Malware Bytes Security

Subscribe to Malware Bytes Security feed
Cyber Security Software & Anti-Malware
Updated: 22 min 53 sec ago

Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks

4 hours 57 min ago

Passkeys were supposed to make stolen passwords a thing of the past. No password to phish, no secret to reuse, and no string of characters sitting in a database waiting to be leaked.

Over time, it’s thought that passkeys will replace passwords entirely. But what happens when malware steals the master key?

Researchers have found a way for malware to hijack passkey-protected accounts through Google Password Manager, highlighting an important exception: passkeys can be very secure but the software surrounding them still has weaknesses.

What are passkeys?

Passkeys are a password replacement based on public‑key cryptography. Instead of a secret you remember and type, each account gets a key pair where the private key never leaves your devices, and the website only ever sees the public key and signed challenges. Because there’s nothing reusable to phish or reuse on another site, passkeys are marketed as “phishing‑resistant” and safer than passwords stored in a browser or password manager.

By the end of 2024 Google reportedly said that 800 million Google accounts used passkeys.

Passkeys have a major advantage over passwords: there is nothing useful for a phishing site to steal. A passkey is also tied to the website it was created for, making it much harder to trick into authenticating to the wrong domain.

The other significant difference is that if malware steals a password vault, an attacker still often needs to get past a second factor on another device, such as an authenticator app on your phone, before they fully own the account. With passkeys, many services relying on them simply trust the passkey assertion, and in some cases even trust a single “user verified” flag without confirming whether a real biometric or PIN event occurred.

Malware comes into play

The researchers, however, started with a malware infected Windows computer and came up with three possible attack scenarios to steal Google synchronized passkeys. Google Password Manager can synchronize passkeys between devices, which is convenient since you don’t want to register a new passkey every time you buy a new computer. But it also opens them up to abuse.

From bad to worse the attacks are:

  • Pass‑ta‑key: malware on the victim’s computer silently asks Chrome and Google’s cloud to create a valid passkey login, no biometric or PIN prompt needed.
  • Silver Pass‑ta‑key: malware abuses device re‑enrollment to register its own user‑verification key, then logs in as the victim from the attacker’s machine without touching the victim’s device.
  • Golden Pass‑ta‑key: Malware extracts Google’s security domain secret (the master encryption key), decrypts all synced passkeys, and can reuse them anywhere, even after losing access to the original device.
How to stay safe

The researchers urge services to stop blindly trusting the user verification flag and to properly validate that a real User Verified event occurred before granting access. Google, in turn, is encouraged to harden device registration and recovery, and verify that new devices and keys are backed by genuine hardware rather than accepting them at face value.

For end users, passkeys still offer strong protection against classic phishing websites and credential stuffing attacks based on reused passwords. The weak point highlighted here is not so much the concept of passkeys, but the way they’re implemented, synchronized, and trusted without enough verification on the server side.

Until vendors close these gaps, basic anti‑malware hygiene remains critical. The best ways to prevent malware from using your passkeys are:

  • Keep on top of updates: make sure your systems and software are patched as soon as you can.
  • Use up-to-date real-time anti-malware protection.
  • Treat unexpected attachments or links as suspicious until proven innocent.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Junk Cleaner clears the clutter from your Android 

7 hours 1 min ago

Your phone is full again, and the warning appears at exactly the wrong moment. Suddenly you can’t update apps, record a video, or save another photo.  

The cause is rarely one giant file. Storage disappears in a steady drizzle of leftovers: temporary files an app creates and forgets, caches that grow in the background, and downloads you no longer need. None of it is dangerous, but it can gradually fill your phone’s storage. 

Junk Cleaner is a new tool in Malwarebytes for Android, available from version 5.22. It finds that clutter, shows you what’s using space, and lets you decide what to remove. 

What Junk Cleaner finds 

Junk Cleaner looks for three broad categories of storage clutter: 

  • Leftover and residual files: Temporary and system-generated files that apps leave behind. 
  • Old and large downloads: Files you saved but no longer use or remember. 
  • (Coming soon) Hidden app caches: Storage used by apps in places Android keeps out of easy reach. 

A file showing up in one of these categories doesn’t mean it’s harmful. It just means it’s taking up space and might be worth removing. That distinction matters because Junk Cleaner is about storage, not threats. It works separately from Malwarebytes malware scanning and web protection, and it doesn’t touch your photos, messages, or documents. 

Scan, review, clean 

Junk Cleaner scans the relevant areas of your device in parallel, guided by a set of rules that can be updated as we learn about new kinds of leftover files. The results are grouped by category and show how much space each item is using. 

After the scan, you review the findings and choose what to clear. Nothing is deleted until you confirm the selection. The results are presented as a simple list showing each category and how much space you could recover. 

.kadence-column445671_58044d-dd{max-width:400px;margin-left:auto;margin-right:auto;}.wp-block-kadence-column.kb-section-dir-horizontal:not(.kb-section-md-dir-vertical)>.kt-inside-inner-col>.kadence-column445671_58044d-dd{-webkit-flex:0 1 400px;flex:0 1 400px;max-width:unset;margin-left:unset;margin-right:unset;}.kadence-column445671_58044d-dd > .kt-inside-inner-col,.kadence-column445671_58044d-dd > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-column445671_58044d-dd > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-column445671_58044d-dd > .kt-inside-inner-col{flex-direction:column;}.kadence-column445671_58044d-dd > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-column445671_58044d-dd > .kt-inside-inner-col:before{opacity:0.3;}.kadence-column445671_58044d-dd{position:relative;}@media all and (min-width: 1025px){.wp-block-kadence-column.kb-section-dir-horizontal>.kt-inside-inner-col>.kadence-column445671_58044d-dd{-webkit-flex:0 1 400px;flex:0 1 400px;max-width:unset;margin-left:unset;margin-right:unset;}}@media all and (max-width: 1024px){.kadence-column445671_58044d-dd > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}@media all and (max-width: 767px){.wp-block-kadence-column.kb-section-sm-dir-vertical:not(.kb-section-sm-dir-horizontal):not(.kb-section-sm-dir-specificity)>.kt-inside-inner-col>.kadence-column445671_58044d-dd{max-width:400px;-webkit-flex:1;flex:1;margin-left:auto;margin-right:auto;}.kadence-column445671_58044d-dd > .kt-inside-inner-col{flex-direction:column;justify-content:center;}} A quick look under the hood 

Junk Cleaner uses rules to identify patterns of clutter. These are not malware or phishing signatures. They describe file types and locations that may be worth reviewing when you need more space.  

The scanner checks the relevant directories, matches files against those rules, measures how much space each hidden cache occupies, and combines the results into a single review screen. 

Junk Cleaner automates a repetitive Android chore without turning storage cleanup into another complicated job. 

Built at a hackathon 

Junk Cleaner began as an internal hackathon project, an idea one engineer wanted to explore over a few focused days. The prototype proved useful enough to grow into a shipping feature, and reached all users in Malwarebytes for Android version 5.22. 

Turning the demo into a product meant more than polishing the screen. The team added Android permission handling, cache cleaning, and review experience needed for a feature people could rely on across different devices. 

We like that origin story because many useful features begin the same way: someone scratches an itch, builds something quickly, and turns a rough idea into a tool that can help millions of people. Future updates will bring smarter sorting, finer filters, and more control over what’s included. 

Make room for what matters 

Running out of space always seems to happen at the worst possible moment. Junk Cleaner clears away the leftovers that quietly build up, leaving more room for the photos, apps, and moments that actually matter. 

Junk Cleaner is available in Malwarebytes for Android from version 5.22. Open the app, run a scan, review the results, and reclaim your space in a few taps. 

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Apple battles it out again with the UK over encrypted iCloud access

Tue, 08/04/2026 - 4:30pm

The UK Home Office has once again demanded Apple allows it access to encrypted iCloud data.

