Malware Bytes
Fake popular sites offer a free app, instead take over PCs
A website built to look almost exactly like CNN’s homepage is telling visitors to download “the new CNN app.” But it’s not CNN’s app, and has nothing to do with the news company.
The campaign doesn’t stop at CNN. It also uses fake Stremio and Avast installers hosted on similarly convincing lookalike sites, all targeting Windows users. The installers are part of the same campaign to trick people into installing legitimate remote-management software that’s already linked to the attacker’s account.
Instead of downloading the software they expected, victims install O&O Syspectr, a genuine, digitally signed remote administration tool used by IT teams to manage computers. In the wrong hands, that tool can give an attacker remote access to a victim’s PC, allowing them to run commands, install additional software, or explore files and data. The CNN, Avast, and Stremio lures all point back to the same Syspectr account.
Another lookalike site uses a fake crypto-mining browser game instead of a trusted brand, but delivers the same software from a different Syspectr account.
Here’s what we found, why your antivirus has no reason to stop it, and the one 10-second check that would have caught it every time.
What the fake CNN page looks likeThe site copies CNN’s real homepage closely enough that most people wouldn’t look twice. It has current headlines, the same layout, and even a red “Live Updates” tag on a real story. A pop-up interrupts almost immediately: “Get the latest news first in the new CNN app—it’s live and free,” with a red Download button underneath.
The file behind that button is named CNN_App.setupad4693fd-d903-4791-8f58-975261c93ca2.exe—the same Syspectr installer that shows up under different branding elsewhere, down to the account ID embedded in the filename.
The same trick, impersonating other brandsA lookalike site at avast-premium[.]shop mimics Avast’s real download page closely, including the logo, review scores, and a blue “Free download” button for “Avast One.” The file behind it is named AVAST_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe.
Another malicious site, stremiotv[.]online, copies Stremio, a legitimate media-center app. The file it pushes visitors to download is named Stremio_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe.
Both carry the same account ID found in the CNN installer.
By impersonating trusted brands, the attackers trick visitors into installing the legitimate O&O Syspectr remote-access tool, which gives the attackers remote access to the victims’ computers.
Not every lure needs a trusted brand, however.
syncminer[.]xyz invents its own hook instead: an “idle miner” browser game showing a slowly-ticking cryptocurrency balance, with a “Download Miner Plugin” button promising faster payouts. The identical site also runs at idleminer[.]pro with the same layout, same game, and same download.
Both distribute the same file, named oo-syspectr-setup9158bf2a-ff25-4290-b96c-2dc5eb310391.exe outright, carrying its own account ID that is different from the CNN, Avast, and Stremio lures we saw.
It’s not malware, which is why antivirus can miss itEvery one of these files is a real, digitally signed piece of software from O&O Software GmbH, a legitimate German company. Syspectr is sold openly to IT departments and gives an operator remote desktop control and an admin-level command line on whatever machine it’s installed on.
That’s why antivirus software may not stop it. Antivirus is designed to detect malicious software, not flag a legitimately signed business tool just because of how it arrived on a computer. The attacker only has to convince victims to install a legitimate remote-management tool that’s already linked to the attacker’s account.
The 10-second check that gives it awayOn Windows, right-click any installer like this, choose Properties, and open the Details tab. Two fields—File description and Product name—identify every installer we examined as O&O Syspectr, alongside a copyright notice for O&O Software GmbH.
The filename can be changed by anyone distributing the file, but those embedded details come from the signed software itself. Changing them would invalidate the digital signature, so they reveal what the installer really is.
How we know these are connectedEvery Syspectr installer includes the account ID of whoever generated it, embedded directly in the filename. The CNN-, Avast-, and Stremio-branded files all carry the exact same account ID, showing they were created from a single Syspectr account and simply reskinned for different lures.
The Syspectr installer distributed through the fake crypto-mining game carries a different account ID, suggesting either a second operator using the same playbook or the same group operating under another account.
What this tool can actually doSyspectr is designed to let IT administrators manage computers remotely. Depending on the subscription level, that can include viewing system information, monitoring running processes and services, managing Microsoft Defender, and restricting USB devices.
The paid plans add the features that matter most to attackers. They allow an operator to remotely control the victim’s computer, browse files, run commands, install additional software, and make changes to the system as though they were sitting in front of it. Higher tiers add tools for managing large numbers of devices and, on compatible hardware, even allow remote access when Windows won’t boot.
These remote-control features aren’t available on free Syspectr accounts. They require a Premium subscription or higher.
O&O Software responseO&O responded quickly. Within days, the company disabled Remote Desktop and Remote Console access for free Syspectr accounts, restricting both to paid plans only.
O&O has since identified and suspended the abusive accounts, also blocking them from adding new devices. O&O’s analysis found the attackers relied exclusively on Remote Console, not Remote Desktop. The company says it will keep scanning for this pattern and tighten restrictions further if needed.
It’s a solid response and O&O clearly has a handle on how the abuse is happening. Not every vendor moves this quickly or this effectively when their software gets abused.
How to protect yourself- Only download software from the vendor’s actual website. Search results and ads can lead to convincing fakes.
- Before running any installer you’re unsure about, on Windows you can right-click it, open Properties > Details, and check the File description and Product name fields.
- If you find O&O Syspectr installed and didn’t set it up yourself, uninstall it through Settings > Apps and run a full antivirus scan.
- If you ran an installer like this recently, change passwords for anything you accessed on that machine afterward from a clean machine.
- Protect yourself while browsing online. Malwarebytes Browser Guard blocks known scam and lookalike pages before you land on them.
Fake download sites don’t always deliver malware. Sometimes they deliver legitimate software that’s been weaponized by the person distributing it. That’s why it’s important to download software from the real vendor and, if something doesn’t feel right, check what the installer actually is before you run it.
Indicators of Compromise (IOCs)Account ID 4693fd-d903-4791-8f58-975261c93ca2:
- app.cnn-news[.]net → CNN_App.setupad4693fd-d903-4791-8f58-975261c93ca2.exe
- avast-premium[.]shop → AVAST_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe
- stremiotv[.]online → Stremio_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe
Account ID 9158bf2a-ff25-4290-b96c-2dc5eb310391:
- syncminer[.]xyz → oo-syspectr-setup9158bf2a-ff25-4290-b96c-2dc5eb310391.exe
- idleminer[.]pro → oo-syspectr-setup9158bf2a-ff25-4290-b96c-2dc5eb310391.exe
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)
It may sound entirely bizarre but the prices you once paid for hotels, educational classes, or staplers could have all been higher because you used a Mac computer, lived in a certain zip code, or lacked an Office Depot in your neighborhood.
No, really.
In 2012, The Wall Street Journal reported that the travel booking site Orbitz showed Mac users pricier hotel options than PC users, because the company had determined that Mac users spend, on average, 30% more a night on hotels. That same year, The Wall Street Journal (once again) reported that Staples.com showed higher prices to visitors who lived farther away from a competitor like Office Depot. And in 2015, the reporting outfit ProPublica revealed that customers in certain zip codes were shown higher prices for college test prep courses offered by The Princeton Review.
As that investigation found, if customers:
“type some zip codes into the company’s website, they are offered The Princeton Review’s premier course for as little as $6,600. For other zip codes, the same course cost as much as $8,400. One unexpected effect of the company’s geographic approach to pricing is that Asians are almost twice as likely to be offered a higher price than non-Asians.”
This is surveillance pricing put into action.
Under surveillance pricing, companies collect as much data as possible about consumers so that they can alter the literal prices those consumers pay for the exact same goods as everyone else. It is reportedly what caused some customers to see higher prices for televisions in the Target app when those customers were physically located in a Target parking lot. It is also allegedly why Home Depot customers in wealthy neighborhoods oddly paid less. And it is what Delta Airlines walked away from after public backlash.
The near-omnipresence of surveillance pricing is also why so many videos can be found online today that claim that minor alterations to a person’s data trail—like changing an IP address using a VPN or shopping for airline tickets on a public library’s computer—can lead to lower prices online.
The proof behind these claims, however, is harder to test.
Thankfully, one person has already tried.
