FakeSecurity is a malware activity cluster associated with credential theft and payment-data theft, and linked to both web skimming and multi-stage malware delivery operations. The actor has been tied to a FakeSecurity JS-sniffer ecosystem that compromised e-commerce sites and to broader malware distribution campaigns that delivered commodity stealers and remote-access malware through phishing pages, malicious macro-enabled documents, fake software update lures, and staged payload hosting. In 2020, activity attributed to FakeSecurity was linked to a multi-wave campaign that distributed Vidar stealer and later Raccoon Stealer, with additional use of AveMaria RAT, Buer Loader, and Smoke Loader. The operation used phishing infrastructure and fake update themes, including pages built with the Mephistophilus phishing kit, to infect victims and steal browser data, payment information, account data, autofill data, and cryptocurrency wallet information. The same ecosystem was also associated with JS-sniffer compromises of online stores, indicating overlap between endpoint credential theft and e-commerce payment-card harvesting. More recent FakeSecurity-tracked activity has used trusted third-party hosting platforms as staging infrastructure for multi-stage Windows malware. Observed tradecraft includes encoded PowerShell, heavily obfuscated batch scripts, removal of Mark-of-the-Web metadata to reduce SmartScreen protections, persistence through autorun mechanisms, extraction of embedded payloads, shellcode decryption, and injection into explorer.exe with watchdog-style execution maintenance. Across reporting, the cluster demonstrates strong defense-evasion and post-exploitation tradecraft while relying heavily on social engineering, staged download chains, and commodity malware families to monetize access and stolen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
167 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign leveraging Hugging Face-hosted payloads and obfuscated scripts to infect Windows systems while masquerading as security-related software.
Activity cluster using Hugging Face-hosted scripts in a multistage Windows infection chain that deploys a payload disguised as Windows Defender, establishes persistence, and performs in-memory process injection into explorer.exe.
Conducting a multi-stage malware distribution and payment-data theft campaign targeting e-commerce, using phishing pages, malicious macro documents, JS-sniffers, and MaaS-delivered stealers/loaders.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.