The Guardian reports that the Home Office issued a Technical Capability Notice to Apple, this time targeting only British users. A Technical Capability Notice is a formal government order that compels tech and telecommunications companies to build or maintain specific technical functions—such as intercepting data or removing encryption protections—so law enforcement can access communications.

In the last round of this ongoing battle, the UK secretly ordered Apple to provide blanket access to protected iCloud backups around the world. Advanced Data Protection (ADP) is Apple’s opt‑in end‑to‑end encryption for iCloud backups, which even Apple itself cannot read. Apple argued that weakening or removing ADP would expose users to data breaches and other threats, and instead chose in January 2025 to withdraw ADP for UK customers rather than build a backdoor, while leaving it available elsewhere.

So, instead of working to keep citizens safe and secure, the Home Office just ended up removing an option for them.

Apple has responded by lodging a complaint with the Investigatory Powers Tribunal (IPT), seeking to challenge the scope and lawfulness of the government’s powers to issue such notices under the Investigatory Powers Act. The Tribunal is an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully.

Privacy International and Liberty have parallel complaints at the IPT challenging Technical Capability Notices more broadly, including their secrecy and necessity, and have asked for Apple’s claim to be heard in public given its wide public-interest implications.

I feel the fear of leaving an intentional backdoor is justified. If it exists, there is a chance that (AI-assisted) criminals will find and exploit it.

Weighing the importance of the right to privacy and the ability to investigate cases including terrorism and child sexual abuse is not easy. Apple’s ADP is used by many and as soon as criminals would know it’s no longer safe for them to use, they’d move to other platforms. Platforms where no legislative power will be able to gain access.

Reddit r/privacy users have been discussing alternatives for a year.

But, given the danger of a backdoor becoming available for criminals, we think in this case privacy should prevail. Let us know how you feel in the comments.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Categories: Malware Bytes

Travelers targeted when logging into hotel Wi-Fi networks

Tue, 08/04/2026 - 8:05am

Microsoft has warned that hotel, conference, and other hospitality Wi-Fi networks are being actively abused by a Russian group to target travelers worldwide. The campaign, dubbed “CaptiveCrunch” turns a routine Wi-Fi login moment into an opportunity to compromise corporate accounts and devices.

From the user’s perspective, nothing looks out of the ordinary: they connect to hotel Wi-Fi, get the usual captive portal prompt, and perhaps see a familiar‑looking message about needing to update something before they can browse. However, behind the scenes, the allegedly state-linked group position themselves in the network path and manipulate DNS (Domain Name System) and HTTP traffic from captive‑portal Wi-Fi.

From there, several things can happen:

  • Logins are stolen: The user’s browser session is redirected to attacker‑controlled phishing pages, like fake Microsoft login prompts, where credentials, device codes, or OAuth tokens are harvested.
  • Malware is downloaded: The user is presented with fake update or ClickFix dialogs that download malware. In these cases, usually a remote access trojan (RAT) plus an infostealer.
  • A machine-in-the-middle attack (MitM) where traffic is quietly proxied through attacker infrastructure, putting the user in a position for further credential theft.

Reportedly, one of the main malware strains used in these attacks is called CornFlake,  a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes.

The infostealer was identified as ChocoShell, a fileless Powershell-based information stealer which primarily goes after browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems.

Microsoft lists a set of fake dialogs that may appear once you connect to compromised Wi‑Fi:

  • winupdate: A bogus Windows Update window with “Working on updates… Don’t turn off your computer.”
  • defender: A fake Windows Security virus scan.
  • directx: “DirectX End‑User Runtime Web Installer.”
  • vcredist: A Microsoft Visual C++ redistributable installer.
  • sysopt: A disk optimization utility.
  • netfix: A Windows Network Diagnostics ‘fix’ tool.
  • browser: A browser update prompt.
  • pdfview: A document/PDF viewer installer.
How to stay safe

Malwarebytes has long warned about the safety of public Wi-Fi. Here’s how you can stay safe while traveling:

  • Use your own phone’s hotspot instead of using the public Wi‑Fi. A mobile connection, especially with an eSIM and a reputable carrier, significantly reduces the likelihood of an attack compared to an unknown hotel network.
  • If you’re forced to use public Wi‑Fi, use a VPN with an active Kill Switch: Complete the authentication on the hotel portal first, then launch your VPN before opening any website or app. The Kill Switch feature will instantly block all internet traffic if the VPN disconnects even for a second, preventing cybercriminals from injecting malicious code out in the open. While CaptiveCrunch operates around captive portals and pre‑VPN flows, a VPN still reduces other risks and limits passive data collection once you’re online.
  • Always inspect the certificate of any public Wi‑Fi login or ‘security’ portal that asks for more than a room number or basic credentials. These aren’t always a straight‑up giveaway, but sometimes they can be an obvious clue: mismatched hostnames, untrusted issuers, or plain HTTP are red flags that should stop you from proceeding.
  • Many captive portals ask for an email address for registration or marketing. Even in benign cases, there is little value in handing over your real inbox. If you must provide an address, consider giving a fake one or a throwaway alias that is unrelated to your primary accounts.
  • If you are asked to download software, a certificate, a browser update, or a fix tool in order to connect, stop. You should never have to download anything just to log into Wi‑Fi.
  • Don’t rush to follow instructions on a webpage or prompt, especially if it asks you to run commands on your device or copy-paste code. Be cautious of pages urging immediate action: sophisticated ClickFix pages add countdowns, user counters, or other pressure tactics to make you act quickly.
  • Secure your devices. Use an up-to-date, real-time anti-malware solution with a web protection component.
  • Avoid entering Microsoft 365, Google Workspace, or other high‑value credentials directly into any page reached via captive portal redirection. If you need to check corporate mail, follow known URLs rather than clicking through prompts.

And last but not least, update your browser, operating systems, and other important software before you travel. That reduces the chance of getting legitimate update requests while you’re away.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Online backlash ends in Google rolling back Google Earth AI tool after a day

Tue, 08/04/2026 - 7:35am

Google has walked back an AI feature that allowed users to generate artificial images inside Google Earth, after a predictable flurry of deepfakes.

Google switched on the AI image generation feature inside Google Earth’s web version on July 30. It was available to everyone.

The system used Google’s Nano Banana 2 image generator to create its images. That tool can already generate images from simple text input, but the advantage of doing it in Google Earth is that it can use the real satellite images as the basis for its deepfake versions. That makes it easier to make AI pictures with real, accurate building and landscape details.

In its initial blog post on the launch, it said that students could use it to “bring history to life”, while realtors could use it to produce professional real estate plans. However, others warned that the system could be used to mislead people.

Within hours, researchers and press outlets demonstrated that the tool would happily produce photorealistic satellite imagery of things that did not happen in places where they did not happen.

Dutch open source intelligence researcher Henk van Ess explained: “I tried refugees at the Mexican border, a nuclear plant in Iran, a crash in Amsterdam, a hospital with a bomb crater in Gaza. Nothing was refused”.

Demonstrating what was possible with the new capability, NPR fabricated an image of fires in Iran, along with a deepfake of Washington, D.C. underwater. The BBC ran images of a collapsed Eiffel Tower and the Great Pyramid of Giza swallowed by a sinkhole. Even though the service had some guardrails in place, the BBC’s anti-disinformation Verify service was able to circumvent them by tinkering with basic AI prompts.

Google acknowledged the failure in a statement on X:

“We’ve seen geospatial professionals using this feature for a range of useful purposes, however we’ve also seen people sharing screenshots of generated imagery that appear to violate our policies. So we’re rolling back this feature in Google Earth while we work on implementing stronger guardrails.”

It didn’t commit to never re-introducing the idea.

Users were apparently unimpressed. “There is 0 chance that no one on your development team didn’t raise exactly this concern,” commented one. “You guys are living in a complete bubble,” accused another.