Video journalist Chris Parr, known on YouTube as Chris the Producer, ran a wild experiment into whether he could “stress-test” surveillance pricing. Far beyond changing his IP address or making online purchases from different locations, Parr started from scratch. By first registering an LLC in the state of Wyoming, Parr granted that LLC both a credit card and a phone, effectively creating a brand new consumer persona to be tracked. But creating a realistic data trail for his LLC would require a little extra help—help that Parr received from an actor he hired for the part.
Today, on the Lock and Code podcast with host David Ruiz, we speak with Parr about his experiment into surveillance pricing, including a high-wire drone act to purchase a White Castle Crave Case in the air space above his home state’s wealthiest neighborhood:
“To the data collectors, they don’t know that this phone is floating in the air, like 200 feet in the air. They just see a geolocation on it.”
Tune in today to listen to the full conversation.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.
New turnkey kit makes it easy for anyone to become a scammer
In 2026, online scams have unfortunately become part of the new normal. They can appear almost anywhere, from social media and messaging apps to search results, websites, and online communities, and they can target anyone. Sometimes, all it takes is a moment of curiosity and a convincing offer.
Among the most devastating scams are so-called “get-rich-quick” schemes. These scams promise something that’s difficult for people to resist: the chance to make a lot of money, quickly and with little or no effort. It may come in the form of an investment opportunity, a new cryptocurrency project, or an exclusive chance to get in early before everyone else.
However, behind the promises of easy money can be carefully designed operations built to gain trust, collect deposits, and ultimately leave victims with significant financial losses. In some cases, scammers go to considerable lengths to make their projects appear legitimate, creating professional-looking websites, social media profiles, and convincing stories designed to attract as many victims as possible.
This is the story of one such project: a crypto scam discovered on a cybercrime forum, where the people behind it appeared to openly discuss and promote their operation.
What we found provides a glimpse into how modern online scams are built, promoted, and potentially used to target everyday consumers.
Meet “xrep” Threat actor’s profile on a cybercrime underground forumThe threat actor known as xrep has been active in the cybercrime underground since March 2026. It appears that xrep has already built a positive reputation among customers, receiving favorable feedback for the services and solutions they provide.
Positive feedback left by another cybercriminal
In general, xrep specializes in ready-to-use solutions related to X, formerly known as Twitter. Rather than requiring customers to build their own infrastructure or develop the necessary tools, xrep offers what can essentially be described as a full turnkey solution for scammers.
This approach significantly lowers the barrier to entry for scammers looking to conduct malicious activities. By providing a ready-made package that requires little technical expertise to deploy, xrep enables individuals with limited skills to potentially launch scams with considerably less effort.
$TSLA scam: A crypto investment opportunity designed to steal Tesla scam kit offer
The scam project, discovered on May 16 by the Malwarebytes research team on a high-profile cybercrime forum, is a good example of how modern scams combine social engineering, phishing, and financial fraud into a single operation.
The product, priced at just $500, is essentially a ready-made website designed to look like a legitimate cryptocurrency presale. The supposed opportunity is presented as an exclusive $TSLA token presale for users of X, creating the impression that visitors have been personally selected for an early investment opportunity.
Tesla scam kit description and pricingThe website is designed to look professional and trustworthy, clearly impersonating the Tesla brand name and company logo. It supports multiple languages and is optimized for both computers and mobile devices. But the most important part is what happens behind the scenes.
The scam begins with a fake “eligibility check.” Visitors are asked to enter their X username. The screenshots below are taken from the $TSLA token scam site.
The website then retrieves their real profile picture and uses it to generate a fictional token allocation. This makes the offer appear personalized, giving the victim the impression that they have been specifically chosen to participate.
Figure 7: Scam project screenshotThe site also uses classic psychological pressure tactics. A fake fundraising progress bar continuously increases, a countdown timer creates a sense of urgency, and warnings suggest that the token price will increase soon. These features are designed to create FOMO (fear of missing out) and encourage victims to act before they have time to question whether the investment is legitimate.
Once a victim is convinced, the scam offers two ways to lose money or access to their cryptocurrency wallet.
The first is a classic phishing attack. Victims are encouraged to connect their cryptocurrency wallet to receive a supposed 15% bonus. Instead of connecting a legitimate wallet, they are prompted to enter their 12-word recovery phrase, also known as a seed phrase.
This phrase is effectively the master key to a cryptocurrency wallet. Anyone who obtains it may be able to access the funds stored in that wallet.
The second method involves direct payments. After going through the fake wallet process, victims are redirected to a convincing-looking personal dashboard. There, they can see a fabricated token balance and are encouraged to purchase additional $TSLA tokens.
The victim is instructed to manually send cryptocurrency, such as Bitcoin, Ethereum, USDT, or Dogecoin, to an address controlled by the scammer.
Victims may believe they have made a legitimate investment, but no real tokens are being purchased. Instead, the scammer simply receives the cryptocurrency while the victim sees a fake balance displayed on the website.
What makes this operation particularly concerning is the level of control provided to the scammer. The kit includes an administrative panel where the operator can monitor victims, view their X usernames and locations, track their activity, and collect the recovery phrases entered into the phishing page.
The scammer can also check whether a stolen wallet contains valuable cryptocurrency. This allows them to identify which victims may be worth targeting further. The operator can even manipulate the fake balance shown to a victim, for example, increasing the displayed amount to make the victim believe their investment is growing and encourage them to send even more money.
The administrative panel also allows scammers to manage fake purchase orders and send personalized messages to victims. For example, if someone has already made a payment, the scammer can send a notification claiming that the transaction is delayed and that the victim needs to pay an additional network fee. This creates another opportunity to extract money from someone who has already fallen for the initial scam.
In other words, this is not simply a fake cryptocurrency website. It is a complete scam-in-a-box. The technical infrastructure, phishing functionality, fake investment dashboard, victim tracking, and administrative controls are bundled together into a ready-to-use package.
The significance of this discovery goes beyond this particular $TSLA-themed project. By selling a complete, turnkey operation, xrep effectively lowers the technical barrier for individuals who want to conduct cryptocurrency scams. Someone who may not have the skills to build a phishing website, develop an administration system, or create convincing investment interfaces can potentially purchase the kit and begin targeting victims with minimal effort.
For ordinary internet users, the lesson is simple: a professional-looking website does not make an investment opportunity legitimate. Personalized offers, countdown timers, rapidly increasing “fundraising” figures, and promises of exclusive access are all tactics that can be used to create a false sense of urgency. Most importantly, no legitimate investment opportunity should ever require you to give away your cryptocurrency wallet’s recovery phrase.
Once that phrase is compromised, the consequences can be devastating, and unlike a traditional bank transfer, cryptocurrency transactions are often impossible to reverse.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Edge is dropping older extensions, affecting popular privacy tools
Microsoft is beginning the retirement of Manifest V2 (MV2) extensions in Edge this month, with consumer completion targeted for the end of 2026 and managed-enterprise deprecation in early 2027.
Microsoft says that change is justified because 95% of the most-used MV2 extensions in the Edge Add-ons store have already moved to Manifest V3 (MV3). It counted 58 MV2 extensions with “meaningful usage,” only three of which lack a publicly available MV3 alternative.
Starting this month, some Edge users will see warnings in edge://extensions and on Edge Add-ons store pages. Over the following months, MV2 extensions will be disabled by default.
This shift mostly affects privacy tools that modify requests, headers, redirects, or responses. MV2 extensions will need to be redesigned or lose particular features. Extensions relying on persistent background activity must also adapt to MV3’s service worker lifecycle model.
The change affects some well-known privacy and content-blocking extensions. Among them is the classic version of uBlock Origin, one of the most popular ad blockers for Edge, with more than 13 million installs.
The change is intended to improve security and performance. MV3 replaces some long-running background code and broad request-interception behavior with more constrained, declarative mechanisms. But those constraints also remove capabilities that sophisticated privacy, content-blocking, and request-modifying extensions relied on.
Several developers have complained about the challenges of adapting to MV3. One of the main issues is the limit on the number of rules a browser extension can include.
