Malware Bytes Security

Subscribe to Malware Bytes Security feed
Cyber Security Software & Anti-Malware
Updated: 1 hour 13 min ago

Search results are sending people to fake Bitrefill checkouts

2 hours 28 min ago

Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and mobile top-ups. You can pay on their website for all of these with cryptocurrency.

The scam is designed to catch people searching for Bitrefill or something it sells, like a gift card. Victims see a search result that appears to lead to Bitrefill but actually points to a lookalike domain. The fake site then takes them through what appears to be a normal purchase. The fake sites are not operated by or affiliated with Bitrefill; scammers have copied its branding and checkout process.

The victim chooses an amount and a cryptocurrency before receiving a QR code and payment address. But instead of paying Bitrefill, they send the cryptocurrency directly to an address controlled by the scammers. They receive nothing in return, and recovering the payment is extremely unlikely.

Why fake crypto checkouts work so well

Phishing typically involves several steps. First, an attacker has to steal a password. Then, they may have to get past two-factor authentication (2FA), log in to the account without tripping a fraud check, and find some way to turn account access into money. Plenty of scams fall apart somewhere in that chain.

This payment scam avoids those hurdles by persuading victims to send money directly to the scammers. There is no account to break into and no stolen card to use. The victim sends cryptocurrency straight to an address the scammers control, and cryptocurrency payments generally cannot be reversed or charged back.

The payment request also fits the situation. A demand for cryptocurrency might look suspicious on many websites, but Bitrefill genuinely accepts it. On a convincing copy of its checkout, paying with cryptocurrency appears completely normal.

All this may explain why we found a cluster of fake sites rather than a single page, with checkouts allowing payments of up to $1,990.

What the fake checkout looks like

The site we examined is a close copy of Bitrefill’s checkout, hosted on a domain built by bolting a word onto the brand name. Everything a customer would expect is present. The branding is right, the layout matches, the page is quick and polished, and the payment flow behaves exactly the way the real one does.

The fake checkout asks for an email address and links to terms of service and a privacy policy, helping it look legitimate.

You’re asked for an email address for order updates, with links to terms of service and a privacy policy. You then choose how to pay, from a list offering Bitcoin, Ethereum, USDC, USDT, Solana, and Litecoin. The site also offers card payments for a small surcharge.

The fake checkout offers several cryptocurrencies and appears to support card payments.

Next, you pick an amount, with preset buttons and a maximum of $1,990, although inconsistent currency symbols offer a small clue that something is wrong.

The fake checkout accepts payments of up to $1,990.

Finally, you reach a payment screen showing a QR code, an address marked for one-time use, the amount converted into your chosen cryptocurrency, and a countdown clock giving you just under an hour to send the funds.

The final screen provides a cryptocurrency address and QR code, along with a countdown timer .

None of those elements is a red flag on its own. Unique addresses, expiry timers, and currency conversion are all normal for crypto checkouts, which is exactly why the copy is convincing. Every pressure cue on the page is borrowed from legitimate payment systems.

The only meaningful difference is the address the money goes to, and by the time the victim sends the cryptocurrency, getting it back is extremely unlikely.

How people are reaching these pages

The distribution here does not appear to rely on email. Bitrefill has said publicly that sites copying its checkout and using similar names have been turning up in search engine results, and that its security team has been working with takedown specialists to have them removed.

The site’s configuration supports that. The fake checkout hands visitors back to a second domain in the same family, and the link it uses carries a parameter naming a search engine, suggesting the operators are tagging incoming traffic by where it came from.

There’s a detail here that deserves more attention than it usually gets. The fake checkout has commercial analytics software installed on it, the same kind of product a legitimate e-commerce team uses to measure how many visitors abandon a cart. Its presence suggests the operators want to measure and improve the number of visitors who complete a payment.

These campaigns are not opportunistic one-offs thrown together by someone hoping for a lucky hit. They’re run as businesses, measured and tuned like any other funnel, with the victim in the role of the customer.

A brand name is not a destination

The domains in this cluster use several tricks to make their addresses look convincing. Some swap one letter for a visually similar character, making the brand appear correct unless you look closely. Others add a plausible word such as pay or gift, producing addresses that resemble official payment sites. Some do both.

Several use internationalized domain names, which can contain characters from different alphabets or accented versions of Latin letters. Browsers translate these domains into an ASCII format beginning with xn--, known as Punycode. To the eye, the displayed versions can be almost indistinguishable from the genuine name.

Different domain names display as variations of “Bitrefill,” while their Punycode versions begin with xn--.

The answer is not simply to become better at spotting tiny differences. These domains are designed to defeat visual inspection, and they can be especially difficult to recognize on a phone screen. Recognizing a company name somewhere in a web address does not tell you who owns it.

Remember, seeing the right company name in a URL is not enough. Check that the actual domain is exactly the one the company uses.

What to do
  • Start at the website you already trust. Use a saved bookmark or carefully enter bitrefill.com yourself. If you are already making a purchase on the legitimate site, stay within that session instead of opening a checkout page from a separate search.
  • Treat search results for payment and checkout pages with suspicion. Scammers can buy search ads or manipulate their sites into appearing prominently. The first result is not necessarily the safest one.
  • Check the address bar before you send. Cryptocurrency payments generally cannot be reversed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment.
  • Be wary of domains containing a brand followed by an extra word. A legitimate subdomain would place the additional wording before the company’s main domain, as in pay.example.com. An address such as example-pay.com is a completely separate domain that anyone could register.
  • Don’t approve wallet requests on a site you have not verified. Simply connecting a wallet does not normally transfer funds, but a fraudulent site may ask you to sign a transaction or grant token permissions that allow assets to be stolen.
  • If you have already sent funds, act quickly, although recovery is unlikely. Report the destination address to the exchange or wallet provider you used, report the incident to your national fraud reporting service, and notify Bitrefill so it can add the domain to its takedown efforts. Recovery services that promise to retrieve stolen cryptocurrency for an upfront fee are often follow-up scams.
Check before you click

The simplest protection against a page like this is to avoid reaching it. Malwarebytes Browser Guard is a free browser extension that blocks known scam and phishing sites, along with malicious ads and search results that lead to them.

Got a screenshot or URL of a suspected scam? Upload it to Scam Guard—built into Malwarebytes Premium Security on Windows, Mac, iOS, and Android—and you’ll get a verdict and safety tips in seconds.

Indicators of compromise (IOCs)

Domains:

biterflll[.]com

bitigift[.]com

bitrefall[.]com

bitrefill-payments[.]com

bitrefill-pays[.]com

bitregift[.]com

bitregill[.]com

bitretill[.]com

bitrgift[.]com

bitrgifts[.]com

bitrnfill[.]com

bitruflli[.]com

butrefill[.]com

pay-bitregill[.]com

pay-bitrgift[.]com

pay-bitrgifts[.]com

pay-butrefill[.]com

pay-bitigift[.]com

xn--bitrefll-71a[.]com

xn--bitrefll-h2a[.]com

xn--bitrefll-pay-kfb[.]com

xn--bitrefll-pay-xfb[.]com

xn--bitrefll-q2a[.]com

xn--bitreill-cz9c[.]com

xn--bitreill-pay-yq4f[.]com

xn--btrefill-l2a[.]com

xn--pay-bitrefll-fgb[.]com

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Google’s new search redirects make links harder to check before you click

Mon, 09/14/2026 - 10:17am

Google is changing how some links in its search results work.