Google’s fallback safeguard was a SynthID watermark and the fact that generated images didn’t appear in the main Google Earth experience for others to see. SynthID is Google DeepMind’s watermarking system, an invisible signal baked into the pixels of AI-generated images so that a compatible detector can spot them later. Google positions it as one half of its provenance stack, sitting alongside the C2PA metadata standard the wider AI industry has settled on.

On paper, the signal is meant to hold up through compression and even social media re-uploads. However, these claims collapsed on contact with reality. The watermarks are detectable by Google’s AI services like Gemini. They are not visible to users, who can screenshot the images and share them anywhere. It’s unlikely that everyone will know to check for the provenance of an image. Researchers have also reported that Gemini could not reliably identify AI-generated images with a SynthID watermark.

What this means for you

Content creators were already producing fake AI images showing events that didn’t happen. Traditionally, satellite imagery has been a key component of open source journalism. Fake it convincingly and you are attacking the reference layer reporters use to check whether something actually happened.

This also comes at a time when trust in AI is measurably eroding. According to our own research, released in June, 88% of people said it’s becoming harder to tell what content online is genuinely human or real, with 84% saying that even “convincing video evidence” no longer feels like proof. 

The practical advice is to take a breath whenever a disturbing satellite image of a disaster, a weapon strike, or a border crossing hits your timeline. Check whether a wire service with a named reporter has published it. Look for a caption identifying the imagery provider. If the source is an anonymous account posting a single dramatic frame, assume you might be looking at something assembled in a browser tab last night.

For more information on how to identify AI images, check out our guide.

The industry’s shipping model now apparently treats users as the test group. Critical media literacy is now the only reliable tool that readers and viewers have.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

WhatsApp account takeover scam asks you to “vote for my friend”

Tue, 08/04/2026 - 2:22am

A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely.

It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click.

We spotted the scam showing up in our anonymized Scam Guard submissions. WhatsApp is popular with cybercriminals, and the third most common channel where we see scams delivered, behind websites and email.

At first glance, nothing seems out of the ordinary. But the link doesn’t lead to a real voting page. Instead, it redirects to a page that appears to be related to WhatsApp, often involving the legitimate wa.me domain, where the real attack begins.

This scam works because it combines trust and curiosity. If the message comes from someone you know, you’re far less likely to question it and far more likely to follow through to do them a small favor.

In some versions of the scam, the link redirects you into a flow that abuses WhatsApp’s legitimate “Linked devices” feature.

Depending on your device, you may see what looks like a WhatsApp page prompting you to continue, verify, or connect. In some cases, the victim is guided through steps that resemble setting up WhatsApp Web or linking a new device.

The goal is to trick you into authorizing a new linked session that gives the attacker access to your WhatsApp account.

A typical flow looks like this:

  • You tap the “vote” link.
  • A page opens that appears to be related to WhatsApp.
  • You’re prompted to complete a connection or verification step.
  • That action links your WhatsApp account to a device controlled by the attacker.

Some versions of this scam take a less direct route. Instead of sending victims to a fake voting page, the message or the landing page instructs victims to open WhatsApp, go to “Connected Devices,” and enter a code supplied by the scammer.

These scammers aren’t trying to steal your password. Instead, they’re tricking you into giving them access to your account yourself.

How WhatsApp’s Linked devices feature works

WhatsApp allows you to use your account on multiple devices, including a web browser or desktop app, through its Linked devices feature.

Normally, this works by:

  • Opening WhatsApp on your phone.
  • Scanning a QR code displayed on another device.
  • Approving the connection.

Once linked, that secondary device can:

  • Read your messages.
  • Send messages as you.
  • Access your ongoing conversations in near real time.

But if you follow those steps, you could be giving an attacker access to your messages, contacts, and ongoing conversations.

This is a legitimate and widely used feature, especially for WhatsApp Web. But in this scam, attackers abuse it to gain the same level of access without your informed consent.

Once a scammer links their device to your WhatsApp account, they can continue accessing your conversations until that device is removed.

From there, they can:

  • Send messages pretending to be you, including forwarding the same scam to your contacts.
  • Ask friends or family for money or sensitive information.
  • Read your chats and harvest personal information.

Because this doesn’t involve a traditional login, there are no obvious signs like password reset emails or failed login alerts. The attacker’s device simply appears as another linked session on your account.

Unless you check your linked devices, the compromise can go unnoticed for quite some time.

How to stay safe

Scams like this rely on quick reactions and misplaced trust. A few simple precautions can make a big difference:

  • Be cautious with unexpected “vote” or “support” requests, even if they come from someone you know.
  • Don’t click unexpected links, especially if you’re immediately asked to verify, connect, or link your WhatsApp account.
  • Never follow instructions to link devices or scan QR codes unless you initiated the action yourself.
  • Regularly review your linked devices in WhatsApp (Settings > Linked devices) and log out of any you don’t recognize.

If you suspect your account has already been compromised, immediately log out of all linked devices and warn your contacts so they don’t fall for follow-up scams.

Indicators of Compromise (IOCs)

These domains are typically short-lived and quickly replaced. However, they may help you recognize similar scams if you encounter them:

ngdance[.]fun/vote
fokindenfo1[.]lol/home/voteeeg3
stardancer[.]fun/home/voteCZ03
thebestscollato[.]top/home/scolatica
vatiter[.]click/home/voteerok
megadencer[.]top/home/eng10

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

“Adult TikTok” searches lead to scams

Mon, 08/03/2026 - 5:35pm

Search for certain combinations of “TikTok” and adult content, and sooner or later you’ll land on a page promising exactly what you searched for: an endless feed of explicit clips, no signup required, just tap and watch.

There isn’t one.

On the other side of that click is an ad funnel dressed up as exclusive content.

These pages aren’t connected to TikTok itself. They simply exploit the platform’s name to attract search traffic. TikTok’s huge user base, and the number of people searching for adult content associated with the platform, make it an attractive lure both for advertisers and scammers.

What you need to know right away

Nothing on these pages is genuine content pulled from TikTok. Their entire business model is get you to click, sign up, or install something.

The operators don’t need to host any videos to make money. The promise of exclusive content is enough to generate clicks, signups, and downloads.

Although you’re probably not going to lose your life savings here, you could well end up on a spam list, installing an unwanted app, or paying for an “age verification” that doesn’t verify anything.

A pitch built around your search

These pages are designed to match exactly what you searched for. Many are built to rank for popular search terms in Google and other search engines, rather than relying on visitors coming from TikTok itself. They often acknowledge the frustrating hunt for working links before presenting themselves as the solution.

Below that, you’ll usually find a deliberately blurred video thumbnail, reassuring labels like “18+ only” and “HD clips,” and one or two buttons inviting you to Start watching or Sign up for free.

Mirroring the visitor’s own search behavior back at them is a common tactic in this category of ad-lure page. It’s designed to make the offer feel more relevant rather than generic.

What happens after you click varies from site to site, but you rarely get the content you were promised. Instead, you’re likely to be redirected through advertising networks, asked to hand over an email address or payment card for “age verification,” or prompted to install an app from outside the official app stores.

Each click or redirect can earn the site operator money through advertising or affiliate commissions, even if you never sign up or download anything.

Every step of the journey has value: A click can generate advertising revenue, a signup can earn an affiliate commission, and an email address can be sold or added to marketing lists. A payment card entered for “age verification” can lead to recurring subscription charges. Whether you ever see a video is irrelevant because the site has already achieved its goal.

Legitimate websites don’t normally need your payment card to prove you’re over 18. Fake “age verification” pages often use the process to collect card details, sign people up for recurring subscriptions, or both.

There’s no content, but there is a funnel

The blurred thumbnail is the entire “product.” It’s designed to look like a legitimate preview, suggesting there’s something just behind the next click, even though there usually isn’t. The site makes money from the clicks, signups, and downloads, not from any videos.