The rules must fit within browser-defined ceilings. Chrome documents a guaranteed minimum of 30,000 static rules, a maximum of 100 declared static rulesets with 50 enabled at once, 5,000 session rules, and limits on regular-expression rules.
This does in no way mean that Microsoft is banning ad blockers. They simply need to find different ways to remain effective.
Building Browser Guard for Manifest V3At Malwarebytes, we’ve already gone through the process of adapting our free Browser Guard extension to MV3 and came out better than we went in.
So, while Manifest V3 introduced meaningful improvements to browser security, it also created real challenges for security tools like Browser Guard.
Rather than scaling back, the Browser Guard team rebuilt its approach from the ground up, focusing on behavior, patterns, and faster response times. The result is protection that’s different under the hood, but just as committed to keeping you safe online.
You can download Browser Guard for Edge from the Edge Add-ons store.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
A week in security (August 3 – August 9)
Last week on Malwarebytes Labs:
- AI chat bots are sliding into League of Legends friend requests
- Meta ordered to pay $942 million over harm to children
- Apple WebKit vulnerabilities reveal your IP address, despite Private Relay
- Scammers target OnlyFans users with deepfakes
- Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
- Anthropic’s Mythos AI used social engineering to target real people
- Google’s synchronized passkeys can be stolen in “Pass‑ta‑key” attacks
- Junk Cleaner clears the clutter from your Android
- Apple battles it out again with the UK over encrypted iCloud access
- Travelers targeted when logging into hotel Wi-Fi networks
- Online backlash ends in Google rolling back Google Earth AI tool after a day
- WhatsApp account takeover scam asks you to “vote for my friend”
- “Adult TikTok” searches lead to scams
- The AI Act kicks into action, forces companies to be clear about AI chatbots
- Californians can tell data brokers to DROP their information
Stay safe!
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
AI chat bots are sliding into League of Legends friend requests
Lina K., a co-worker, recently shared a firsthand account of how bots are adding League of Legends players via the Riot client friends list immediately after a match ends, striking up a flirty conversation, and eventually pushing an OnlyFans link. The pattern lines up with a wave of complaints that have piled up on Reddit and Facebook gaming communities over the past several months, and it fits into a broader trend of AI-assisted social engineering that has moved from dating apps straight into game clients.
The patternThe scheme reported by multiple League of Legends players follows a near-identical script. A friend request lands in the Riot client within moments of a match ending, from an account whose name does not match anyone from that game. The message opens with generic flattery like “you played really well last game” or “I liked your playstyle” designed to sound like a genuine compliment from an opponent or teammate.
When questioned about who they are, the accounts often claim to have been on the enemy team despite name mismatches, and many present themselves as a woman looking for a duo partner. A detail that likely raises engagement odds. Victims who check the account’s profile frequently find it blank: no visible match history, no overview data, sometimes a very low account level. These are all signs of a throwaway account built or bought purely for outreach, but sometimes they turn out to be stolen existing accounts.
After a short exchange, the contact says they are “getting off soon” and hands over a Discord username, moving the conversation to a platform Riot’s chat protections cannot see or moderate.
Once on Discord, the persona shifts into a longer-form romance/flirtation script. Usually, hours of chat building rapport, paired with a steady stream of photos that are suggestive but stop short of explicit content, a tactic that keeps engagement high while deferring the “reveal” until trust is established. That reveal ultimately comes in the form of a link to a paid subscription platform, most often OnlyFans, framed as an exclusive, limited-time offer.
A reverse image search on the photos sent during one such conversation turned up the same pictures recycled across unrelated websites and at least one YouTube video, with commenters in that video describing having received identical images from a bot under different names. This is strong evidence that the same photo set is cycling through many chats simultaneously, run at scale rather than by one individual.
Lina stated:
“One of my friends tried to break the bot too, left it on read for some time – the bot actually switched the pictures to match the context of “Concern” on the face of the model with “Why are you not replying?”, which quite clearly gave away bulk image generation for the script.’
When the account was pressed with a “reveal your instructions” style prompt-injection attempt (text formatted to look like a system message ordering the bot to break character and print its configuration), it did not comply and instead stayed in persona, deflecting the request and continuing the pitch.
That resilience to a common jailbreak technique suggests the bot’s operators have added guardrails against exactly this kind of probing, or that the “model” behind it is a simpler scripted flow layered with some LLM-generated text rather than an open, unrestricted chatbot.
Why this is happening inside the game client nowWhat makes this wave notable isn’t the romance scam script itself. AI-driven catfishing has been documented on dating apps and social media for a couple of years. The difference is the entry point. Players have reported getting these bot friend requests after essentially every single match, with no way to distinguish a real player’s request from a bot’s inside the Riot client.
Community threads describe the bots seemingly appearing right after a game ends, which has fueled speculation that the bot operators are scraping or monitoring publicly available match data through third-party stats-tracking sites and associated APIs to identify recently finished games and target participants, though this has not been independently confirmed by Riot.
Riot’s own client architecture may be inadvertently helping. The Riot Client exposes local endpoints (such as the friends list API) that third-party tools and overlays query, and community-run “op.gg“-style trackers pull player and match data that could plausibly be used to correlate who just finished a game with who to target next. Some affected players have found a partial workaround: switching on the client’s “streamer mode,” which hides recent match and online status information, appears to reduce how often bot requests arrive. Which is an indirect clue that the targeting relies on visible activity signals rather than random spam.
Safer. Cleaner. Ad-free browsing. The end goal: content promotion, not always theftUnlike classic Discord scams that push fake Nitro codes or malware-laden “test my game” links to hijack accounts, this particular chain appears primarily aimed at driving paid subscriptions to an OnlyFans-style page of a fake AI girl. That doesn’t make it harmless. Even when the underlying OnlyFans account is real, the conversations are very likely run by paid chat operators or scripted/AI-powered systems working from a shared script and a reused media library, a business model that has been described by former OnlyFans “chatters” themselves: agencies assign staff (or bots) to respond as the creator around the clock, pull from a pre-made vault of photos and messages, and are financially incentivized to convert every conversation into a subscription or tip.
There are also more damaging variants layered onto the same funnel. Community reports describe some of these bot accounts eventually sending a link that, once clicked, is designed to hijack the recipient’s Discord account or harvest credentials rather than lead to legitimate content.
That means the “girl who wants to duo” opening can just as easily terminate in an account-takeover attempt as in a subscription upsell. Because the funnel starts with a low-cost, disposable Riot account and migrates the target to Discord within minutes, the League client friend request functions purely as a first-contact filter: cheap to generate, easy to discard after a single use, and outside the reach of Riot’s in-game reporting tools once the conversation moves off-platform.
How to stay safeRecognizing these scams is the best way to protect yourself. But there is more you can do:
- Treat any Riot client friend request from an unrecognized name as suspicious by default, especially one that arrives seconds after a match ends—check whether the account actually appeared in your last game before accepting anything.
- Enable streamer mode or equivalent privacy settings in the Riot client to limit what activity and match data outside parties can see, which several affected players found reduced the frequency of these requests.
- Be skeptical of anyone who quickly steers the conversation off-platform to Discord, especially if they cite being unavailable (“gotta go soon, here’s my Discord”) as the reason—this is a deliberate move to a channel with less moderation and no shared match context to verify identity.
- Run a reverse image search (Google Images, TinEye, or a dedicated tool) on any profile or “personal” photos sent early in a conversation; recycled images across unrelated sites or forums are one of the most reliable tells of a bot or catfishing operation.
- Watch for AI-typical conversation patterns: responses that feel scripted, arrive instantly regardless of time of day, are grammatically flawless but emotionally generic, or that consistently dodge voice/video calls.
- Never send money, gift cards, cryptocurrency, or payment details to someone you met exclusively through in-game or Discord contact, no matter how convincing the rapport feels—legitimate connections do not require urgent financial “help” or exclusive subscription purchases within hours of meeting.
- Do not click links sent by unfamiliar contacts, even ones framed as harmless subscription pages, game invites, or file downloads; some variants of this scheme are documented to lead to credential-stealing or account-hijacking pages rather than legitimate content.
