Back Cybernews Hackers bait users with popular VPNs, but fake installers lead to complete compromise
A click on a wrong result or a mistype can lead users to download malware instead of a legitimate VPN app. Security researchers at ThreatLocker warn of hackers using trojanized installers masquerading as Kuailian VPN (LetsVPN) – installing them would lead to complete system compromise.
LetsVPN is a popular tool for bypassing internet censorship in China. However, attackers are distributing a legitimate, signed installer alongside malware packaged in an MSI installer. The analyzed file was named “Kuailian_win-setup.86.msi.”
“This installer drops and executes an encrypted RAT (remote access trojan) that provides attackers with complete control over a victim’s machine and its data,” Threat Locker warns in a report.
The fake installer drops malware first, and only then continues to install the actual VPN app to trick unsuspecting users into thinking the installation completed successfully.
The malware initially acts as a shellcode loader that connects to the command-and-control (C2) server. The final RAT payload is loaded into memory and never touches the disk, evading file-based detection.
To communicate with attackers, the malware has a selection of 40 possible C2 servers.
Some of the domain names are variations of “Nishihaoren,” which, when translated from simplified Chinese, means “you are a good person.” Therefore, the researchers dubbed the malware “GoodPersonRAT”.
Once running on the victim system, the RAT waits for commands and offers an extensive feature set. The malware is capable of monitoring the screen, logging keystrokes, stealing clipboard content, scanning local browsers for cookies, profiles, login data, and history, targeting Telegram Desktop. The attacker also has full control over the victim’s computer to run any commands.
Even though the malware doesn’t leave files, it establishes persistence through service registration, and SYSTEM-level scheduled tasks that auto-start and initialize before user logon.
Curious what others think this story? Contribute your thoughts to the debate below.
“This Trojan installer is a direct attack on LetsVPN users, many of whom operate behind the Great Firewall of China,” the researchers warn.
Attackers may clone popular VPNs and apps to bundle malicious installers. The ThreatLocker Threat Intelligence team warns users and administrators to verify the integrity of software bundles before installing them.
The report doesn't specify the actual distribution vector. Attackers usually prey on their victims using malvertising, SEO/ poisoning, phishing links, fake download sites, forums, and direct messages.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