Instead of linking directly to the destination, Google has started routing some search result links through opaque google.com/goto?url=... redirects. The url parameter does not show a readable version of the destination but uses a custom, Google-specific encoding.

Google confirmed the rollout to Search Engine Roundtable:

“We have a long history of deploying technical measures against evolving forms of abuse, and we regularly take steps to protect our services and users.”

Google has not said precisely what abuse the change is intended to prevent. However, the most likely reason is that the redirects are designed to make bulk extraction of destination URLs from Google search results more difficult and costly. Automated tools must now ask Google to resolve each result separately.

Since the rollout has apparently not reached my neck of the woods yet, I had to grab an image from another source.

Image courtesy of seroundtable.com

Some Reddit users find the change ironic: Google built its search business by automatically collecting information from other websites, but is now making it harder for others to collect information from Google.

Other users have complained about the collateral damage to legitimate tools. Rank tracking, SEO auditing, research, archival, accessibility, and alternate-index services may all face the same rate limits and costs as abusive scrapers.

Search results data provider Autom reports that the final destination is viewable only through the redirect response’s Location header. This means bulk collectors must make an additional request for every result.

Security

The first thing that popped into my one-track mind was the security downside. We often tell users to hover over a link before clicking it so they can check where it leads. That advice is less useful when hovering reveals an encoded Google redirect rather than the destination website.

Google still displays the claimed destination above each search result, but users can no longer use the link preview as an independent check.

So, Google, where does this leave our advice? We already tell people not to click Sponsored search results. Should we now tell them to avoid goto?url links too? Or will you give users an easy way to check where a link leads before they click it?

Safer. Cleaner. Ad-free browsing.

INSTALL BROWSER GUARD

Categories: Malware Bytes

Revolut gave customer IDs and financial data to a government impostor

Mon, 09/14/2026 - 7:15am

Revolut has acknowledged that it disclosed sensitive customer records to an unauthorized party. The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain, according to TechCrunch.

Revolut is a London-based banking and financial platform with more than 80 million customers globally, according to the company.

Revolut describes this as an external impersonation scam, not an intrusion into its systems. It also says customer funds were not affected. Revolut has not identified the government agency or disclosed its email domain.

The attacker appears to have abused the trust attached to a real government email domain to make bogus requests for customer information. Revolut detected the activity, blocked the sending address, and says it notified the relevant agency, law enforcement, data protection authorities, and financial regulators.

“Upon detection, we immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators.”

Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:

  • Identity and contact information like dates of birth, postal address, email address, and phone number.
  • Copies of IDs such as passports and driver’s licenses.
  • Verification selfies.
  • Account statements and transaction histories.

Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.

Those customers have received or will receive an email specifying which of their personal data was disclosed:

How to stay safe

The likely consumer impact will be second-stage fraud attempts rather than immediate unauthorized transfers. Here are some guidelines to help keep your money safe:

Treat any unexpected Revolut-related contact as suspicious, especially calls, emails, WhatsApp messages, or text messages claiming you need to “secure” an account, reverse a transfer, or replace documents. Do not use links or phone numbers supplied in the message. Revolut advises ending contact with suspected scammers and contacting the company through official channels.

IDs and other exposed information could be used for identity theft. Monitor your accounts and credit reports for unfamiliar account openings or credit applications, and consider placing a fraud alert or using credit monitoring where available in your country.

If you received a notification email, check your balances, cards, beneficiaries, recent transfers, account statements, and linked devices. Report any unfamiliar activity immediately through Revolut’s secure in-app chat.

If you were involved in a data breach, read our blog Involved in a data breach? Here’s what you need to know for more recommendations. 

Pro tip: Use Malwarebytes Scam Guard to analyze any suspicious communications. It can help you determine whether a message is a scam and advise you on what to do next.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Categories: Malware Bytes

Crypto customers targeted by scammers after email marketing provider breach

Fri, 09/11/2026 - 11:01am

An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields.

The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms.

Brevo initially said an attacker had gained access to 120 customer accounts, some of which were used to send phishing emails to the customers’ contact lists.

Brevo later said 138 customer accounts had been accessed in its postmortem:

“On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. 6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts. 93 accounts have no meaningful activity.”

According to reports, popular cryptocurrency companies Trezor, CoinTracking, and BitBox confirmed that phishing emails were sent to customers subscribed to their newsletters. Trezor warned its roughly 347,000 newsletter subscribers that a security incident at a third-party provider had resulted in a massive phishing campaign.

Trezor makes hardware wallets that store cryptocurrency private keys offline. Its customers received a phishing email titled “Critical Security Alert: STM32 Entropy Bug Identified.”

The subtitle read: “Urgent update regarding hardware microcontroller vulnerability.”

The email said:

“Dear customer,

We have some difficult news to share. Unfortunately, our engineering team has identified a critical hardware-level vulnerability in the STM32 microcontrollers used in a range of Trezor devices.

Currently we believe the majority of defective devices were initialized prior to 2023, however some newer devices also may be vulnerable. The bug is a hardware factory defect present in an estimated 1 in 4 devices.

The vulnerability results in:

  • Insufficient randomness in recovery phrase generation
  • Exposure of seeds to brute-force cracking
  • Seeds with as little as 40 bits of entropy”

That phishing email also contained a link that prompted recipients to download an app and enter their wallet backup.

CoinTracking said the attackers sent its customers an email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” which also contained a malicious link. 

Because the emails came from legitimate company domains and looked convincing, some recipients may have fallen for them. The exact number is not currently known.

How to stay safe

It can be difficult to recognize a phishing email when it comes from a legitimate company domain and looks convincing. But there are a few things to keep in mind:

  • If a company emails you about an urgent security problem, check its official website or app for confirmation.
  • Do not install apps through links in unsolicited emails, no matter how urgent the message claims to be.
  • Never enter your recovery phrase anywhere other than on your physical device.
  • Reputable companies will not ask for recovery phrases, API keys, or login details by email.
  • Use Malwarebytes Scam Guard to check whether a message might be a scam and get guidance on what to do next.
  • Keep an eye out for further information about other Brevo customers that have been affected. The attackers exported contacts from 43 accounts, which could be used in future targeted phishing attacks.
What to do if you followed the link

Trezor advises moving your funds to a new wallet if you entered your wallet backup in any form. If you followed a link in a similar email from another provider, contact that company directly for advice.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

Android malware creates a hidden copy of your banking app

Fri, 09/11/2026 - 8:14am

Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.

To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.

The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there. Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles.

Android work profiles are normally used to keep work apps and data separate from personal ones. Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile.

How an attack works

Victims are lured into sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.

To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as overlays.

The sideloaded app checks which other apps are installed and tells the operator which relevant banking targets are present.

Fake banking-login overlays steal both banking credentials and the device’s PIN.

The operator installs Vwork, which creates a new work profile on the device and clones the selected banking app. Vwork differs from Shelter in ways that make it useful to malware. It removes protections on cross-profile interaction, exposes components that can be used to set up a profile, clone and list apps, and open apps, and hides its launcher icon.