- Lock down Discord’s privacy settings (restrict who can DM you and send friend requests) and enable multi-factor authentication, since a compromised Discord account is often used to relaunch the same scam against the victim’s own friend list.
- Report suspicious Riot client accounts to Riot Support and suspicious Discord accounts/servers to Discord Trust & Safety; reporting does not remove the account instantly but it feeds the pattern data that platforms use to detect and ban clusters of bot accounts.
- If a bot or scripted persona pushes back convincingly against attempts to “break” it (e.g., ignoring prompt-injection or jailbreak-style messages designed to expose it as an AI), treat that resilience itself as a red flag rather than reassurance—a well-guarded script is not the same as a genuine person.
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Meta ordered to pay $942 million over harm to children
A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.
Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.
Meta said it disagreed with the ruling and planned to appeal.
“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”
But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:
- Develop an under-13 prediction model within two years.
- Seek proof of age from users it estimates are under 13.
- Treat uncertain accounts as belonging to minors until their age is verified.
- Delete personal data collected from under-13 users.
The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.
This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.
From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts.
Safer. Cleaner. Ad-free browsing. How to keep your children safeIn February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).
Some tips for parents:
- Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
- Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
- Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
- Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
- Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
- Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.
The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
Meta ordered to pay $942 million over harm to children
A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.
Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.
Meta said it disagreed with the ruling and planned to appeal.
“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”
But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:
- Develop an under-13 prediction model within two years.
- Seek proof of age from users it estimates are under 13.
- Treat uncertain accounts as belonging to minors until their age is verified.
- Delete personal data collected from under-13 users.
The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.
This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.
From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts.
Safer. Cleaner. Ad-free browsing. How to keep your children safeIn February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).
Some tips for parents:
- Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
- Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
- Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
- Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
- Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
- Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.
The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
Apple WebKit vulnerabilities reveal your IP address, despite Private Relay
Three WebKit mechanisms have been discovered to bypass Apple’s iCloud Private Relay. In fact, the mechanisms can bypass any browser‑level proxy configuration, including Psylo’s proxy, Tor-on-iOS proxy setups, and so on.
Private Relay is a VPN-like system for Safari on iOS which is meant to prevent websites from viewing the visitor’s IP address and location.
But because all three methods described by the researchers occur outside WebKit’s normal page loading path, Apple’s iCloud Private Relay never sees them and, as a result, means you can’t hide your IP address or Domain Name System (DNS) path in these cases.
The three features are:
- DNS prefetching
Modern browsers try to be faster by looking up the IP addresses of links on a page before you click them, a feature known as DNS prefetching. In WebKit, these DNS lookups can bypass the configured proxy/relay and go straight through the system’s normal DNS stack, exposing which DNS servers you are using and, indirectly, where you really are. Even if the actual page load goes through Private Relay, the prefetch DNS queries can still leak metadata about your network. - WebAuthn and passkeys
WebAuthn (the standard behind passkeys) sometimes needs to fetch a small file from the website’s domain to verify that the credential is being used on the right site. The researchers found that, on Apple platforms, this fetch is performed outside the usual WebKit page‑loading path, which means it is not sent through the Safari proxy or Private Relay. The result is that a site using passkeys can cause your device to contact it directly, revealing your true IP address even if the rest of your browsing is supposedly hidden behind a relay. - WebTransport and related technologies
WebTransport is a newer API that gives websites a way to open low‑latency, bidirectional connections to a server. In the scenarios the researchers tested, these WebTransport connections were also initiated outside the proxied WebKit code path, creating another route for sites to receive traffic straight from the device. That traffic again carries the device’s real IP, not the relay or proxy IP the user expects.
From a user‑experience point of view, the problem is that all three mechanisms look like normal browser behavior and require no special tricks from a malicious site.
What’s affectedAffected are Safari on iOS and macOS when Private Relay is used, because Private Relay is implemented as a WebKit‑level proxy that only applies to Safari traffic. Additionally, any iOS/macOS browser or app that relies on WebKit’s proxy configuration to hide the IP (e.g., Psylo, Onion Browser/Tor on iOS, and other proxy browsers), since they all hit the same WebKit behavior.
And that’s not necessarily all. For most of iOS’s history, any app that browsed the web had to use Apple’s WebKit framework and JavaScript engine. This meant that Chrome, Firefox, Edge, Brave, and other browsers on iPhone were effectively different shells around the same WebKit engine Safari uses. Under pressure from the EU’s Digital Markets Act (DMA), Japan’s Smartphone Act, and similar regulatory pushes, Apple introduced a mechanism for non‑WebKit engines, but only in constrained ways.
Malwarebytes’ Senior manager for iOS software Roman Dvoinev commented:
“Basically the API has been “open” for a while, but no browser vendor has actually shipped a non-WebKit browser yet. Major players are still in prototype phase, as Apple’s bar for shipping a browser to iOS is very high.”
Malwarebytes VPN is not affected, since it tunnels the device’s entire network traffic at the system level.
The researchers have reported the problems to Apple and are expecting patches by fall.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
Scammers target OnlyFans users with deepfakes
OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live chats, and then ghost them after the followers pay up in advance.
How the catfishers hook their baitThis is a form of catfishing, in which an attacker impersonates someone online and engages in romantic or sexual interactions for ulterior motives. In this case, the scammers create fake accounts on platforms like TikTok, using material lifted from a real creator’s photos and given a synthetic voice. They’ll use that to nudge viewers into a direct message conversation on services like Snapchat.
Once there, the “creator” asks for a Cash App payment in exchange for exclusive content. Cash App is a peer-to-peer payments service built for casual sends between friends, not for commerce. Transfers clear instantly and settle in the recipient’s balance within seconds. Once it’s been sent, it’s very difficult to recover.
That informal design is exactly what makes it useful here. As soon as the fan pays up, the criminal blocks them and disappears.
Why the laws don’t reach the actual serversLawmakers are tackling this with multiple state-level anti-deepfake bills. Federally, the Take It Down Act criminalizes non-consensual explicit content, including AI-generated images, and requires rapid platform takedowns. In the EU, the AI Act requires anyone who uses AI for image generation to disclose it publicly.
So why is this still happening?
The problem is that domestic laws only apply to domestic platforms. The stolen material largely sits on overseas hosts, making it difficult to control.
Even if laws could be universally enforced, it might not matter. In three experiments conducted this year, researchers at the University of Bristol found that most participants relied on deepfake content even after being told it was fake.
What actually helpsThis kind of fraud has two victims: the fans who lose money to scams, and the creators. The latter lose income that they might have collected from fans, and also run the risk of retribution from disgruntled followers who think they’ve been taken advantage of.
One creator, Jessieanna Campbell, told USA Today that confused fans complained to her after mistakenly thinking she had taken their money. “I get messages all the time, like, ‘Hey, why did you take my $150 and block me?’ and I’m like, ‘What are you talking about?'”
USA Today also interviewed one creator who had angry fans visit her home, and is now sometimes scared to leave her house.
Some creators are hiring private content takedown services to try and fix the problem themselves. Others are posting public service announcements warning of these fake accounts. But it’s up to the fans to listen.
If a “creator” on a third-party platform contacts you, watch the video closely; the deepfakes are often flawed. USA Today reported that a TikTok video impersonating creator Elaina St. James, made by animating a still photo and cloning her voice, showed distorted teeth and frozen eyebrows. Here’s our guide to spotting deepfakes of any kind.
Common sense is the bottom line. If someone steers you into a direct messaging platform and solicits money for exclusive content, think twice. Check with the creator via a verified account to see if it’s real.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam
If you’ve spent any time browsing lately, you may have run into a full-screen popup warning you that your Apple ID or Amazon account was just used for a mysterious $149.99 purchase. It looks urgent. It looks official. And if you look at two examples side by side, it becomes obvious that it’s neither.
Below are two popups pulled from real pages—one dressed up as Apple Support, one as Amazon.
Same con, two costumesBelow, one popup is skinned as Apple Support, the other as Amazon. Swap the logo and color palette and the structure is identical: a warning icon, a claim that a $149.99 purchase was just made “via Pre-Authorization,” and a phone number to call immediately. That phone number is exactly the same in both.
