← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Bogus website fakes virus scan, installs Venom Stealer instead
A fake website impersonating Avast antivirus is tricking users into infecting their computers with Venom Stealer malware. The site runs a fake virus scan, claims to find threats, and prompts users to download a malicious file disguised as a system cleaner. The malware, identified as part of the Venom Stealer family, steals browser credentials, session cookies, cryptocurrency wallets, and other sensitive data. It uses evasion techniques like direct system calls and debugger checks to avoid detection. The stolen information is exfiltrated to a command-and-control server disguised as an analytics service. This campaign demonstrates a classic scare-and-fix scam, exploiting users' trust in reputable security brands to deliver malware.
MITRE ATT&CK & Malware Families
Indicators of Compromise (3)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 0a32d6abea15f3bfe2a74763ba6c4ef5 | — | 2026-03-27 | |
| FileHash-SHA256 | ecbeaa13921dbad8028d29534c3878503f45a82a09cf27857fa4335bd1c9286d | — | 2026-03-27 | |
| domain | app-metrics-cdn.com | — | 2026-03-27 |