Depending on the page, the operator makes money in several ways:

  • Affiliate commissions. You click through to a dating site, adult subscription, VPN, app, or other offer. If you sign up, the site owner gets paid.
  • Advertising revenue. Every redirect, pop-up, or ad impression earns money.
  • Lead generation. Your email address is collected and sold or used for spam and phishing.
  • Subscription traps. “Age verification” asks for a payment card, then quietly enrolls you in a recurring subscription.
  • Potential malware. Some pages push unwanted software or even malware outside official app stores.
Why this lure works

Adult content lures carry a built-in advantage most scams don’t have: embarrassment. People are less likely to mention it to a friend, ask for a second opinion, or report it, which means fewer eyes catch the scam before it spreads further.

What to do
  • Close the tab. There isn’t any exclusive TikTok content waiting behind Start watching.
  • Don’t enter your email address, payment card, or date of birth to verify access. It isn’t verifying anything, it’s collecting data.
  • Don’t install anything you were prompted to download from a page like this.
  • If you’ve already entered information, treat it as exposed. Watch for follow-up spam or phishing emails, and change any passwords you may have reused.

Adult-content lures are one of the oldest tricks in malvertising. Using TikTok’s name just makes them feel more relevant to today’s searches.

Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

The AI Act kicks into action, forces companies to be clear about AI chatbots

Mon, 08/03/2026 - 5:08pm

The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing Artificial Intelligence (AI) systems.

From August 2, what you’ll likely notice are more “this is AI” labels, clearer rules for powerful foundation models, and new ways for users and researchers to complain when systems go off the rails.

The AI Act moved from theory to practice for three big areas:

  • General‑purpose AI (GPAI) models: The new AI Office in Brussels, together with national regulators, can now enforce rules on providers of general‑purpose AI models (think large language models and other foundation models behind many tools).
  • Transparency obligations: Transparency rules kick in for interactive systems and AI‑generated content: chatbots must say they are bots, and synthetic audio, images, video and text need to be marked as AI‑generated or manipulated.
  • Banned AI uses: A set of “unacceptable risk” AI uses is now formally prohibited, with enforcement shared between the AI Office, national authorities and the European Data Protection Supervisor for EU institutions.

Note that content that was generated and published before August 2, doesn’t need to be retro‑labelled, but anything published on or after that date falls under the rules, even if it was generated earlier.

From a security perspective, the AI Act’s transparency push is less about banning AI and more about taking away its best camouflage: pretending to be human.

Non‑compliance with transparency obligations can attract fines up to 15 million Euros (17.3 million USD) or 3% of worldwide annual turnover, whichever is higher, which should be significant enough to get large providers’ attention.

To make enforcement more than a paper tiger, the AI Office has launched tools aimed at people who see problems from the inside or as users:

  • Complaint tool: Individuals and organizations can report alleged infringements of the AI Act by providers or deployers of AI systems supervised by the AI Office.
  • Whistleblower tool: People professionally connected to AI providers or deployers get an anonymous channel to flag potential violations that could endanger fundamental rights, health or public trust.
  • Downstream complaints channel: Firms building on top of GPAI models can report suspected breaches by the underlying model providers.

This creates a formal path for reporting systemic issues: think unsafe model behavior, ignored red‑team findings, or deployments that quietly cross legal lines around manipulation or discrimination.

Bans on “nudifiers” and abusive content

The AI Office has introduced explicit prohibitions on AI systems that generate non‑consensual sexually explicit or intimate content (including “nudifier” apps) and child sexual abuse material.

For victims of these abuses, that’s more than a symbolic move. It gives regulators and law enforcement a clear legal basis to go after both providers and deployers of such systems in the EU, rather than trying to squeeze them into older, less specific laws.

These rules will apply from December 2, 2026, with companies given time to bring their systems into compliance or pull them from the EU market.

Regrettably, this will not stop abuse completely. Attackers will still use unlabeled tools and infrastructure outside the EU. But it raises the bar for legitimate services and makes it harder for mainstream platforms to ignore the risks of deceptive AI‑driven features.

The AI Act won’t make AI safe overnight, but it shifts the default from “anything goes” to “you must play by some basic rules if you operate in the EU.” For users, that’s a step toward AI systems you can at least recognize and question, instead of having invisible technology quietly shape our online experience.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

Californians can tell data brokers to DROP their information

Mon, 08/03/2026 - 4:50pm

California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place.

DROP was created under California’s Delete Act, which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry.

Data brokers collect and sell extensive personal information, including financial details, online behaviors, and location data. This data is often gathered without explicit consent, raising concerns about privacy and transparency.

DROP is a state service that sends a standardized deletion/opt‑out request to all data brokers registered with the California Privacy Protection Agency. Starting August 1, 2026, registered data brokers in California are required to access DROP and have 90 days to delete a person’s records after a request.

How to use DROP

You’ll need to provide at least one reachable email address and/or mobile phone to verify your identity and track the request. Be ready to provide basic personal data (name, address, contact details) that brokers are likely to have and that DROP uses to match your records.

  • Go to the DROP portal.
  • Use the “Get Started” button on the homepage.
  • Accept the terms and conditions presented by the platform by using the “I accept” button.
  • You’ll need to verify that you are a California resident: you can either input your personal information manually, or authenticate via Login.gov, which allows identity verification through a federal login. If you receive the message “Unable to verify” your status as a California resident, click the link on screen to “Request a review of your eligibility.”
  • After residency verification, create a deletion request:
    • Provide your email address and/or phone number to verify contact details.
    • Fill in basic information (name, address, etc.) so brokers can locate your records.
  • Submit your request through DROP and you’ll receive a DROP ID that lets you track the status of your request online. Store that number somewhere.

Now, it’s up to the data brokers. They now have 90 days to delete your records and comply with opt‑out obligations. If you run into a problem there is a dedicated help site.

For non-Californians

Some other states—like Oregon, Texas, and Vermont—also require data broker registration, though only California currently offers a centralized platform like DROP. If you live in such a state, check your attorney general’s website or privacy office for a “data broker registry” or opt‑out guidance, and follow their listed processes to submit requests directly to each broker.

Even without DROP, US residents can still reduce data broker collection and sale of their data, but it requires more manual work. Where no centralized government tool exists, you can identify brokers by searching for “data broker opt‑out” and review lists from privacy advocacy groups.

For each broker you’ll have to submit individual requests:

  • Use their web forms, email addresses, or postal addresses to request:
    • Deletion of your data, and
    • Opt‑out from sale or sharing of your data.

You’ll need to provide enough information to match your record (e.g., name, address, email, phone) but avoid oversharing additional sensitive data.

It’s advisable to maintain a spreadsheet with dates, brokers, and confirmations. Most privacy laws specify response deadlines, often 30–45 days, though this varies by state.

Sounds like a lot of work? Malwarebytes Personal Data Remover can help.

How to reduce future data broker collection

This is probably the only field where “security by obscurity” works.

Use multiple email addresses where you reserve one for financial/critical accounts and use aliases or disposable emails for newsletters, shopping, and registrations, making it harder for brokers to build a unified profile.

A VPN encrypts your traffic and hides your IP address, reducing the ability of websites and analytics firms to link activity to a stable, location‑based identifier.

For non‑critical services, avoid providing full legal names, exact home addresses, or phone numbers if they’re not strictly necessary. This is especially true for rewards and loyalty programs.

Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

SCAN NOW

Categories: Malware Bytes

Fake Fortnite rewards are stealing players’ accounts

Fri, 07/31/2026 - 12:16pm

Fortnite scam pages like the ones below appear by the dozen every day, recycled endlessly under different names and designs.

One version promises $50 from a fake superhero collaboration. Another claims it can calculate what your locker is worth. Both lead to the same destination: a fake Epic Games login page designed to steal your account. It’s an old trick, but it still catches people out.

The short version

If a website promises free V-Bucks, cash, or a tool to calculate your locker’s value, then asks you to log in with your Epic account to get it, it’s not run by Epic.

Epic doesn’t offer an official tool that values accounts, and no legitimate giveaway requires you to sign in through a third-party site. You’re just handing your Epic username and password to scammers.