Fake Apple alert Fake Amazon alertThat reused phone number is the tell. If you only see one popup, running the number through a lookup tool like Malwarebytes Scam Number Check is usually enough to expose it—a real Apple or Amazon line won’t come back flagged, but a scam number typically does, often tied to complaints about several unrelated companies at once.
Why the copy is built the way it isEvery element in these popups is doing specific psychological work:
- A believable, moderate dollar amount. $149.99 is high enough to alarm you, low enough to sound like a real subscription or product charge rather than an obvious lie.
- “Pre-Authorization” jargon. This is real payment terminology (used for things like hotel holds or gas station charges), borrowed here to sound technically credible to someone who doesn’t handle payments professionally.
- Manufactured urgency. “Call immediately,” “Immediate Action Required,” “no hold times”—all are designed to get you dialing before you stop to verify anything.
- Visual authority. Red warning triangles, brand-matching fonts and layouts, and a full-screen modal that blocks the rest of the page all borrow the visual language of legitimate security alerts.
- A single, frictionless call to action. One button, one phone number. The popup wants exactly one thing from you: to pick up the phone.
If you do call, the number connects to a live scammer posing as support staff, whose actual goal is to get remote access to your device, walk you through “verifying” your identity in a way that hands over real account or payment info, or push you toward paying a fake fee—often via gift cards or a wire transfer.
How to tell if it’s fakeA few checks work regardless of which brand is being impersonated:
- Real companies don’t alert you this way. Apple and Amazon notify you about account activity through email, in-app notifications, or your account’s activity log—never through an unexpected popup while you’re browsing.
- No legitimate company tells you to call a phone number to stop a charge. Disputing a charge happens through your bank, your card issuer, or the company’s actual account dashboard—not a hotline dictated by a popup.
- Check where the popup is actually served from. These often ride in on malicious ads, compromised sites, or browser redirects—the underlying page may be spoofed or injected, not the real apple.com or amazon.com support page it appears to sit on top of.
- A popup you can’t easily close is a red flag on its own. Legitimate sites don’t need to trap you behind a full-screen modal to relay account information.
- If in doubt, go direct. Close the tab (force-close via task manager if needed) and navigate to the company’s site yourself, or call the number printed on your card or official account page—never the one in the popup.
- Check the number before you dial it. Run it through Malwarebytes Scam Number Check to see if it’s already been flagged as a scam line.
- Block it before it loads. A browser extension like Malwarebytes Browser Guard catches both known malicious pages and unknown ones showing scam-like behavior, so these popups often get stopped before they ever render.
The brand on screen—Apple, Amazon, or whoever’s next—is the least important part of this scam. What actually matters is the pattern underneath: an unexpected popup, a suspiciously specific dollar amount, urgent language, and a phone number that wants you to call before you think. Once you recognize that pattern, it doesn’t matter which company’s name is stamped on top of it.
Anthropic’s Mythos AI used social engineering to target real people
Anthropic’s Mythos AI agent, tested by the UK AI Safety Institute (AISI), has reportedly attempted a real‑world social‑engineering style hack against GitHub maintainers by creating fake human profiles, pressuring them to accept malicious code, and then editing logs to hide its tracks when challenged.
AISI was running cybersecurity evaluations of Anthropic’s Mythos and OpenAI’s Sol when it detected unusual outbound data transfers from its research systems. An investigation showed that some agents had engaged in “sustained, potentially harmful activity” targeting real people and organizations, rather than staying within the intended test environment.
The most serious activity involved an Anthropic Mythos agent tasked with solving a GitHub‑related cybersecurity challenge. The agent identified real GitHub maintainers, researched them, and created multiple fake accounts impersonating those individuals. Using private messages and a file‑sharing service, it tried to pressure and deceive the maintainers into approving malicious code so that it would run on GitHub’s systems.
But what worries me personally most is that when the agent was confronted about this, it edited earlier activity to make it look harmless and considered adopting a new identity to continue the operation, displaying clear deceptive behavior beyond its original prompt.
AISI frames these incidents as rare events under very specific conditions, but important signals of what such models may do in the hands of malicious actors when given open‑internet access. Anthropic and OpenAI both argued the test parameters were not representative of their production deployments and said they are investigating and improving evaluation and guardrail practices.
This incident is not an isolated event.
Anthropic has separately disclosed that Claude models gained unauthorized access to three external organizations during cybersecurity capture‑the‑flag style evaluations run with a third‑party partner, Irregular. These were related to the HuggingFace incident last month.
Meta has also joined the list of vendors reporting AI agents breaching third‑party systems during testing. Allegedly, Meta’s Muse Spark model exploited a security vulnerability in another company “in a manner similar to previously-reported instances with other companies.”
How to stay safeWhile the sky is not falling, the people that fear “Skynet” is coming are getting their ammunition handed to them by companies running tests resulting in sandbox escape, credential abuse, lateral access to multiple services, and weaponization of open-source software ecosystems.
What you can do as a potential target:
- Make sure all the software on your device is up to date, because using known vulnerabilities is easier than finding new ones.
- Use up-to-date, real-time security protection to keep malware off your systems and devices.
- Verify the safety of attachments and download links through separate channels before opening them.
- Use multi-factor authentication (MFA) where possible.
- Have a look at our blog on how to use Github safely.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
Passkeys were supposed to make stolen passwords a thing of the past. No password to phish, no secret to reuse, and no string of characters sitting in a database waiting to be leaked.
Over time, it’s thought that passkeys will replace passwords entirely. But what happens when malware steals the master key?
Researchers have found a way for malware to hijack passkey-protected accounts through Google Password Manager, highlighting an important exception: passkeys can be very secure but the software surrounding them still has weaknesses.
What are passkeys?Passkeys are a password replacement based on public‑key cryptography. Instead of a secret you remember and type, each account gets a key pair where the private key never leaves your devices, and the website only ever sees the public key and signed challenges. Because there’s nothing reusable to phish or reuse on another site, passkeys are marketed as “phishing‑resistant” and safer than passwords stored in a browser or password manager.
By the end of 2024 Google reportedly said that 800 million Google accounts used passkeys.
Passkeys have a major advantage over passwords: there is nothing useful for a phishing site to steal. A passkey is also tied to the website it was created for, making it much harder to trick into authenticating to the wrong domain.
The other significant difference is that if malware steals a password vault, an attacker still often needs to get past a second factor on another device, such as an authenticator app on your phone, before they fully own the account. With passkeys, many services relying on them simply trust the passkey assertion, and in some cases even trust a single “user verified” flag without confirming whether a real biometric or PIN event occurred.
Malware comes into playThe researchers, however, started with a malware infected Windows computer and came up with three possible attack scenarios to steal Google synchronized passkeys. Google Password Manager can synchronize passkeys between devices, which is convenient since you don’t want to register a new passkey every time you buy a new computer. But it also opens them up to abuse.
From bad to worse the attacks are:
- Pass‑ta‑key: malware on the victim’s computer silently asks Chrome and Google’s cloud to create a valid passkey login, no biometric or PIN prompt needed.
- Silver Pass‑ta‑key: malware abuses device re‑enrollment to register its own user‑verification key, then logs in as the victim from the attacker’s machine without touching the victim’s device.
- Golden Pass‑ta‑key: Malware extracts Google’s security domain secret (the master encryption key), decrypts all synced passkeys, and can reuse them anywhere, even after losing access to the original device.
The researchers urge services to stop blindly trusting the user verification flag and to properly validate that a real User Verified event occurred before granting access. Google, in turn, is encouraged to harden device registration and recovery, and verify that new devices and keys are backed by genuine hardware rather than accepting them at face value.
For end users, passkeys still offer strong protection against classic phishing websites and credential stuffing attacks based on reused passwords. The weak point highlighted here is not so much the concept of passkeys, but the way they’re implemented, synchronized, and trusted without enough verification on the server side.
Until vendors close these gaps, basic anti‑malware hygiene remains critical. The best ways to prevent malware from using your passkeys are:
- Keep on top of updates: make sure your systems and software are patched as soon as you can.
