PULSE NAME
Bogus website fakes virus scan, installs Venom Stealer instead
WHITE AlienVault 2026-03-27 Modified: 2026-04-08
3
IOCs
LOW VOLUME
A fake website impersonating Avast antivirus is tricking users into infecting their computers with Venom Stealer malware. The site runs a fake virus scan, claims to find threats, and prompts users to download a malicious file disguised as a system cleaner. The malware, identified as part of the Venom Stealer family, steals browser credentials, session cookies, cryptocurrency wallets, and other sensitive data. It uses evasion techniques like direct system calls and debugger checks to avoid detection. The stolen information is exfiltrated to a command-and-control server disguised as an analytics service. This campaign demonstrates a classic scare-and-fix scam, exploiting users' trust in reputable security brands to deliver malware.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Venom Stealer Quasar RAT StormKitty
Indicators of Compromise (3)
All FileHash-MD5 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0a32d6abea15f3bfe2a74763ba6c4ef5 2026-03-27
FileHash-SHA256 ecbeaa13921dbad8028d29534c3878503f45a82a09cf27857fa4335bd1c9286d 2026-03-27
domain app-metrics-cdn.com 2026-03-27