If you or your child entered your Epic login details on one of these sites, assume the account has been compromised. Change the password immediately, turn on two-factor authentication, and don’t reuse that password on any other accounts.

Why do they want your login?

A stolen Fortnite account can be worth real money. Criminals can take over accounts with rare skins, spend any saved payment methods, sell the account on underground marketplaces, or use it to scam the owner’s friends. They may also try the same username and password on other online accounts, hoping the password has been reused.

Why Fortnite?

Fortnite still attracts around 110 million monthly players and has more than 650 million registered accounts. That alone makes it an attractive target for cybercriminals.

The audience’s age matters too. In December 2022, the US Federal Trade Commission (FTC) fined Epic Games a record $520 million, after alleging that the company knew children made up a substantial share of its player base and left voice and text chat turned on by default, exposing them to strangers. The Consumer Financial Protection Bureau (CFPB) also cites industry experts who say young gamers are especially vulnerable to phishing because they spend more time on social media and are less familiar with social engineering.

The game is also built around visible status. Skins, emotes, and pickaxes cost real money, making the idea that “your locker has a price” feel plausible. Rare or discontinued skins really do sell for hundreds of dollars on unofficial marketplaces, even though Epic offers no official way to cash out V-Bucks and selling accounts violates its terms of service. That kernel of truth is exactly what these locker-value scams exploit.

That’s also what makes them more convincing than a simple V-Bucks giveaway. Instead of promising something for nothing, they play on curiosity about something the player already owns. That’s probably why this version keeps coming back.

How the scam works

Some pages promise rewards:

Others skip the free-reward pitch and frame the locker itself as hidden value the player is owed:

Others frame it as competition instead of currency:

The hook changes, but the fake login page doesn’t. These sites all do the same thing. They ask you to sign in with your Epic account so they can steal your username and password.

Another variant: Fake settlement claims

This one borrows a real story. Epic did settle with the FTC for $520 million, and real payments are still going out in 2026. But the real settlement pays actual dollars through the FTC’s own process, not in-game V-Bucks through an “Epic Games Locker,” and the claim window closed in July 2025.

References to an “EU Regulatory Mandate” and the case number shown on these pages don’t match any genuine legal action.

How to stay safe

Fortnite scams change constantly, but the advice doesn’t.

  • Use Malwarebytes Browser Guard to block known phishing sites before they have a chance to steal your login details.
  • Only sign in to your Epic account at epicgames.com. If another website asks for your Epic login, leave.
  • Be sceptical of offers that sound too good to be true. Free V-Bucks, locker valuations, and surprise rewards are all common phishing lures.
  • Verify refunds and settlements on the official source. If a page claims you’re owed money, check the regulator’s website yourself instead of following its links.
  • Turn on two-factor authentication (2FA). It can stop attackers from accessing your account even if they steal your password.
  • Use Malwarebytes Scam Guard. It can help you identify suspicious links and messages before you click.
What to do if you clicked
  • Change the Epic password immediately, going directly to epicgames.com, not through the suspicious link.
  • Turn on two-factor authentication if you haven’t already.
  • Check your linked email for password reset requests or login alerts you didn’t make.
  • Review connected devices/services on the account and remove anything unfamiliar.
  • If you entered payment details anywhere, contact your card issuer and monitor your statements.
  • Report the page to Epic’s support and flag it as phishing in your browser.
  • If the page claims to be part of a settlement or refund, verify it on the regulator’s official website. For the Epic settlement, that’s ftc.gov.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Fake Flash Player installs AtlasRAT

Fri, 07/31/2026 - 7:03am

Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer.

People still go looking for “Flash player” because a surprising amount of content and software was built around Flash and never properly migrated. Users often just want a quick way to get those old sites, games, or business apps working again.

The underlying problem is that Adobe ended support for Flash Player on December 31, 2020, and actively blocks Flash content from running in the official player.

Attackers know some people will still search for Flash to run a game or a business app, so they wrap their malware in a fake Flash‑related installer that looks familiar and legitimate.

That’s likely why the AtlasRAT infection chain starts with a Delphi executable named FlashPlay.Exe, masquerading as an “AGE Flash Player” installer. The first-stage loader runs entirely in memory and reconstructs additional payloads instead of dropping obvious files to disk, a technique often referred to as fileless malware.

The final payload (MainDll.Dll) uses a self‑signed certificate spoofing CN=update.Microsoft.Com to initialize Transport Layer Security (TLS) client communication and encrypts Command and Control (C2) traffic.

A self‑signed certificate means the owner signs with their own key instead of a trusted certificate authority (CA). That means an attacker can create a certificate claiming to be update.microsoft.com or google.com, even though they don’t control those domains. A web browser would reject such a certificate with a warning. Custom malware, however, can simply ignore the operating system’s trust checks and use it to set up encrypted C2.

Once AtlasRAT is installed, the operator gains long‑term remote control of the infected Windows system with capabilities including:

  • Collecting credentials via offline keylogging
  • Gathering system information and identifying installed security products
  • Exfiltrating data over encrypted channels
  • Injecting DLLs into applications like WeChat, potentially allowing the attacker to monitor or manipulate messaging, or to hide malware activity or connectivity.

Based on historical data, the researchers suspect that AtlasRAT is a reusable framework or commercial offering rather than a one-off tool used by a single group.

How to stay safe

When looking for apps and software to perform a specific task, remember that cybercriminals often exploit popular searches in semi-targeted attacks. In previous campaigns, for example, AtlasRAT has also been distributed as a fake VPN installer.

Some tips to keep this RAT, and others, off your computer:

  • Carefully check what you’re about to install. Sponsored search results are not a guarantee that software is legitimate.
  • Use an up-to-date, real-time anti-malware solution to detect and block remote access Trojans. Malwarebytes detected AtlasRAT as Malware.AI.1710771908
  • Keep your operating system, browser, and security software up to date.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Malwarebytes for Windows, now available on the Microsoft Store 

Thu, 07/30/2026 - 12:01pm

When you’re setting up a new PC or looking for an app you already know, the Microsoft Store is often the easiest place to start. It’s built into Windows and lets you find, install, and update apps in one place. Malwarebytes for Windows is now available there too. 

Malwarebytes for Windows is still available from our website and trusted partners. The Microsoft Store simply gives you another trusted way to get it. 

If you’ve ever helped someone set up a new PC over the phone, you’ll know how much simpler it is to say, “Open the Microsoft Store, search for Malwarebytes, and click Get.” There are no web addresses to type, and no worrying whether you’ve landed on the right download page.  

That’s important because cybercriminals use fake download pages and bogus security software to trick people into installing malware instead of the product they intended to download. Searching for Malwarebytes in the Microsoft Store gives you another straightforward way to make sure you are installing the genuine app. 

The same Malwarebytes, now in the Microsoft Store 

Installing Malwarebytes from the Microsoft Store gives you the same Malwarebytes for Windows you know and love, not a limited Store edition. 

Some desktop apps available through app stores have fewer features or capabilities than versions downloaded directly from the developer. Malwarebytes is not one of them. You get the same real-time protection, the same Windows integration, and the same features. The Microsoft Store changes where the installation begins, not what the product can do. 

That’s especially important for security software. Malwarebytes needs to run continuously in the background and work closely with Windows to help protect your PC. The Microsoft Store version isn’t a scanner-only companion app or a browser shortcut; it’s the full Malwarebytes for Windows. 

No compromises. No missing features.  

  • The full Malwarebytes. You get the complete app, not a limited Store edition.  
  • The same protection. Real-time security and all the features you’d expect.  
  • Your choice of subscription. You’re not locked into Microsoft Store-only billing.  
  • Automatic updates. Malwarebytes continues to update seamlessly, just as it always has. 

The Microsoft Store listing also gives you app information, screenshots, and another trusted place to install Malwarebytes. 

Already using Malwarebytes from our website? There’s nothing to reinstall or change. You’re already protected. 