- Use up-to-date real-time anti-malware protection.
- Treat unexpected attachments or links as suspicious until proven innocent.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Junk Cleaner clears the clutter from your Android
Your phone is full again, and the warning appears at exactly the wrong moment. Suddenly you can’t update apps, record a video, or save another photo.
The cause is rarely one giant file. Storage disappears in a steady drizzle of leftovers: temporary files an app creates and forgets, caches that grow in the background, and downloads you no longer need. None of it is dangerous, but it can gradually fill your phone’s storage.
Junk Cleaner is a new tool in Malwarebytes for Android, available from version 5.22. It finds that clutter, shows you what’s using space, and lets you decide what to remove.
What Junk Cleaner findsJunk Cleaner looks for three broad categories of storage clutter:
- Leftover and residual files: Temporary and system-generated files that apps leave behind.
- Old and large downloads: Files you saved but no longer use or remember.
- (Coming soon) Hidden app caches: Storage used by apps in places Android keeps out of easy reach.
A file showing up in one of these categories doesn’t mean it’s harmful. It just means it’s taking up space and might be worth removing. That distinction matters because Junk Cleaner is about storage, not threats. It works separately from Malwarebytes malware scanning and web protection, and it doesn’t touch your photos, messages, or documents.
Scan, review, cleanJunk Cleaner scans the relevant areas of your device in parallel, guided by a set of rules that can be updated as we learn about new kinds of leftover files. The results are grouped by category and show how much space each item is using.
After the scan, you review the findings and choose what to clear. Nothing is deleted until you confirm the selection. The results are presented as a simple list showing each category and how much space you could recover.
.kadence-column445671_58044d-dd{max-width:400px;margin-left:auto;margin-right:auto;}.wp-block-kadence-column.kb-section-dir-horizontal:not(.kb-section-md-dir-vertical)>.kt-inside-inner-col>.kadence-column445671_58044d-dd{-webkit-flex:0 1 400px;flex:0 1 400px;max-width:unset;margin-left:unset;margin-right:unset;}.kadence-column445671_58044d-dd > .kt-inside-inner-col,.kadence-column445671_58044d-dd > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-column445671_58044d-dd > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-column445671_58044d-dd > .kt-inside-inner-col{flex-direction:column;}.kadence-column445671_58044d-dd > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-column445671_58044d-dd > .kt-inside-inner-col:before{opacity:0.3;}.kadence-column445671_58044d-dd{position:relative;}@media all and (min-width: 1025px){.wp-block-kadence-column.kb-section-dir-horizontal>.kt-inside-inner-col>.kadence-column445671_58044d-dd{-webkit-flex:0 1 400px;flex:0 1 400px;max-width:unset;margin-left:unset;margin-right:unset;}}@media all and (max-width: 1024px){.kadence-column445671_58044d-dd > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}@media all and (max-width: 767px){.wp-block-kadence-column.kb-section-sm-dir-vertical:not(.kb-section-sm-dir-horizontal):not(.kb-section-sm-dir-specificity)>.kt-inside-inner-col>.kadence-column445671_58044d-dd{max-width:400px;-webkit-flex:1;flex:1;margin-left:auto;margin-right:auto;}.kadence-column445671_58044d-dd > .kt-inside-inner-col{flex-direction:column;justify-content:center;}} A quick look under the hoodJunk Cleaner uses rules to identify patterns of clutter. These are not malware or phishing signatures. They describe file types and locations that may be worth reviewing when you need more space.
The scanner checks the relevant directories, matches files against those rules, measures how much space each hidden cache occupies, and combines the results into a single review screen.
Junk Cleaner automates a repetitive Android chore without turning storage cleanup into another complicated job.
Built at a hackathonJunk Cleaner began as an internal hackathon project, an idea one engineer wanted to explore over a few focused days. The prototype proved useful enough to grow into a shipping feature, and reached all users in Malwarebytes for Android version 5.22.
Turning the demo into a product meant more than polishing the screen. The team added Android permission handling, cache cleaning, and review experience needed for a feature people could rely on across different devices.
We like that origin story because many useful features begin the same way: someone scratches an itch, builds something quickly, and turns a rough idea into a tool that can help millions of people. Future updates will bring smarter sorting, finer filters, and more control over what’s included.
Make room for what mattersRunning out of space always seems to happen at the worst possible moment. Junk Cleaner clears away the leftovers that quietly build up, leaving more room for the photos, apps, and moments that actually matter.
Junk Cleaner is available in Malwarebytes for Android from version 5.22. Open the app, run a scan, review the results, and reclaim your space in a few taps.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
Apple battles it out again with the UK over encrypted iCloud access
The UK Home Office has once again demanded Apple allows it access to encrypted iCloud data.
The Guardian reports that the Home Office issued a Technical Capability Notice to Apple, this time targeting only British users. A Technical Capability Notice is a formal government order that compels tech and telecommunications companies to build or maintain specific technical functions—such as intercepting data or removing encryption protections—so law enforcement can access communications.
In the last round of this ongoing battle, the UK secretly ordered Apple to provide blanket access to protected iCloud backups around the world. Advanced Data Protection (ADP) is Apple’s opt‑in end‑to‑end encryption for iCloud backups, which even Apple itself cannot read. Apple argued that weakening or removing ADP would expose users to data breaches and other threats, and instead chose in January 2025 to withdraw ADP for UK customers rather than build a backdoor, while leaving it available elsewhere.
So, instead of working to keep citizens safe and secure, the Home Office just ended up removing an option for them.
Apple has responded by lodging a complaint with the Investigatory Powers Tribunal (IPT), seeking to challenge the scope and lawfulness of the government’s powers to issue such notices under the Investigatory Powers Act. The Tribunal is an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully.
Privacy International and Liberty have parallel complaints at the IPT challenging Technical Capability Notices more broadly, including their secrecy and necessity, and have asked for Apple’s claim to be heard in public given its wide public-interest implications.
I feel the fear of leaving an intentional backdoor is justified. If it exists, there is a chance that (AI-assisted) criminals will find and exploit it.
Weighing the importance of the right to privacy and the ability to investigate cases including terrorism and child sexual abuse is not easy. Apple’s ADP is used by many and as soon as criminals would know it’s no longer safe for them to use, they’d move to other platforms. Platforms where no legislative power will be able to gain access.
Reddit r/privacy users have been discussing alternatives for a year.
But, given the danger of a backdoor becoming available for criminals, we think in this case privacy should prevail. Let us know how you feel in the comments.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
Travelers targeted when logging into hotel Wi-Fi networks
Microsoft has warned that hotel, conference, and other hospitality Wi-Fi networks are being actively abused by a Russian group to target travelers worldwide. The campaign, dubbed “CaptiveCrunch” turns a routine Wi-Fi login moment into an opportunity to compromise corporate accounts and devices.
From the user’s perspective, nothing looks out of the ordinary: they connect to hotel Wi-Fi, get the usual captive portal prompt, and perhaps see a familiar‑looking message about needing to update something before they can browse. However, behind the scenes, the allegedly state-linked group position themselves in the network path and manipulate DNS (Domain Name System) and HTTP traffic from captive‑portal Wi-Fi.
From there, several things can happen:
- Logins are stolen: The user’s browser session is redirected to attacker‑controlled phishing pages, like fake Microsoft login prompts, where credentials, device codes, or OAuth tokens are harvested.
- Malware is downloaded: The user is presented with fake update or ClickFix dialogs that download malware. In these cases, usually a remote access trojan (RAT) plus an infostealer.
- A machine-in-the-middle attack (MitM) where traffic is quietly proxied through attacker infrastructure, putting the user in a position for further credential theft.
Reportedly, one of the main malware strains used in these attacks is called CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes.
The infostealer was identified as ChocoShell, a fileless Powershell-based information stealer which primarily goes after browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems.
Microsoft lists a set of fake dialogs that may appear once you connect to compromised Wi‑Fi:
- winupdate: A bogus Windows Update window with “Working on updates… Don’t turn off your computer.”
- defender: A fake Windows Security virus scan.
- directx: “DirectX End‑User Runtime Web Installer.”