The operator can then remotely carry out transactions from the newly created profile, with the option to hide activity behind a black screen.

This is how Gigabud turns Android’s profile separation into a fraud tool: after compromising a phone, it creates a second profile, places a cloned banking app inside it, and performs the transaction from there. The result can be a dangerous gap between a malware alert in one profile and a fraudulent banking session in another.

How to stay safe

The immediate protection advice is familiar but important:

Sideloading. Install banking and other apps only from the official store or a direct link to the publisher’s website.

Install requests. Treat unsolicited requests to install an APK as a likely scam. If you’re unsure whether something’s a scam, run it through Malwarebytes Scam Guard.

Permissions. Do not enable Accessibility or “display over other apps” for a supposed airline, tax, delivery, or government app. Overlays require explicit user approval on modern Android, so a request like this is a red flag.

Protection. Use an up-to-date real-time anti-malware solution for your Android devices. Malwarebytes detects components of Gigabud as Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, Android/Trojan.Banker.ACR6C67829FH20, Android/Trojan.Banker.SIB02FFFFFF1112H106, Android/Trojan.Banker.SIB0181193e44H71, Android/Trojan.Banker.AUR2f2f4fb5C95, and Android/Trojan.Spy.Gigabud.xc.

Anyone who has installed a suspicious APK and granted it Accessibility access should contact their bank through a trusted channel, revoke the app’s special permissions, uninstall it, and consider a factory reset after preserving only known-good data.

A second instance of a banking app merits particular scrutiny. A separate work profile by itself is not proof of compromise because work profiles also have legitimate uses. But the presence of a cloned banking app definitely is suspicious.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

Thu, 09/10/2026 - 11:49am

BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble.

Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless.

But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running on Windows within days of one another.

The campaign is a timely reminder that once a security flaw, or even its fix, becomes public, attackers may move faster than many users expect.

The attacks began with phishing emails. A victim who clicked a malicious link could be sent to a web page designed to exploit two vulnerabilities in Chrome’s V8 JavaScript engine, followed by a Windows vulnerability to break out of the browser’s protections and gain higher privileges on the computer.

The Chrome vulnerabilities used by BlueMoon were patched in the Stable channel on September 3 and September 8, 2026. The first was already actively exploited when Google released its update. Microsoft addressed the Windows vulnerability in its September Patch Tuesday updates, by which point it was also being exploited.

CISA has since added all three flaws to its Known Exploited Vulnerabilities (KEV) catalog, which lists vulnerabilities known to have been exploited in real-world attacks.

The notable part is not just that BlueMoon exploited the flaws, but how quickly the capability appears to have spread. Publicly visible upstream fixes can give attackers clues before downstream browser updates reach users, allowing a weaponized chain to be developed and adopted by multiple groups very quickly.

Does that mean that patches can no longer be tested before they are released to the public? No, but we may need to rethink how they are tested and deployed, because it appears some cybercriminals are effectively beta-testing the patches themselves.

The researchers also found clues, but no conclusive evidence, that the exploit kit was developed with AI assistance. The broader concern is credible: AI tools can help attackers interpret source-code changes, write and modify code, document test results, and learn from failed attempts.

In practical terms, the gap between “a flaw is fixed upstream” and “most people are protected” may be increasingly valuable to attackers. We should try to minimize that gap.

How to stay safe

Not every security update needs to be installed the moment it appears. In organizations especially, updates may need testing, staged deployment, and contingency plans. But vulnerabilities known to be actively exploited deserve greater priority. That is precisely why CISA’s KEV catalog is so important: It helps organizations identify the vulnerabilities they should address first.

For home users:

  • Install browser and operating-system updates promptly. Use the few minutes they take to grab a drink rather than repeatedly postponing them.
  • Don’t click links in unsolicited emails.
  • Use up-to-date, real-time anti-malware protection to help catch the malware that exploit kits attempt to deliver.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Will AI kill us all within the next decade?

Thu, 09/10/2026 - 8:18am

The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control.

Jacob Coxon, an AI researcher who has worked at Anthropic and OpenAI, said:

“The people building AI earnestly believe that it could kill us all by the end of the decade.”

Evan Hubinger, Anthropic’s Alignment Science lead, who also worked at OpenAI, responded in a post on X:

“We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade.”

Hubinger added:

“What I am worried about is superintelligence arising from recursive self-improvement, as we have said is happening faster than we thought.”

That figure should be treated as Hubinger’s personal assessment. It is not a forecast, an established fact, or evidence that today’s chatbots are about to become dangerous on their own. Nor is it something I know enough about to endorse or dismiss.

Researchers are actively studying whether highly capable systems could act in unintended ways, exploit vulnerabilities, or be used to automate cyberattacks.

A BBC report notes that Hubinger described the risk from current models as low. His concerns focus on possible future systems with far greater autonomy and capability.

As companies and governments weigh the pace of AI development, we need sensible safeguards, including independent testing, limits on high-risk autonomous uses, transparency from developers, and accountability when AI systems cause harm.

Those measures should also address the problems we already face as cybercriminals use AI for fraud, privacy abuse, and other cybercrimes. Like many powerful technologies, AI can be used as a weapon, particularly when safeguards lag behind its capabilities.

Extreme predictions can be emotionally compelling, especially when made by people closely involved in the technology. But uncertainty cuts both ways: Serious warnings deserve scrutiny, not unquestioning belief.

The practical message is neither “ignore AI safety” nor “prepare for a robot apocalypse.” Companies, governments, and researchers need to work together to ensure that safety measures keep pace with rapid development.

Cooperation can complement competition, and in this case, it could be crucial.

Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

SCAN NOW

Categories: Malware Bytes

Update Chrome now to protect against an actively exploited vulnerability

Thu, 09/10/2026 - 6:52am

Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited.

The stable channel has been updated to 153.0.8010.36/.37 for Windows and Mac, and 153.0.8010.36 for Linux.

How to update Chrome

If you don’t want to wait for the rollout to reach you, manually updating is easy.

The easiest option is to allow Chrome to update automatically. But you can end up lagging behind on updates if you never close your browser or if something goes wrong, such as an extension preventing the update.

To update manually, click the More menu (three dots), then go to Settings > About Chrome. If an update is available, Chrome will start downloading it automatically. Restart Chrome to complete the update, and you’ll be protected against these vulnerabilities.

Chrome 153.0.8010.36/.37 is up to date

You can find an explanation of the version numbering system and step-by-step instructions in our guide: How to update Chrome on every operating system.

Technical details

The actively exploited vulnerability is tracked as CVE-2026-87491. The description says it’s an out-of-bounds write vulnerability in Chrome’s V8 engine that could allow a remote attacker to execute arbitrary code inside the browser’s sandbox via a crafted HTML page.

This means the bug was found in the part of Chrome that runs JavaScript. A malicious website could exploit it by getting someone to load a specially designed web page, causing Chrome’s JavaScript engine to mishandle memory and run attacker-chosen instructions. Those instructions would initially run within Chrome’s security sandbox rather than with unrestricted access to the whole device.