How to get it 

Open the Microsoft Store from the Start menu or taskbar, search for Malwarebytes, and click Get. Windows handles the installation. Once it’s installed, Malwarebytes will open, ready for you to get started.  

Malwarebytes for Windows is available on the Microsoft Store now. Whether you install it from the Store, malwarebytes.com, or a trusted partner, you’ll get the same Malwarebytes protection for your Windows PC. 

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Hims & Hers sued over alleged health data privacy failures

Thu, 07/30/2026 - 9:58am

The US Federal Trade Commission (FTC), together with Utah and California, has filed a lawsuit against telehealth provider Hims & Hers.

The FTC alleges that the company shared consumers’ sensitive health information with third‑party advertising platforms despite promising strong privacy protections.

Hims & Hers is a telehealth and digital health platform that connects users with licensed medical providers for online consultations, prescription medications, and personal care products.

The complaint also accuses Hims & Hers of deceptive billing and subscription practices that made it hard for users to avoid charges or cancel subscriptions.

According to the FTC’s complaint, filed in federal court in California, Hims & Hers:

  • Shared sensitive health data, including details about medical conditions, with ad platforms such as Meta and Snap despite privacy promises.
  • Charged before consultations. The company promised users they could consult a medical provider before being charged, but the FTC says many consumers were enrolled in recurring prescription subscriptions shortly after they submitted an intake form, often without first having a consultation.
  • Made cancellation difficult. Before 2023, cancellation reportedly required contacting customer service by phone, email, or chat. Even after an online cancellation option appeared, the FTC alleges the button was hidden behind multiple steps and confusing options.

From a cybersecurity and privacy research perspective, this isn’t just about a single telehealth brand. It highlights three broader trends we see repeatedly in consumer programs:

Privacy policies versus reality. A company can market itself as privacy‑focused while still integrating third‑party advertising and analytics software development kits (SDKs) that leak sensitive information. This becomes especially concerning when health‑related events are linked to user accounts or tracking cookies.

Friction as a feature. Hard‑to‑find cancellation flows and unclear billing practices are examples of “dark patterns” that nudge users into paying for services they might not have chosen given all relevant information.

Regulatory pressure is growing. Health‑related services are under increasing scrutiny, especially when they handle sensitive data and combine it with advertising platforms.

The court will ultimately decide whether Hims & Hers violated the law, but the FTC’s action sends a clear signal: regulators are paying close attention to how health‑related services collect, use, and share sensitive data.

For anyone who values online privacy, the Hims & Hers case is a reminder that “health tech” does not automatically mean “privacy first.”

How to stay safe

More often than not, the privacy loopholes are hidden in the privacy policy somewhere.

Pro tip: one thing AI is good at is reading between the lines. Ask an AI chatbot to summarize a privacy policy and identify when your information may be shared with third parties. AI makes it much easier to understand lengthy privacy policies without reading every word yourself. If companies fail to follow their own privacy policies, regulators and consumers can hold them accountable.

Other than that:

  • Don’t share sensitive information unless it’s genuinely needed to provide the service.
  • Use strong, unique passwords and multifactor authentication (MFA). Even if a company is compliant, breaches happen. Unique passwords and two‑factor authentication limit the damage if your account details are exposed.
  • Check your browser and app permissions. Disable unnecessary tracking features where possible, and consider privacy‑focused browser settings or extensions that limit third‑party cookies and trackers.

Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

SCAN NOW

Categories: Malware Bytes

Hidden prompt turns Microsoft Copilot into an AI worm

Thu, 07/30/2026 - 8:58am

A security researcher has demonstrated how Microsoft Copilot for Word can be tricked into spreading a self‑propagating prompt‑injection “AI worm.” The attack silently alters documents and embeds its own hidden instructions into newly created files, allowing it to spread through normal document-sharing workflows without macros or traditional malware.

The technique allows an attacker to hide a JSON‑formatted prompt as white text on a white background inside a Word document. When someone asks Copilot for Word to draft or edit content based on that document, Copilot strips away the formatting, reads the hidden text, and treats the embedded instructions as part of the user’s request.

Copilot then modifies the active document and appends the full malicious prompt as hidden white text. That new document becomes a new carrier. Anyone who later uses it as source material for Copilot triggers the same behavior, allowing the prompt injection to spread to more documents. Because the documents are created and edited by legitimate users, the attack can be difficult to trace.

The researcher could still reproduce the full worm chain even after Microsoft rolled out multiple mitigations, including upgrades to newer GPT‑5.5 and 5.6 models.

At the time of writing, there is no complete mitigation for this broader class of attacks across comparable large language model (LLM)‑based products. It’s characterized as an architectural weakness of current LLM systems: attacker‑controlled content shares the same context window as trusted instructions. Attacks that exploit this behavior are known as prompt injection attacks and may never be fixed.

How to stay safe

Treat documents from outside your organization as untrusted, especially if you plan to use them with Copilot for Word.

Review any attached document before using it as Copilot source material, and carefully verify Copilot‑generated/edited documents before sharing or reusing them.

If you don’t use Copilot, you can disable it.

Malwarebytes users can turn off Copilot under Tools > System Tweaks > Miscellaneous.

Malwarebytes setting to disable Copilot

Or in Word itself:

For individual users who don’t want Copilot in Word:

  • Open Word, go to File > Options > Copilot and clear the Enable Copilot checkbox, then restart Word.
  • In some versions of Word, the setting appears under File > Options > General in a Copilot section. In both cases, the key is unchecking the “Enable Copilot” setting.

You can also remove the Copilot icon from the ribbon by right‑clicking the ribbon, open the customization dialog, locate the Copilot/Assistance button, and removing it.

Alternatively, you can limit Copilot’s role by following these instructions:

  • In Word, go to File > Account > Account Privacy > Manage Settings, and uncheck Turn on optional connected experiences. This reduces certain cloud‑powered AI features, including Copilot‑related functions that rely on those services.
  • In the Microsoft 365 Admin Center, under Copilot > Settings, set Pin Microsoft 365 Copilot Chat to Do not pin Copilot chat in Microsoft 365 apps so the chat pane doesn’t appear by default in apps like Word.

This doesn’t remove Copilot entirely or stop these attacks, but it does reduce its visibility and limits some of its cloud‑assisted functionality.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

Apple accused of letting fake crypto app steal $1.8 million

Wed, 07/29/2026 - 6:30pm

Apple’s tagline for its App Store says, “The apps you love. From a place you can trust.” You might love the apps, but can you trust the store? A federal lawsuit filed in the Northern District of California last week suggests not.

Three people have accused Apple of promoting a fake version of the Sparrow Wallet cryptocurrency app through its App Store, even though the real app’s developer had spent over a year telling Apple that he hadn’t produced a version for the mobile platform.

The fake app drained a combined $1.8 million from the victims’ wallets between May and August 2025, and now they’re furious with Apple for allowing it to happen.

How the scam worked

According to the legal complaint published courtesy of BleepingComputer, James Ramirez, Christopher Ellis, and Jalen Delgado downloaded a fake version of Sparrow Wallet from Apple’s App Store. It asked users to enter their recovery phrase (the 12 or 24 words that restore access to a crypto wallet), which is something a legitimate wallet app may also ask for during setup.

Instead of keeping that information private, though, the app handed it to the criminals running the scam. Once someone else has your recovery phrase, they have access to your wallet. If they transfer your cryptocurrency to another address, you cannot get it back.

Ramirez, Ellis, and Delgado say they lost approximately $875,000, $840,000, and $120,000 in Bitcoin, respectively.

Apple terminated the legit developer’s account

The real Sparrow Wallet is a desktop application for Windows, macOS, and Linux. It has never had an official iPhone app.

Craig Raw, the developer of the actual Sparrow Wallet, reported fake versions to Apple in the weeks leading up to January 2024 and publicly confirmed that month that the fake app was still live despite repeated reports.