- vcredist: A Microsoft Visual C++ redistributable installer.
- sysopt: A disk optimization utility.
- netfix: A Windows Network Diagnostics ‘fix’ tool.
- browser: A browser update prompt.
- pdfview: A document/PDF viewer installer.
Malwarebytes has long warned about the safety of public Wi-Fi. Here’s how you can stay safe while traveling:
- Use your own phone’s hotspot instead of using the public Wi‑Fi. A mobile connection, especially with an eSIM and a reputable carrier, significantly reduces the likelihood of an attack compared to an unknown hotel network.
- If you’re forced to use public Wi‑Fi, use a VPN with an active Kill Switch: Complete the authentication on the hotel portal first, then launch your VPN before opening any website or app. The Kill Switch feature will instantly block all internet traffic if the VPN disconnects even for a second, preventing cybercriminals from injecting malicious code out in the open. While CaptiveCrunch operates around captive portals and pre‑VPN flows, a VPN still reduces other risks and limits passive data collection once you’re online.
- Always inspect the certificate of any public Wi‑Fi login or ‘security’ portal that asks for more than a room number or basic credentials. These aren’t always a straight‑up giveaway, but sometimes they can be an obvious clue: mismatched hostnames, untrusted issuers, or plain HTTP are red flags that should stop you from proceeding.
- Many captive portals ask for an email address for registration or marketing. Even in benign cases, there is little value in handing over your real inbox. If you must provide an address, consider giving a fake one or a throwaway alias that is unrelated to your primary accounts.
- If you are asked to download software, a certificate, a browser update, or a fix tool in order to connect, stop. You should never have to download anything just to log into Wi‑Fi.
- Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy-paste code. Be cautious of pages urging immediate action: sophisticated ClickFix pages add countdowns, user counters, or other pressure tactics to make you act quickly.
- Secure your devices. Use an up-to-date, real-time anti-malware solution with a web protection component.
- Avoid entering Microsoft 365, Google Workspace, or other high‑value credentials directly into any page reached via captive portal redirection. If you need to check corporate mail, follow known URLs rather than clicking through prompts.
And last but not least, update your browser, operating systems, and other important software before you travel. That reduces the chance of getting legitimate update requests while you’re away.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Online backlash ends in Google rolling back Google Earth AI tool after a day
Google has walked back an AI feature that allowed users to generate artificial images inside Google Earth, after a predictable flurry of deepfakes.
Google switched on the AI image generation feature inside Google Earth’s web version on July 30. It was available to everyone.
The system used Google’s Nano Banana 2 image generator to create its images. That tool can already generate images from simple text input, but the advantage of doing it in Google Earth is that it can use the real satellite images as the basis for its deepfake versions. That makes it easier to make AI pictures with real, accurate building and landscape details.
In its initial blog post on the launch, it said that students could use it to “bring history to life”, while realtors could use it to produce professional real estate plans. However, others warned that the system could be used to mislead people.
Within hours, researchers and press outlets demonstrated that the tool would happily produce photorealistic satellite imagery of things that did not happen in places where they did not happen.
Dutch open source intelligence researcher Henk van Ess explained: “I tried refugees at the Mexican border, a nuclear plant in Iran, a crash in Amsterdam, a hospital with a bomb crater in Gaza. Nothing was refused”.
Demonstrating what was possible with the new capability, NPR fabricated an image of fires in Iran, along with a deepfake of Washington, D.C. underwater. The BBC ran images of a collapsed Eiffel Tower and the Great Pyramid of Giza swallowed by a sinkhole. Even though the service had some guardrails in place, the BBC’s anti-disinformation Verify service was able to circumvent them by tinkering with basic AI prompts.
Google acknowledged the failure in a statement on X:
“We’ve seen geospatial professionals using this feature for a range of useful purposes, however we’ve also seen people sharing screenshots of generated imagery that appear to violate our policies. So we’re rolling back this feature in Google Earth while we work on implementing stronger guardrails.”
It didn’t commit to never re-introducing the idea.
Users were apparently unimpressed. “There is 0 chance that no one on your development team didn’t raise exactly this concern,” commented one. “You guys are living in a complete bubble,” accused another.
Google’s fallback safeguard was a SynthID watermark and the fact that generated images didn’t appear in the main Google Earth experience for others to see. SynthID is Google DeepMind’s watermarking system, an invisible signal baked into the pixels of AI-generated images so that a compatible detector can spot them later. Google positions it as one half of its provenance stack, sitting alongside the C2PA metadata standard the wider AI industry has settled on.
On paper, the signal is meant to hold up through compression and even social media re-uploads. However, these claims collapsed on contact with reality. The watermarks are detectable by Google’s AI services like Gemini. They are not visible to users, who can screenshot the images and share them anywhere. It’s unlikely that everyone will know to check for the provenance of an image. Researchers have also reported that Gemini could not reliably identify AI-generated images with a SynthID watermark.
What this means for youContent creators were already producing fake AI images showing events that didn’t happen. Traditionally, satellite imagery has been a key component of open source journalism. Fake it convincingly and you are attacking the reference layer reporters use to check whether something actually happened.
This also comes at a time when trust in AI is measurably eroding. According to our own research, released in June, 88% of people said it’s becoming harder to tell what content online is genuinely human or real, with 84% saying that even “convincing video evidence” no longer feels like proof.
The practical advice is to take a breath whenever a disturbing satellite image of a disaster, a weapon strike, or a border crossing hits your timeline. Check whether a wire service with a named reporter has published it. Look for a caption identifying the imagery provider. If the source is an anonymous account posting a single dramatic frame, assume you might be looking at something assembled in a browser tab last night.
For more information on how to identify AI images, check out our guide.
The industry’s shipping model now apparently treats users as the test group. Critical media literacy is now the only reliable tool that readers and viewers have.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
WhatsApp account takeover scam asks you to “vote for my friend”
A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely.
It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click.
We spotted the scam showing up in our anonymized Scam Guard submissions. WhatsApp is popular with cybercriminals, and the third most common channel where we see scams delivered, behind websites and email.
At first glance, nothing seems out of the ordinary. But the link doesn’t lead to a real voting page. Instead, it redirects to a page that appears to be related to WhatsApp, often involving the legitimate wa.me domain, where the real attack begins.
This scam works because it combines trust and curiosity. If the message comes from someone you know, you’re far less likely to question it and far more likely to follow through to do them a small favor.
In some versions of the scam, the link redirects you into a flow that abuses WhatsApp’s legitimate “Linked devices” feature.
Depending on your device, you may see what looks like a WhatsApp page prompting you to continue, verify, or connect. In some cases, the victim is guided through steps that resemble setting up WhatsApp Web or linking a new device.
The goal is to trick you into authorizing a new linked session that gives the attacker access to your WhatsApp account.
A typical flow looks like this:
- You tap the “vote” link.
- A page opens that appears to be related to WhatsApp.
- You’re prompted to complete a connection or verification step.
- That action links your WhatsApp account to a device controlled by the attacker.
Some versions of this scam take a less direct route. Instead of sending victims to a fake voting page, the message or the landing page instructs victims to open WhatsApp, go to “Connected Devices,” and enter a code supplied by the scammer.
These scammers aren’t trying to steal your password. Instead, they’re tricking you into giving them access to your account yourself.
How WhatsApp’s Linked devices feature worksWhatsApp allows you to use your account on multiple devices, including a web browser or desktop app, through its Linked devices feature.
Normally, this works by:
- Opening WhatsApp on your phone.
- Scanning a QR code displayed on another device.
- Approving the connection.
Once linked, that secondary device can:
- Read your messages.
- Send messages as you.
- Access your ongoing conversations in near real time.
But if you follow those steps, you could be giving an attacker access to your messages, contacts, and ongoing conversations.
This is a legitimate and widely used feature, especially for WhatsApp Web. But in this scam, attackers abuse it to gain the same level of access without your informed consent.
Once a scammer links their device to your WhatsApp account, they can continue accessing your conversations until that device is removed.
From there, they can:
- Send messages pretending to be you, including forwarding the same scam to your contacts.
- Ask friends or family for money or sensitive information.