Chrome’s sandbox is intended to limit that code’s access to the rest of the device, but the flaw is still serious because it gives an attacker a foothold simply by getting a target to view a malicious web page. Emails are unlikely to trigger the flaw because most reputable email clients sanitize incoming HTML before displaying it. They strip or disable active web features that would let a sender run code in the inbox, such as JavaScript. However, an email could contain a link that takes the recipient to a malicious website.

Besides this medium-severity flaw, the update fixes five vulnerabilities rated Critical, four of which were found in WebGL (Web Graphics Library). WebGL is a JavaScript programming interface used to render interactive 2D and 3D graphics inside the browser without needing extra plugins.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Copyright scammers get Instagram accounts suspended and demand payment

Thu, 09/10/2026 - 5:59am

Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC.

Criminals file fake copyright complaints with Instagram, claiming that an account is using material it doesn’t own. Repeated complaints can trigger a temporary account suspension from the platform, locking out the victim even though they haven’t done anything wrong. The criminal then moves the conversation to another platform, such as Telegram, and demands a ransom to withdraw the complaint.

We’ve reported on a similar scheme before. In that case, scammers abused Instagram’s reporting system to get accounts taken down and then charged their owners to restore them.

The BBC interviewed the owner of a history-focused Instagram account who said that he had been hit by copyright claims multiple times from the same email address. Repeated copyright claims can eventually result in an account being disabled, making this particularly damaging for people who use Instagram to generate income.

The account holder eventually paid $50 in cryptocurrency because he said it could take weeks for Meta to deal with his claim and that they were unhelpful to begin with. However, the scammers targeted him again immediately afterward.

Users do have free support routes, including the appeal option that comes with the copyright notification and Instagram’s in-app Help section. Paid options include the 24/7 access to a support agent that comes with Meta Verified, while Meta Business Support is available to some eligible business and advertising accounts.

The scam works because Meta has automated much of its processing of copyright complaints. It doesn’t verify the authenticity of complaints when they are filed, and repeated complaints can result in an account being temporarily taken down. Its policy says that only rights holders or their authorized representatives can file a complaint, but it doesn’t check their ID before acting. That means criminals can pretend to be rights holders or their lawyers and get away with it.

AI could make it easier for scammers to file these fraudulent complaints at scale, turning the attack into a trawling exercise. If they convince just a few victims to pay a ransom, it can become worth their while, especially if Meta takes too long to resolve the problem manually.

The BBC spoke to one Instagram account owner who said that he had lost brand contracts over the issue. Meta hadn’t been able to assure him that the problem wouldn’t happen again, he said.

This problem is drawing legal scrutiny. In India, the Delhi High Court is examining whether social media platforms can legally suspend user accounts over copyright violations. In a separate case, Meta acknowledged in court that 13 copyright strike notices against one Instagram user were fraudulent and restored the account.

Meta told the BBC that it fights deceptive behavior intended to scam people. After reviewing the accounts identified by the BBC, it restored affected content and added unspecified protections intended to prevent similar attacks. However, the company hasn’t announced any blanket protections designed to fix its “suspend first, verify later” approach.

Law enforcement advises victims not to pay the ransom because that feeds the scammers. It also doesn’t guarantee that they won’t hit you again. In fact, it might make them more likely to do so if they know that you are willing to cough up.

Copyright complaints are also commonly used as phishing lures. We have previously reported on scammers sending fake copyright warnings to X users and convincing copyright notices to YouTube creators. Those attacks tried to steal people’s login details. In this case, the scammers are abusing Instagram’s genuine complaints system to get accounts suspended.

How to protect your Instagram account
  • Turn on two-factor authentication. This will not prevent fraudulent complaints, but it can help protect your account if scammers also try to steal your login.
  • Check copyright complaints in Instagram. Don’t rely on links or screenshots sent by email, Telegram, or another messaging service.
  • Don’t pay to have a complaint withdrawn. Paying does not guarantee that the scammer will withdraw it or leave your account alone.
  • Don’t share login details or verification codes. A scammer may use the copyright complaint to steer you toward a fake Instagram login page.
  • Use Instagram’s official appeal process. Keep copies of the complaint, ransom demands, usernames, email addresses, and payment requests as evidence.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

More than 100,000 fake stores are out to steal your card details

Wed, 09/09/2026 - 11:02am

Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores.

The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined.

The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even loading images directly from the real companies’ infrastructure.

As we have reported in the past, AI-powered website builders make it easy to clone major brands. However, Nebty’s findings are based on shared website and infrastructure characteristics, rather than evidence that every domain is operated by a single identified group.

BleepingComputer reports an important checkout-level detail: 96% of confirmed DoppelCart shops reportedly shared identical build files and used just 27 ecommerce backends.

The fake shops mimic more than 44,000 brands, with a median of two clones for each brand.

“However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.”

Nebty observed advertised discounts of up to 65%, a tactic designed to encourage shoppers to act before closely checking the domain, company details, or payment process.

The fraudulent checkout pages collect cardholder data and transmit it to attacker-controlled servers over WebSockets in real time. That may include card numbers, expiry dates, CVVs (card verification values), billing information, and even one-time confirmation codes issued by banks.

Capturing an authentication code in real time can help criminals to complete a payment while the victim is still going through the checkout flow.

How shoppers can stay safe

A professional-looking store, the use of HTTPS, authentic product images, and a familiar logo do not prove that a website is legitimate. Before entering payment details, shoppers should take a few minutes to verify where they are buying from.

  • Check the web address carefully. If possible, reach the retailer through its official app, a saved bookmark, or a web address you already know, rather than sponsored search results or ads on social media.
  • Be wary of unusually large discounts. A low price does not prove that a store is fake, but it is a reason to check the site more carefully.
  • Search for the exact web address alongside terms such as “scam” or “reviews.” Check that the contact details, returns policy, and company information match the real retailer.
  • Pay by credit card or another service with buyer protection. Avoid cryptocurrency, bank transfers, gift cards, and other payments that are difficult to reverse.
  • Check every bank verification request carefully. Make sure the merchant and amount are correct, and never give a one-time code to a retailer or anyone who contacts you.
  • Use an up-to-date, real-time anti-malware solution with web protection.
  • If you’re unsure whether a store is genuine, use Malwarebytes Scam Guard to help you assess it.

If you’ve already paid, act quickly. Contact your card issuer, report the suspected fraud, ask about replacing or monitoring your card, and save screenshots, order confirmations, web addresses, and correspondence.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Microsoft fixes record 964 flaws, including 2 exploited zero-days

Wed, 09/09/2026 - 6:01am

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record.

Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch.

The release includes fixes for two actively exploited Windows zero-days. Both are local elevation-of-privilege vulnerabilities that could allow an attacker who already has access to a device to gain SYSTEM privileges. Neither provides remote access by itself, but SYSTEM-level access is valuable to malware operators after they gain an initial foothold through phishing, stolen credentials, or another method.

