Categories: Ad Guardian Plus

Malware disguised as one of most used VPNs

A dangerous trojan replaced a popular VPN. The cybercriminals cloned the genuine website in order to trick visitors into downloading the dangerous trojan.

Researchers at Doctor Web discovered a harmful banking trojan disguised as the popular virtual private network, NordVPN. Win32.Bolik.2 was hidden alongside VPN downloads, from a website designed to be mistaken for the official NordVPN’s site.

The criminals behind the fake managed to both obtain a visual similarity to the original website and domain name, but also a valid SSL certificate, thanks to Let’s Encrypt, which allowed the fake website past browser security checks.

The website also came with the actual offer of the genuine website ($2.99/month), for three years. This is the second time the group strikes after the same hackers hid a banking trojan in the cloned sites of different corporate office programs. Then, they were caught distributing the file via a hacked free video editing service – VSDC.

The trojan sneaks in alongside a legitimate copy of the VPN or office software from these fake sites to steal data from clueless victims.

Doctor Web explained that “The Win32.Bolik.2 trojan is an improved version of Win32.Bolik.1 and has qualities of a multicomponent polymorphic file virus. Using this malware, hackers can perform web injections, traffic intercepts, keylogging and steal information from different bank-client systems.”

Doctor Web mentioned that the malware has been primarily targeted at English-speaking audiences, and the fake NordVPN page has already been visited thousands of times.

Laurentiu Titei

View Comments

Recent Posts

How To Install Windows Fax And Scan In Windows 11

It is a pain to send and receive faxes or scan documents in Windows, even…

5 hours ago

Change Windows 10 UEFI Boot Logo with HackBGRT Tool

Are you bored with the same UEFI boot logo that appears every time you turn…

2 days ago

Top Cybersecurity Threats in 2026

According to recent research from the World Economic Forum, the global cost of cybercrime will…

6 days ago

Epson L3150 Resetter Adjustment Program Free

Epson L3150 is a highly efficient all-in-one solution for wireless printing. This wireless EcoTank printer…

7 days ago

Where Are Drivers Stored in Windows 11 and 10

Knowing where drivers are stored in Windows 11/10 is especially helpful when you want to…

1 week ago

Safest Ways to Pay Online from a Windows PC

It may sound shocking, but nearly 43% of e-commerce consumers, i.e, around 2 in 5…

1 week ago