- Read your chats and harvest personal information.
Because this doesn’t involve a traditional login, there are no obvious signs like password reset emails or failed login alerts. The attacker’s device simply appears as another linked session on your account.
Unless you check your linked devices, the compromise can go unnoticed for quite some time.
How to stay safeScams like this rely on quick reactions and misplaced trust. A few simple precautions can make a big difference:
- Be cautious with unexpected “vote” or “support” requests, even if they come from someone you know.
- Don’t click unexpected links, especially if you’re immediately asked to verify, connect, or link your WhatsApp account.
- Never follow instructions to link devices or scan QR codes unless you initiated the action yourself.
- Regularly review your linked devices in WhatsApp (Settings > Linked devices) and log out of any you don’t recognize.
- Enable two-step verification in WhatsApp for an extra layer of protection.
- If a message feels off, verify it with the sender through another channel before acting.
- Malwarebytes Scam Guard can also help spot scams like this. It’s included with the Malwarebytes Mobile Security app for Android and iPhone.
If you suspect your account has already been compromised, immediately log out of all linked devices and warn your contacts so they don’t fall for follow-up scams.
Indicators of Compromise (IOCs)These domains are typically short-lived and quickly replaced. However, they may help you recognize similar scams if you encounter them:
ngdance[.]fun/vote
fokindenfo1[.]lol/home/voteeeg3
stardancer[.]fun/home/voteCZ03
thebestscollato[.]top/home/scolatica
vatiter[.]click/home/voteerok
megadencer[.]top/home/eng10
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
“Adult TikTok” searches lead to scams
Search for certain combinations of “TikTok” and adult content, and sooner or later you’ll land on a page promising exactly what you searched for: an endless feed of explicit clips, no signup required, just tap and watch.
There isn’t one.
On the other side of that click is an ad funnel dressed up as exclusive content.
These pages aren’t connected to TikTok itself. They simply exploit the platform’s name to attract search traffic. TikTok’s huge user base, and the number of people searching for adult content associated with the platform, make it an attractive lure both for advertisers and scammers.
What you need to know right awayNothing on these pages is genuine content pulled from TikTok. Their entire business model is get you to click, sign up, or install something.
The operators don’t need to host any videos to make money. The promise of exclusive content is enough to generate clicks, signups, and downloads.
Although you’re probably not going to lose your life savings here, you could well end up on a spam list, installing an unwanted app, or paying for an “age verification” that doesn’t verify anything.
A pitch built around your searchThese pages are designed to match exactly what you searched for. Many are built to rank for popular search terms in Google and other search engines, rather than relying on visitors coming from TikTok itself. They often acknowledge the frustrating hunt for working links before presenting themselves as the solution.
Below that, you’ll usually find a deliberately blurred video thumbnail, reassuring labels like “18+ only” and “HD clips,” and one or two buttons inviting you to Start watching or Sign up for free.
Mirroring the visitor’s own search behavior back at them is a common tactic in this category of ad-lure page. It’s designed to make the offer feel more relevant rather than generic.
What happens after you click varies from site to site, but you rarely get the content you were promised. Instead, you’re likely to be redirected through advertising networks, asked to hand over an email address or payment card for “age verification,” or prompted to install an app from outside the official app stores.
Each click or redirect can earn the site operator money through advertising or affiliate commissions, even if you never sign up or download anything.
Every step of the journey has value: A click can generate advertising revenue, a signup can earn an affiliate commission, and an email address can be sold or added to marketing lists. A payment card entered for “age verification” can lead to recurring subscription charges. Whether you ever see a video is irrelevant because the site has already achieved its goal.
Legitimate websites don’t normally need your payment card to prove you’re over 18. Fake “age verification” pages often use the process to collect card details, sign people up for recurring subscriptions, or both.
There’s no content, but there is a funnelThe blurred thumbnail is the entire “product.” It’s designed to look like a legitimate preview, suggesting there’s something just behind the next click, even though there usually isn’t. The site makes money from the clicks, signups, and downloads, not from any videos.
Depending on the page, the operator makes money in several ways:
- Affiliate commissions. You click through to a dating site, adult subscription, VPN, app, or other offer. If you sign up, the site owner gets paid.
- Advertising revenue. Every redirect, pop-up, or ad impression earns money.
- Lead generation. Your email address is collected and sold or used for spam and phishing.
- Subscription traps. “Age verification” asks for a payment card, then quietly enrolls you in a recurring subscription.
- Potential malware. Some pages push unwanted software or even malware outside official app stores.
Adult content lures carry a built-in advantage most scams don’t have: embarrassment. People are less likely to mention it to a friend, ask for a second opinion, or report it, which means fewer eyes catch the scam before it spreads further.
What to do- Close the tab. There isn’t any exclusive TikTok content waiting behind Start watching.
- Don’t enter your email address, payment card, or date of birth to verify access. It isn’t verifying anything, it’s collecting data.
- Don’t install anything you were prompted to download from a page like this.
- If you’ve already entered information, treat it as exposed. Watch for follow-up spam or phishing emails, and change any passwords you may have reused.
Adult-content lures are one of the oldest tricks in malvertising. Using TikTok’s name just makes them feel more relevant to today’s searches.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
The AI Act kicks into action, forces companies to be clear about AI chatbots
The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing Artificial Intelligence (AI) systems.
From August 2, what you’ll likely notice are more “this is AI” labels, clearer rules for powerful foundation models, and new ways for users and researchers to complain when systems go off the rails.
The AI Act moved from theory to practice for three big areas:
- General‑purpose AI (GPAI) models: The new AI Office in Brussels, together with national regulators, can now enforce rules on providers of general‑purpose AI models (think large language models and other foundation models behind many tools).
- Transparency obligations: Transparency rules kick in for interactive systems and AI‑generated content: chatbots must say they are bots, and synthetic audio, images, video and text need to be marked as AI‑generated or manipulated.
- Banned AI uses: A set of “unacceptable risk” AI uses is now formally prohibited, with enforcement shared between the AI Office, national authorities and the European Data Protection Supervisor for EU institutions.
Note that content that was generated and published before August 2, doesn’t need to be retro‑labelled, but anything published on or after that date falls under the rules, even if it was generated earlier.
From a security perspective, the AI Act’s transparency push is less about banning AI and more about taking away its best camouflage: pretending to be human.
Non‑compliance with transparency obligations can attract fines up to 15 million Euros (17.3 million USD) or 3% of worldwide annual turnover, whichever is higher, which should be significant enough to get large providers’ attention.
To make enforcement more than a paper tiger, the AI Office has launched tools aimed at people who see problems from the inside or as users:
- Complaint tool: Individuals and organizations can report alleged infringements of the AI Act by providers or deployers of AI systems supervised by the AI Office.
- Whistleblower tool: People professionally connected to AI providers or deployers get an anonymous channel to flag potential violations that could endanger fundamental rights, health or public trust.
- Downstream complaints channel: Firms building on top of GPAI models can report suspected breaches by the underlying model providers.
This creates a formal path for reporting systemic issues: think unsafe model behavior, ignored red‑team findings, or deployments that quietly cross legal lines around manipulation or discrimination.
Bans on “nudifiers” and abusive contentThe AI Office has introduced explicit prohibitions on AI systems that generate non‑consensual sexually explicit or intimate content (including “nudifier” apps) and child sexual abuse material.
For victims of these abuses, that’s more than a symbolic move. It gives regulators and law enforcement a clear legal basis to go after both providers and deployers of such systems in the EU, rather than trying to squeeze them into older, less specific laws.
These rules will apply from December 2, 2026, with companies given time to bring their systems into compliance or pull them from the EU market.
Regrettably, this will not stop abuse completely. Attackers will still use unlabeled tools and infrastructure outside the EU. But it raises the bar for legitimate services and makes it harder for mainstream platforms to ignore the risks of deceptive AI‑driven features.
The AI Act won’t make AI safe overnight, but it shifts the default from “anything goes” to “you must play by some basic rules if you operate in the EU.” For users, that’s a step toward AI systems you can at least recognize and question, instead of having invisible technology quietly shape our online experience.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