How to apply patches and check if you’re protected

These updates fix security problems and help keep your Windows PC protected. Here’s how to make sure you’re up to date:

  • Click the Start button, then open Settings.
  • Select Windows Update (usually at the bottom of the menu on the left).
  • Click Check for updates. Windows will search for the latest security updates. If you’ve enabled Get the latest updates as soon as they’re available under More options, you may be prompted to restart immediately to complete the update. Otherwise, continue to the next step.
Windows 11 up to date
  • If updates are available, they’ll start downloading automatically. When they’re ready, click Install or Restart now if prompted. Your computer may need a restart to finish the update.
  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set.
Technical details

The unusually large batch also includes high-severity remote-code-execution vulnerabilities in Windows DNS Server and Remote Desktop Services, as well as fixes affecting Exchange Server, SharePoint, SQL Server, Office, and core Windows components.

Let’s take a closer look at the two zero-day vulnerabilities. Microsoft classifies a vulnerability as a zero-day if it was publicly disclosed or actively exploited before an official fix became available.

The first is a Windows Update Stack elevation-of-privilege (EoP) vulnerability with a CVSS score of 7.8 out of 10, tracked as CVE-2026-81963. The description says:

“Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.”

This means Windows can be persuaded to open or modify the wrong file because it follows a shortcut-like pointer without properly checking where that pointer leads. Microsoft says attackers exploited the bug before a patch was available.

The second zero-day, tracked as CVE-2026-85880, also has a CVSS score of 7.8 out of 10. Microsoft describes it as:

“heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.”

Microsoft says an attacker who can execute code in a low-privilege AppContainer could exploit the vulnerability locally to escape the sandbox and elevate their privileges on the affected system. No additional user interaction is required.

Windows ALPC is an internal messaging system in the Windows operating system that allows different programs on the same computer to communicate with each other quickly.

A buffer overflow occurs when an area of memory within a software application reaches its boundary and data spills into an adjacent memory region. The heap is a region of memory used for dynamic memory allocation.

These are not the kinds of bugs a typical victim triggers merely by opening a malicious document or visiting a website. But local privilege escalation is a critical part of many attack chains: After malware runs with limited rights, a SYSTEM-level exploit can help an intruder disable defenses, access protected data, establish persistence, or move through a network.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

The push to stop algorithms controlling social media feeds has begun

Wed, 09/09/2026 - 4:28am

Remember when social media was filled only with posts from your friends, rather than what an algorithm decided you wanted to see? So does the Australian government, and it wants that internet back.

Yesterday, the government released draft legislation outlining a Digital Duty of Care. The proposal includes a measure that Prime Minister Anthony Albanese labeled “My Feed, My Way.” It would allow Australians over 16 to switch off the algorithmic feed that social media platforms deliver automatically to users, instead allowing them to see content from friends and creators they choose to follow.

This legislation, which is expected to reach Parliament before Christmas, would force platforms to send notifications to both new and existing users asking them to choose between the two types of feed. Platforms would then have to respect that choice unless the user changed it.

The feed controls are grabbing the headlines, but the Digital Duty of Care also includes protections for users under 18. Digital services, including social media, online games, apps, and AI chatbots, would have to protect under-18s from harmful content and design features that could negatively affect their behavior or self-esteem.

That includes content that promotes eating disorders, misogyny, crime, life-threatening stunts, pornography, or serious mental health distress.

The proposed law is the latest move from a country known for its aggressive stance on social media safety. Australia banned under-16s from using a wide range of social media platforms, although it hasn’t gone that well.

Three months after the December 2025 ban, 81% of Aussie kids were still using at least one restricted social media platform, down from 86% when the ban was introduced. Before the ban took effect, about 60% used social media at least once a day. Three months later, that figure was 58%.

Bans sound good on paper but they’re hard to enforce.

The new proposal takes a different approach by placing more responsibility on social media companies. The government promises penalties of up to $109.2 million Australian dollars (US$78.6 million) for companies that fail to comply with the Digital Duty of Care.

The Australian eSafety Commissioner would also gain the power to issue removal notices for nudify apps and websites, and streamline its existing child cyberbullying and adult cyber abuse schemes so it can deal with harmful material more quickly.

The move comes less than two weeks after Meta agreed to let teens choose a non-personalized feed as part of a multi-billion dollar settlement with US states.

Why is an opt-out from automatically curated feeds important? Companies that automatically curate your content with their own algorithms tend to show you more of what you’ve been seeing.

That can be great if you’re building a chicken coop and want as much advice as possible on nest box placement. But it can also narrow the range of content you see, making it harder to develop a well-rounded view of a subject.

Perhaps sensing a change in the political wind, social media companies have already begun offering friends-only feeds. Facebook reintroduced this capability in its Friends tab in the US and Canada in March 2025. It called this one of its “OG” Facebook experiences.

TikTok also now has a Friends tab alongside its regular For You feed, while Instagram has offered chronological Following and Favorites feeds since 2022. YouTube has its Subscriptions feed, while Snapchat created separate feeds for friends and other content creators back in 2017.

The problem is that these feeds aren’t the default. Recommended content remains the easiest option to consume.

If you use social media and want more control over what you see, look for its Friends, Following, Favorites, or Subscriptions feed. You might end up with more humblebragging, vaguebooking, or faux-wisdom memes, but at least you’ll know why you’re seeing them. And you can always get some new friends.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Grindr settles HIV status data-sharing lawsuit for $35 million

Tue, 09/08/2026 - 8:51am

Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers.

The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users. It alleges that the dating app breached privacy and data-protection laws during a period ending in early 2020.

The claimants allege that Grindr shared personal and highly sensitive information with advertising companies without consent. According to Austen Hays, the shared data may have included ethnicity, HIV status, the date of a user’s last HIV test, and whether they used pre-exposure prophylaxis (PrEP).

At the time of the alleged data sharing practices, Grindr was owned and controlled by the Chinese gaming company Beijing Kunlun Tech. Grindr was sold to US owners in 2020.

According to a US regulatory filing, Grindr will make two payments of £13 million: one by December 31, 2026, and the second by March 31, 2027.

In its SEC filing, Grindr said that the settlement is not an admission of liability and, while it disputes the allegations, it:

recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period.

The UK settlement follows a separate enforcement case in Norway. The country’s Data Protection Authority found that Grindr had shared users’ personal data with advertising partners for behavioral advertising without a valid legal basis.

These cases illustrate a crucial privacy point: information does not need to be explicitly labeled as medical information or information about sexual orientation to expose intimate details about someone. Advertising identifiers, IP addresses, locations, device information, and confirmation that a person uses a particular app can be combined to identify them or draw sensitive conclusions about their life.

Many free apps rely on advertising SDKs, analytics providers, and other third parties to make money. These integrations can receive identifiers and event data that help target or measure advertising, but they can also create extensive trails of user behavior.

How to protect your privacy on dating apps

Grindr says it has overhauled its privacy program since 2020 and remains committed to user control and responsible data practices. Even so, dating apps can hold unusually personal information about their users.

To limit what you reveal:

  • Review the app’s privacy settings and turn off optional personalized advertising where available.
  • Limit your profile to details you’re comfortable sharing with potential matches.
  • Avoid linking a dating profile to public social-media accounts unless you want identities to be easily connected.
  • Revoke location permissions when you’re not actively using the app, or choose “while using the app” rather than continuous access where your operating system offers it.
  • Keep the app, your operating system, and your security software updated.
  • Watch for romance scams and extortion attempts, particularly requests to move the conversation off the app, send money, share intimate photos, or reveal identifying information.