About a year later, he tried a workaround to stop people from downloading the fake app by submitting a placeholder iOS app with screenshots explicitly warning users that Sparrow Wallet was not available on iOS. Apple responded by terminating his developer account. Thankfully it reversed it later, otherwise he would have been unable to maintain the macOS version.

The complaint also alleges that Apple featured the fake app in curated cryptocurrency collections alongside legitimate products, and allowed additional fake Sparrow Wallet apps onto the App Store even after consumers complained.

Apple’s official response, per TechCrunch, is that:

“apps impersonating others are a violation of its guidelines and it takes swift action to remove them.” Not swift enough, apparently.

The three users are now suing Apple, alleging that it misrepresented the App Store as trustworthy despite knowing about the fake apps. The complaint includes claims of fraudulent concealment, among others, and seeks a jury trial. The plaintiffs are seeking compensation for their losses, along with additional damages permitted under California law.

Not a one-off

Fake cryptocurrency apps are a trend. Kaspersky researchers recently identified 26 crypto wallet impersonators inside Apple’s ecosystem, all targeting seed phrases and recovery keys.

Rather than including malicious code directly inside the app, many of these scams direct users to a convincing fake App Store webpage, where they’re prompted to install another version of the app. That malicious version steals cryptocurrency recovery phrases or private keys by abusing enterprise distribution certificates intended for internal company apps.

How to stay safe

Apple points to its enforcement volume: it terminated 193,000 developer accounts and rejected more than 371,000 copycat submissions in 2025. Those figures come from Apple itself, with no mention of an independent audit. The company says that it uses a mixture of human review and machine learning to spot malicious apps.

If you use cryptocurrency on an iPhone, don’t assume that an App Store listing guarantees an app is genuine. Download apps using links from the developer’s official website whenever possible, and check that the developer actually offers an iPhone version before installing it.

The App Store is generally safer than downloading apps from elsewhere, but this case is a reminder that it is not infallible.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

Buying TikTok views or followers? Here’s what you’re really getting

Wed, 07/29/2026 - 12:54pm

A whole industry has sprung up around selling TikTok “growth.”

Cheap views by the hundred, pre-made ad accounts, and polished sales pages promising a repeatable path to serious revenue.

None of it is officially sanctioned by TikTok, and depending on what you’re buying, you could end up wasting money, losing your account, or handing your login details to scammers.

Scam 1: Sites selling cheap likes and engagement

Sites selling bulk engagement all look remarkably similar.

They offer small bundles of views, likes, or followers for a few pounds, usually alongside identical packages for YouTube, Instagram, and other platforms.

The sales pitch is almost always the same: “100% real profiles,” “no bots, no click farms,” and “completely safe.”

Those claims are worth reading carefully because they’re addressing the biggest concern buyers already have.

At this price point, bulk engagement is usually generated through bots, click farms, or other artificial means—the very thing these sites insist they don’t use.

Even if your engagement numbers increase initially, TikTok’s fraud detection systems can remove artificial engagement, and accounts that repeatedly use these services risk being flagged or restricted.

Scam 2: The “aged” ad account marketplace

Another common offer is bulk TikTok Ads accounts sold as “aged” or “trusted,” often bundled with a replacement guarantee if an account stops working. The pitch is that you skip the hassle of setting up and verifying a new advertising account.

The problem is that you don’t know how those accounts were created. Many are built using stolen or synthetic identities, compromised payment details, or other deceptive methods. Buying one means inheriting that history—and the very real risk that TikTok detects it and suspends the account, along with any campaigns or ad budget attached to it. A replacement guarantee won’t help if your advertising is suddenly brought to a halt.

Scam 3: The growth framework

A third type of offer is less obviously a scam and more of a marketing funnel.

Slick landing pages—often hosted on free platforms and paired with an embedded video—promise a “proven blueprint” for turning TikTok into a major source of income, usually backed by impressive but unverifiable claims about past clients.

The immediate goal is usually to collect your email address, and sometimes your phone number, before revealing what’s actually for sale. That might be a paid course, a “done-for-you” management service, or a request for direct access to your TikTok Shop or Ads account.

What happens next varies, but the common thread is the same: you’re being asked to trust an unverified third party with your business, your money, or your account.

What you’re really signing up for

Not every TikTok marketing service is a scam. But if someone’s offering thousands of views for a few pounds, bulk “aged” ad accounts, or guaranteed growth, you’re in a very different part of the market.

These services promise shortcuts. What they often deliver is fake engagement, accounts with questionable histories, or requests for access to your own account.

At best, you’ve wasted your money on engagement TikTok later strips away. At worst, you’re buying an account built on stolen information or giving an untrusted third party full access to your own.

Our advice
  • Don’t pay for views, likes, or followers. Artificial engagement isn’t real growth and can put your account at risk under TikTok’s rules.
  • Never share your TikTok username and password with a “boosting” service, regardless of how it’s presented.
  • Don’t buy or sell TikTok Ads or Business accounts outside TikTok’s own account creation process.
  • Treat “guaranteed revenue” frameworks and courses like any other business opportunity: they’re sales pages first, educational content second.

None of this is unique to TikTok. The platform’s explosive growth has simply given a familiar ecosystem of low-effort scams a new audience.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Categories: Malware Bytes

AI robocalls: Why caller ID is still lying to you

Wed, 07/29/2026 - 11:15am

If you feel like your phone has turned into a scam megaphone, you’re not alone. Robocalls have been a problem for years. Artificial intelligence (AI) is making them slicker, faster, and harder to spot.

A new investigation by Transaction Network Services (TNS) shows that while the big telecom players have stepped up caller ID authentication, many smaller providers are still lagging behind. That leaves plenty of room for criminals to keep making spoofed, AI‑voiced robocalls that seem legitimate right up until they empty your bank account.

Turning back the clock to 2019, lawmakers in the US passed the TRACED Act with a simple goal: make it harder for scammers to lie about who’s calling. The technical was solution STIR/SHAKEN, a pair of catchily-named standards that let phone networks cryptographically sign calls so downstream providers can check whether the caller ID is trustworthy.

On paper, it’s working fairly well for the major carriers. TNS reports that about 85% of voice traffic between Tier 1 networks in 2025 was signed using STIR/SHAKEN, and 93% of those calls received the highest “A” attestation. If the entire ecosystem looked like that, spoofing would become much harder.

Why spoofing still works

The same report found that most lower‑tier communications service providers—typically smaller or specialist carriers—aren’t even close to that level of protection. On average, they only use the required cryptographic signatures about 20% of the time. That means four out of five calls effectively go through the network “unsigned.”

There are reasons for this. The Federal Communications Commission (FCC) has granted some providers extensions, particularly very small and satellite providers, as long as they implement other robocall mitigation measures. Even so, the result is uneven implementation.

From a scammer’s point of view, this is great. Cybercriminals are already using AI to run increasingly sophisticated and scalable robocall attacks and know that even calls with strong authentication can be spoofed or abused when other parts of the chain are weak.

AI voice cloning can be done with just a few seconds of original audio. Combine that with call spoofing and personal information gathered from data breaches, and scammers can make a call appear to come from your bank while using a calm, familiar voice that knows your name or other personal details.

Robocalls cost almost nothing to send. Internet calling allows scammers to dial thousands of numbers for a few cents, which is why the volume is so high. Industry estimates suggest US consumers received around 55 billion robocalls in 2025, with projections creeping toward 60 billion in 2026. That’s roughly 160 million spam calls every single day in one country. Globally, that’s about 385 billion spam/robocall calls each year.

How to stay safe

What can you realistically do as a consumer, given that the network itself is still in transition and attackers are upgrading faster than some carriers?

A few habits still go a long way:

  • Be skeptical of urgency. Real organizations rarely need you to make immediate decisions over the phone about payments, credentials, or remote access. Hang up and call back via a number you find on their official website.
  • Treat caller ID as a clue, not proof. Even if the number looks familiar or matches what you see on a card or website, it can be spoofed.
  • Don’t press buttons or follow instructions in automated menus you didn’t expect. Many robocalls use “press 1 to speak to an agent” as the gateway into a full social‑engineering script.
  • Use call‑blocking and screening tools. Your phone, carrier, or security app may already offer options to block known spam numbers, send unknown callers to voicemail, or label suspicious calls.

