusion weakness vulnerability in the Chrome V8 JavaScript engine, the company said. Usually, this type of flaw can be used to crash the browser, but in this case it can also be used to run arbitrary code on compromised endpoints.  The flaw was discovered by Clement Lecigne from the Google Threat Analysis Group (TAG). Usually, TAG works on finding flaws abused by nation-states, or state-sponsored threat actors. There is no word on who the threat actors abusing this flaw are, though. Read more > Patch Google Chrome now to fix this emergency security flaw > Emergency...

Samsung's ViewFinity S9 may be the monitor creatives have been searching for

Originally revealed during CES 2023 , Samsung has finally launched its ViewFinity S9 5K monitor after nine long months of waiting.  According to the announcement, the ViewFinity S9 is the company’s first-ever 5K resolution (5,120 x 2880 pixels) IPS display aimed primarily at creatives. IPS stands for in-plane switching , a form of LED tech offering some of the best color output and viewing angles on the market. This quality is highlighted by the fact that the 27-inch screen supports 99 percent of the DCI-P3 color gamut plus delivers 600 nits of brightness.  Altogether, these deliver great picture quality made vibrant by saturated colors and dark shadows. The cherry on top for the ViewFinity S9 is a Matte Display coating to “drastically [reduce] light reflections.”  As a direct rival to the Apple Studio Display , the monitor is an alternative for creative professionals looking for options. It appears Samsung has done its homework as the ViewFinity S9 addresses some of...