If you’re unsure whether a message may be part of a scam, you can check it with Malwarebytes Scam Guard, which can help you assess the conversation and decide what to do next.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

MikroTik router flaws allow takeover without a password

Tue, 09/08/2026 - 5:49am

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.

Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet.

Attackers are exploiting two vulnerabilities, collectively dubbed “MikroTrick,” to take full control of vulnerable devices, CERT Polska says.

A compromised router is especially serious because it sits at the edge of your network. An intruder may be able to change DNS settings, redirect or capture traffic, create remote-access tunnels, alter firewall rules, or use the device as a foothold to attack other devices on the network.

Two of the six disclosed vulnerabilities form the chain of compromise known as MikroTrick. The first, tracked as CVE-2026-67276, is an SSH authentication-bypass flaw in the handling of RSA public keys. The second, CVE-2026-86060, is a privilege-escalation flaw involving a specially crafted username in the SSH login process.

Put simply, the first flaw lets attackers get in without a password, and the second lets them make themselves an administrator.

SSH (short for Secure Shell) is a network protocol that establishes encrypted connections between computers for secure remote access.

CERT Polska issued the warning because the patched RouterOS packages are already public, and their comparative analysis has allowed the community to reconstruct some of the flaws they fix. 

How to stay safe

MikroTik router owners should install the latest RouterOS security update as soon as possible. Use the router’s update mechanism or obtain the supported package directly from MikroTik. The update option should be available under Check for updates.

You should also remove public access to the router’s management services. Make sure that SSH is not accessible from untrusted networks. If remote administration is necessary, limit access to known IP addresses.

Remote management should be the exception, not the default. MikroTrick demonstrates that a strong password alone cannot protect a device from an authentication-bypass vulnerability.

MikroTik has added a detection mechanism that scans the configuration at startup for selected signs of unauthorized changes. If it finds any, RouterOS disables the recognized suspicious entries and sets the device’s Flagged status to Yes. Administrators can check this with /system/device-mode/print.

RouterOS restricts several potentially abusable functions while the device is flagged, but MikroTik stresses that the router’s full configuration still needs to be audited before the flag is cleared.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

Mon, 09/07/2026 - 2:23pm

This week on the Lock and Code podcast…

Crooks are taking a holiday. They’re counting on you to fund it.

For decades, cybercriminals have stolen roughly the same types of data. Biographical and personal details—like Social Security numbers, birthdates, addresses, and phone numbers—can be stolen to commit identity fraud. Credit card numbers, expiration dates, and CVC codes can be stolen to make fraudulent purchases. Usernames and passwords can, in the wrong hands, let a cybercriminal impersonate someone, steal sensitive photographs to later use for extortion, or abuse a reputation.

All of these attack models seek to turn sensitive or important data into currency. But an emerging form of digital fraud is targeting data that, when used strategically, practically is currency: Loyalty points.

Loyalty points programs are run by nearly every type of consumer-facing business today, from hotels to airlines to grocery stores to donut shops. As repeat customers accrue these points, they can exchange them for discounted prices on future purchases, cutting the costs of hotel stays, flights, rental cars, and even entire vacations.

But the value stored within these loyalty points makes them a high target for cybercrime, said Kim Sutherland, Global Head of Fraud and Identity at LexisNexis® Risk Solutions.

“Most loyalty currency is worth about one cent per point, and then there are premium programs that can be worth more than that,” Sutherland said, explaining that 100,000 airlines points, for example, can be worth $1,000 in the US. “Why criminals care so much about this is because most of us are not paying attention to our loyalty programs the same way we would our bank account.”

But diligence is much needed here, Sutherland said, noting that one Chicago teacher only learned that 240,000 of his airlines points had been stolen because he received a basic confirmation email about their use. In another example, a man’s airline miles were stolen and fraudulently used to book rental cars in New York and Memphis.

Today, on the Lock and Code podcast with host David Ruiz, we speak with Sutherland about loyalty points theft— how it happens, what companies are doing to protect customers, and what people can do to stay safe.

“Some of us don’t even know how to access those points, right? Or we don’t even know we’re accumulating them, but the fraudsters do.”

Tune in today to listen to the full conversation.

Show notes and credits:

Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)

Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.

Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.

Categories: Malware Bytes

LG TV flaws could let attackers listen in, even in standby mode

Mon, 09/07/2026 - 9:34am

Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices.

In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR)

ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares that fingerprint against a reference database. It can be used to identify programs, ads, and viewing habits.

Now, a new investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers, has examined several LG TV models. The team says its found extensive device and network discovery, ACR tracking, and security weaknesses that could increase the consequences if a television were compromised.

Some findings concern LG’s intended product behavior, while others rely on vulnerabilities that researchers say are still being disclosed responsibly. But the broader lesson is clear: A smart TV deserves the same privacy and security consideration as any other internet-connected computer.

According to Gamers Nexus, packet captures and firmware analysis showed the tested LG TVs identifying devices on the local network, such as phones, PCs, printers, switches, and smart-home hardware. The investigation also says the TVs collected nearby Wi-Fi network names, signal information, and device-related identifiers.

This network information could help build a picture of the other devices in a household. Combined with ACR data, advertising IDs, and other information, it could support detailed profiles of what people watch and the devices they use.

The researchers also demonstrated how a compromised TV could capture audio through its microphone, including when the TV appeared to be off. They even showed how the TV stored audio when it was unplugged from the internet and retrieved it after the connection was restored.

The researchers also reported remote-code-execution vulnerabilities to LG. They have not disclosed full details while the responsible disclosure process is ongoing.

A compromised television could be more than a privacy issue. It might provide an attacker with a foothold on a home or business network, access to audio, or a route to probe other devices.

How to stay safe

The concerns are not limited to one brand. Smart TVs sit at the intersection of entertainment, advertising, and the home network. Treating them as security-sensitive devices—and demanding clear, meaningful privacy choices—is increasingly part of staying safe at home.

There is no need to panic, but owners can take a few practical steps to limit what their TV collects and what it can access:

  • Install firmware updates promptly, especially security updates. Check your model’s support page and the TV’s software-update settings.
  • Review the privacy controls under Settings, Privacy & Terms, or User Agreements. Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need.
  • Don’t accept every agreement by default. Read each consent screen and decline optional advertising and voice-data features where possible.
  • Use a separate IoT or guest network for televisions, cameras, speakers, and other smart-home devices. This limits what a compromised device can reach on your main network.
  • Disable UPnP on your router unless it is genuinely needed and avoid exposing TV services directly to the internet.

Our earlier guide to disabling ACR includes instructions for several popular TV brands.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Flirty OnlyFans promoters on X may be using AI to appear human

Mon, 09/07/2026 - 7:18am

In a recent post, we looked at reports of League of Legends players receiving suspicious friend requests shortly after matches. The accounts quickly steered the conversation toward Discord, where they promoted paid adult-content pages.

At the time, one unanswered question was how much of those conversations was automated. Were people working from scripts behind the accounts? Were they conventional, rules-based chatbots following a limited decision tree? Or were they using generative AI to produce more natural and flexible replies?