And finally—and this is where we can help—check suspicious numbers with our Scam Number Check before you answer or call back.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

Categories: Malware Bytes

OpenAI explains how its AI agent breached Hugging Face

Wed, 07/29/2026 - 10:20am

On July 28, OpenAI published an update on the agent that escaped its sandbox and hacked into Hugging Face during an internal cybersecurity evaluation.

In the update, OpenAI reiterates that the “rogue” system was a more capable, pre‑release research model, not something intended for public deployment, and that it has now been deactivated and locked down for restricted research access only. The company also says it has found no evidence of similar behavior by other models or agents. Taken together, OpenAI presents the Hugging Face incident as an isolated event rather than the start of a broader pattern.

From a security standpoint, four things in the update stand out:

  • OpenAI clarifies that the evaluation environment did not have direct internet access. To reach the internet, the model identified and exploited a previously unknown zero-day vulnerability in Artifactory, the package registry cache proxy used in the test environment. OpenAI says it has disclosed that vulnerability to the vendor and is continuing to work with Hugging Face on the investigation.
  • The system’s goal was simply to “win the test” (cheat on ExploitGym), not to cause damage, yet it still produced a multi‑day, cross‑company security incident. Benign intent did not limit the impact.
  • “Internal only” models can still affect external victims if infrastructure controls fail. A lab environment does not magically contain cyber‑capable systems.
  • The review also found a small number of cases where the models identified and used publicly exposed account-level credentials on publicly available services. This included four accounts across four services as part of the Hugging Face incident, as well as a handful of accounts accessed during other evaluations.

The attacker in this case happened to be an OpenAI research agent, but the tools, techniques, and impact will look awfully familiar to anyone who has spent time in incident response. Now we’ve learned that even the harmless intent in this case did not limit the impact.

The uncomfortable truth is that once we provide an AI agent with the tools, access paths, and a strong incentive to succeed, it may exploit whatever weaknesses it can find, regardless of whether the model is ever intended for public release.

It’s also a reminder that credentials, API keys, and other secrets should never be left in publicly accessible resources.

From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Categories: Malware Bytes

We found 120 fake Walmart stores trying to steal your credit card

Wed, 07/29/2026 - 6:32am

Shoppers browsing on their phones are landing on convincing Walmart lookalike sites offering name-brand liquor at 40% to 70% off, only to be led straight to a checkout page asking for a full credit card number, expiry date, and CVV.

The sites have no connection to Walmart. They’re part of a network of more than 120 near-identical domains built to look like a legitimate retailer just long enough to steal your card details.

Fake Walmart websites

The name “Walmart” is doing most of the work here. It’s one of the most recognized retailers in the world, and it’s that familiarity that makes people lower their guard. A shopper who’d hesitate on an unfamiliar website may think nothing of an unusually large discount because the logo, colours, and layout look familiar.

That trust hasn’t been earned by the site. It’s borrowed from a brand that has nothing to do with it.

If you’ve entered your card details on one of these pages, the safest assumption is that your card has been compromised.

How the scam works

The scam follows a simple pattern: a Walmart-branded homepage, category pages stacked with heavily discounted liquor, and a checkout form asking for full card details.

The discounts do much of the persuading. Seeing premium brands advertised at 60% or 70% off encourages people to buy first and ask questions later.

The same WordPress/WooCommerce template powers every site in the network. They share the same product catalogue, prices, and images. The only differences are fabricated US business addresses and phone numbers that are swapped out for each domain.

How to avoid this scam
  • Be sceptical of discounts that don’t match a retailer’s usual promotions, especially on liquor or electronics.
  • Check the address bar before entering payment details. A genuine Walmart sale won’t send you to an unfamiliar .shop domain.
  • Use tools that can identify scam websites automatically, such as Malwarebytes Browser Guard on desktop, or ask Scam Guard if it thinks a domain is suspicious.
  • On mobile, where these sites are designed to work, Malwarebytes Mobile Security can block known phishing and scam domains before you reach the checkout.
If you already entered your card details
  • Contact your card issuer immediately. Explain what happened and ask whether the card should be cancelled and replaced.
  • Watch your account for unauthorized charges, including small “test” transactions.
  • Report the domain through your browser’s phishing reporting feature and to the FTC at reportfraud.ftc.gov if you’re in the US.

The simplest defence is also the most effective: if a retailer needs a lookalike domain to sell you something, it’s probably a scam.

Indicators of Compromise (IOCs)

allgoodscenter.shop, allneedsbay.shop, allneedslane.shop, allneedsmarket.shop, allneedsstore.shop, allpurposebay.shop, basketandmore.shop, broadbasket.shop, broadbasketbay.shop, broadbasketco.shop, broadbasketlane.shop, broadbasketplace.shop, broadbasketway.shop, broadchoice.shop, broadgoodsbay.shop, broadgoodscenter.shop, broadgoodsplace.shop, broadgoodsway.shop, broadmarketplacehub.shop, broadutility.shop, broadutilityhub.shop, broadvalue.shop, broadvaluebay.shop, broadvalueplace.shop, cartandcrate.shop, completehomegoods.shop, dailybasketport.shop, dailybasketway.shop, dailychoiceway.shop, dailycrate.shop, dailyfindslane.shop, dailygoodscrest.shop, dailygoodsfield.shop, dailygoodspark.shop, dailygoodsridge.shop, dailygoodsway.shop, dailygoodswayhub.shop, dailyhomemarket.shop, dailyutilitybay.shop, dailyutilityway.shop, everydaycartshop.shop, everydayneedsco.shop, everydayvaluebay.shop, generalcart.shop, generalcartlane.shop, generalgoodsport.shop, generalgoodsridge.shop, generalgoodsway.shop, generalgoodsyard.shop, generalmarketbay.shop, generalmarketfield.shop, generalneedsplace.shop, generalvaluebay.shop, goodsandhomebay.shop, goodsandhomeco.shop, goodsandhomehub.shop, goodsandlivinghub.shop, goodsandmoreco.shop, goodsandvaluehub.shop, goodsdistrict.shop, goodslanding.shop, goodsmeadow.shop, goodsroute.shop, goodsvalley.shop, homeandutility.shop, homebasketlane.shop, homebasketway.shop, homecartcenter.shop, homefieldmarket.shop, homefindsco.shop, homegoodscrate.shop, homegoodsport.shop, homegoodsway.shop, homelivinggoods.shop, homeneedslane.shop, homeneedsmarket.shop, homeparcel.shop, homesteadmart.shop, homeutilitystore.shop, homevaluebay.shop, homevalueplace.shop, homevalueway.shop, marketbasketcenter.shop, marketcanvas.shop, marketchoicebay.shop, marketchoiceplace.shop, marketfieldhub.shop, marketfindsbay.shop, marketfoundry.shop, marketgrovehub.shop, markethomeplace.shop, marketpillar.shop, marketpine.shop, marketridge.shop, markettrailway.shop, marketwarehouse.shop, modernsupplyhub.shop, smartbasketplace.shop, smartdailygoods.shop, smartneedshub.shop, smartutilityhub.shop, smartvaluebay.shop, trustedgoods.shop, usefulbasketlane.shop, usefulcartcenter.shop, usefulchoicebay.shop, usefuldailyhub.shop, usefulgoodsbay.shop, usefulgoodscenter.shop, usefulgoodspark.shop, usefulgoodsway.shop, usefulgoodswayhub.shop, usefulgoodsyard.shop, usefulmarket.shop, usefulmarketbay.shop, usefulshelf.shop, usefulutility.shop, usefulvalueplace.shop, utilitygoods.shop, valuechoicebay.shop, valuegoodspark.shop, valuegoodsridge.shop, valuegrove.shop, valueparcel.shop

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Pages