People are more likely to trust someone they believe is personally interested in them. AI can create that impression across many conversations at once, making it easier to persuade people to click links, spend money, or share personal or intimate information. The same approach could also be used for more harmful fraud, including romance scams and sextortion.

Now, developer Álvaro Martínez Majado has investigated several flirty accounts promoting OnlyFans pages on X to see whether their replies were scripted, generated by AI, or written by people. Majado, president of digital rights organization Protecció de la Frontera Electrònica, shared his evidence with Malwarebytes. Although it does not provide a definitive answer, it shows the accounts following rigid conversation scripts while also responding dynamically to unusual requests. The signs that once suggested a real person, such as an unusual reply or personalized voice note, can no longer be trusted.

The script goes on and on

Majado interacted with several accounts on X that followed a familiar pattern. They opened with similar casual, flirtatious language and asked broadly the same qualifying questions: where he lived, what he liked, and what he did for work.

That repetitive structure is exactly what we would expect from a commercially motivated messaging campaign. The goal is not necessarily to have a meaningful conversation. It is to identify people likely to respond, establish rapport, and eventually move them toward a paid page or another destination controlled by the operator.

The accounts also stayed in character when faced with obvious attempts to expose them as bots. That could be the result of hard-coded replies, guardrails around an AI system, or both.

They claimed to live in the same city as the recipient

But some later interactions were more difficult to explain as a simple bank of canned flirtatious responses.

One of the more interesting tests involved an instruction written as ASCII hexadecimal rather than ordinary text. The encoded message told the account to reply with a single word: “Pineapple.”

According to the screenshots supplied to Malwarebytes, the account responded with “Pineapple” in ordinary text.

An account followed an instruction encoded in hexadecimal

That does not conclusively prove which technology was used. It does not identify a model, a provider, or the people behind the accounts. But it is consistent with an automated system capable of interpreting an encoded instruction and changing its output accordingly.

A simple scripted bot could theoretically include a hexadecimal decoder, of course. But that would be unusual in a basic adult-content promotional bot, especially when combined with other examples of flexible and sometimes error-prone responses.

In another interaction, Majado asked an account to provide a reply of exactly 12 characters. It responded with “Imnotabotfr”—an 11-character answer—then appeared to recognize its own counting mistake.

The account failed an exact character-count test, but recognized its error

Anyone who has spent time experimenting with large language models may recognize the pattern. Language models can be very good at generating natural-sounding text while still making surprisingly basic mistakes involving character counts, word counts, and other exact constraints.

A deliberately designed bot could imitate this kind of mistake, so it is not proof of AI. But the account understood an unexpected instruction, attempted to follow it, and reacted when it got the answer wrong. That suggests it may have been generating replies dynamically rather than choosing from a list of pre-written responses. Such accounts can adapt to conversations, making them harder to identify as automated.

Voice notes do not settle the question

The accounts also sent voice notes. In one example, an account read aloud a Unix timestamp supplied during the conversation. In another, it spoke a requested username.

The accounts sent voice notes containing requested information

These responses show that the accounts could incorporate unusual information from a conversation into audio messages. They do not tell us whether a person recorded the clips or a text-to-speech tool generated them.

Text-to-speech tools can generate short, convincing clips quickly and cheaply. An operator can generate them manually, but the process can also be automated: Take a message, pass selected text to a voice-generation service, and send the resulting audio back to the recipient.

Here’s one of those voice notes. Is it a very flirty girl, or AI-generated? Have a listen and see what you think:

The supplied audio metadata offered a possible clue about the tools involved, but it is not enough to attribute the voice notes to a particular service. Platforms and other software can alter audio files and their metadata.

The more important point is that the voice notes were personalized and continued even after the interaction appeared unlikely to lead to a sale. That is consistent with a system designed to keep conversations moving without requiring a human to supervise each one.

AI does not replace the funnel

The evidence does not mean every message from every flirty spam account is written by an AI. Nor does it establish that the X accounts are operated by the same people targeting League of Legends players.

What it does suggest is a plausible hybrid model, supported by identical replies across different accounts alongside more flexible responses.

The repetitive parts of the operation can be scripted: opening messages, questions about location and interests, links, and attempts to move people to another platform. An AI-powered conversational layer could then make the exchange feel less repetitive when someone asks unexpected questions, changes the subject, or tries to test whether the account is real.

This combination makes practical sense for spammers. Scripts provide consistency and keep the conversation directed toward conversion. Generative AI helps the account handle the unpredictable parts of talking to real people.

It also means that traditional “bot tests” are becoming less useful. Asking an account to answer an unusual question, decode a message, or send a voice note may no longer distinguish a real person from a fake one.

How to stay safe

Treat unsolicited flirtatious messages with caution, especially when they quickly become transactional.

  • Do not assume a personalized response or voice message proves an account is genuine.
  • Be wary if a new contact repeatedly tries to move you to Discord, Telegram, Signal, another messaging app, or a paid-content platform.
  • Do not send money, gift cards, cryptocurrency, intimate images, identity documents, or account credentials to someone you only know online.
  • Avoid opening links or downloading files from accounts that contacted you unexpectedly.
  • Reverse-image-search profile photos and look for copied biographies, reused images, or accounts with very limited genuine activity.
  • Report suspicious accounts to the platform, particularly if they impersonate someone, send malicious links, or pressure users for money or explicit material.

Whether it’s a human, a chatbot, or an AI agent you’re talking to is an important question. AI could make these operations more convincing and much easier to scale. One operator could hold flirtatious conversations with many people, adapting the messages without personally managing every exchange.

That makes it easier to create a false sense of connection and persuade people to click links, pay for content, or share personal or intimate information.

The line between a scripted spam account and a responsive conversational partner is getting harder to see. Judge the account by what it wants you to do, not by how convincingly it talks.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

The hidden work of modernizing Malwarebytes

Fri, 09/04/2026 - 1:15pm

Most of the work that keeps a security product trustworthy is invisible. Users see a scan complete, a threat blocked, an update applied overnight. They don’t see the platform underneath. Runtimes, managed libraries, native drivers, and Windows requirements must all stay current and work together across millions of endpoints. Our migration to .NET 10 is one example of how we keep that platform moving and our focus in this article.

It would be easy to call these upgrades maintenance tasks and move on. But that is underselling them. Our code runs continuously, with elevated privileges, next to some of the most sensitive parts of Windows.

Every dependency in our stack, from the runtime and third-party libraries to native drivers and operating-system requirements, affects the environment in which our software runs. When one changes, everything that relies on it may have to change too.

The problem: platforms fall behind by standing still 

In endpoint security, the ground never stops moving. Windows evolves. Threats evolve. Hardware evolves, from ARM64 laptops to machines with far more memory and faster storage than the ones our code was first written for.  

A platform that stands still does not stay the same. It falls behind. Every skipped release of a dependency or runtime widens the gap between the ecosystem we built on and the one that is stable today.  

A modern runtime and .Net 10 in particular can give us better security, faster code paths, a smaller memory footprint, and richer diagnostics. It also gives our engineers language and tooling improvements that help them work more efficiently. 

The stakes are also particularly high for security software: 

  • A web app can be rolled back with a deployment. Software already installed on a customer’s endpoint cannot. 
  • Our code runs with high privileges, alongside kernel drivers and anti-tamper protections.   
  • A runtime regression does not affect one server. It has the potential to affect millions of machines.  

So we treat a runtime upgrade with the same rigor as a security feature. 

The challenge: everything moves together 

Malwarebytes for Windows is not a single program. It is a coordinated system: a user-facing interface, several long-running Windows services, an installer, a self-update pipeline, a plugin surface, and third-party managed dependencies.  

These sit above native drivers and our detection engine. The .NET 10 migration covered the managed parts of Malwarebytes while leaving this native core untouched. But the different layers still have to work together. 

The migration had to satisfy several requirements at once:  

  • Security-sensitive code had to behave identically before and after the change.  
  • Native drivers and anti-tamper layers had to continue working correctly with the  managed code. 
  • The installer and update pipeline had to deploy the new runtime files and clean up old ones.  
  • Plugins and third-party dependencies had to remain compatible. 
  • Existing Malwarebytes installations had to continue working.  
  • Our automated validation had to be extensive enough to trust the result without inspecting every path by hand. 

The boundary between managed and native code deserved particular attention. Managed code in our services talks to native components through interfaces such as P/Invoke and COM. A runtime change can subtly affect how these different parts of Malwarebytes communicate and work together. 

Those differences may never show up in a demo. They might only surface on one machine in 10,000. Finding them before customers do is the important part. 

Not every update looks the same 

There are three main reasons we update a dependency: We choose to, the platform underneath forces us to, or a vulnerability makes us. Each comes with a different timeline.  

Elective modernization. We may choose to move to a new runtime, a new major version of a library, or a new platform capability to take advantage of new features, fixes, or security improvements.  

Baseline shifts. As platform requirements evolve, some older compatibility constraints can hold back modernization. For example, moving to .NET 10 allowed us to update the application baseline and adopt a newer, supported runtime. As part of the same change, Windows 7 support was deprecated. 

Forced patches. Sometimes a vulnerability is disclosed in a library we ship or a system we depend on. The change is no longer optional and the timeline is not ours. What we can control is our readiness: the testing, release process, and staged rollout that allow us to respond quickly without introducing new problems. 

Different reasons and different timelines, but each requires the same careful approach. 

The .NET migration: Why we did it 

Moving to .NET 10 gives Malwarebytes a more secure, supported, and capable foundation for Windows, with several compounding benefits: 

Security. A modern runtime benefits from Microsoft’s ongoing security work, including safer defaults, stronger cryptography, and mitigations for memory and interoperability bugs. Staying on a runtime that Microsoft actively supports means we can continue to apply fixes when vulnerabilities are discovered.  

A supported foundation. It may not be a glamorous reason, but .NET 10 keeps us on a supported, actively developed platform that is better aligned with newer versions of Windows. It makes it easier to adopt future fixes, features, and improvements as routine work instead of one-off projects. 

Diagnostics and observability. Modern .NET has stronger built-in tracing, metrics, and crash diagnostics. In a security product, understanding how code behaves in the field matters. Better diagnostics help us identify and resolve reliability issues.  

Performance and memory efficiency. Recent .NET releases have improved the just-in-time compiler, garbage collector, and core libraries. Our processes run all day in the background, so how efficiently they run and manage memory matters. These capabilities give us more opportunities to improve efficiency, although the impact will vary between components. 

The .NET migration: How we did it  

The guiding principle is simple: Never advance faster than the evidence allows.  

We started by isolating the work on a dedicated branch. We retargeted the platform and refreshed every managed dependency so the new runtime and the codebase agreed on exactly which components should ship.  

That surfaced some of the less obvious consequences of the upgrade early on: libraries that had been renamed or folded into the runtime, files that were no longer needed, and new ones that had to ship in their place. 

Deployment is easy to overlook and expensive to get wrong. A runtime migration is not only about the code that runs. It is also about what lands on the customer’s disk.  

Our installer and update service had to learn the new runtime’s file layout. They had to remove dependencies the runtime now provides, stop shipping renamed files, and deliver replacements cleanly during both fresh installs and in-place updates.  

Getting deployment right is the difference between an upgrade users never notice and one that creates a support problem. 

Once the build was working correctly, the focus moved to validation. 

The migration involved: 

  • Extensive automated testing across services, install, and update paths. 
  • Compatibility validation against real-world configurations and previous installations. 
  • Performance benchmarking to catch regressions in startup, memory, and scan behavior. 
  • Canary and staged deployment, starting with small populations and expanding only when results showed it was safe to do so. 
  • Continuous monitoring and automated regression detection in the field. 
  • Cross-functional work across platform, QA, installation and update, and release engineering. 

“We never advanced faster than the evidence allowed. Every gate had to turn green on its own.” 

The .NET migration: The tradeoffs  

None of this was free, and the choices involved deliberate tradeoffs.  

The tradeoff on the branch was drift. Isolating the migration protected the main codebase, but the longer that branch existed, the more it could diverge from active development. We managed that risk through frequent integration rather than leaving one large, risky merge until the end.  

The tradeoff on rollout was speed. Staged deployment also meant customers received the update later than they would with a big-bang release. We accepted that tradeoff. Evidence from smaller populations gives us an opportunity to catch problems before an update reaches a much larger number of endpoints. 

The tradeoff on AOT was flexibility. Ahead-of-time compilation can improve startup performance but can also constrain dynamic behavior. We applied it selectively, component by component, rather than everywhere by default. 

What the .NET 10 migration means for customers

The best outcome of infrastructure work is that customers benefit from it without having to think about it.  

On .NET 10, those benefits for Malwarebytes customers include:   

  • Improved reliability on a fully supported, actively maintained runtime.  
  • A more secure foundation that benefits from the platform’s continuing security improvements.  
  • Access to new .NET features and fixes. 
  • Better support for newer versions of Windows. 
  • Newer .NET tools can help us develop and deliver new protection faster. 
Lessons worth keeping  

Every one of these updates—the runtime, the baselines, the security patches—leaves the team holding a few convictions more firmly.  

Platform upgrades are strategic investments in everything built on top of them. Modernization also works best when it is continuous: the longer a platform falls behind, the more difficult the eventual upgrade can become. 

Automation is particularly important for changes of this breadth. So are the small, unglamorous decisions made years earlier, such as maintaining clean boundaries between components and having a build process that knows precisely what it ships. 

Those foundations are what make larger changes possible.  

“Technical debt compounds like financial debt. The cheapest upgrade is the one you never postponed.”  

What comes next  

No upgrade is a finish line. Each one is a step in a longer pattern: modernize continuously, in deliberate steps, so the platform never falls behind. Baselines will shift again. Vulnerabilities will land without warning. Each will meet the same discipline: the same tests, the same staged rollout, and the same evidence before we move forward. 

That discipline is what a product trusted to run every day, on every machine, without a second thought is actually made of.  

Malwarebytes for Windows on .NET 10 shipped in version 5.6.0. It is the latest step in a long-standing commitment to invest in the platform beneath the product so the protection on top of it can keep getting better. 

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review

Categories: Malware Bytes

Pages