Threat researchers reported two large malware distribution operations that relied on popular consumer lures rather than software exploits. One campaign used piracy sites offering movies, TV shows, books, and digital library content to push fake plugin or browser update prompts; the downloaded ZIP files abused DLL side-loading, ROP-based decryption, and reflective loading to install a modified SilentCryptoMiner, a watchdog, a RAT component, and CPU/GPU miners. The malware gated execution through DNS tunneling and date-generated command-and-control infrastructure, harvested host data, and established persistence with a fake GoogleUpdateTaskMachineQC service and repeated UAC elevation attempts, with implicated sites drawing roughly 40 million visits in a single month.
A separate operation used openew[.]app, a fake ChatGPT download page impersonating OpenAI, to infect both Windows and macOS users with platform-specific malware. Windows visitors received a credential-stealing loader disguised as Chat_GPT.exe, built with Inno Setup and Electron and launching PowerShell activity that contacted 188.137.246.189, while macOS users were served Atomic Stealer (AMOS) to steal passwords, browser data, Telegram sessions, and cryptocurrency wallet information. Researchers said the macOS payload also attempted to replace legitimate Ledger and Trezor applications with trojanized versions, underscoring a strong cryptocurrency theft motive and showing how attackers are exploiting AI-brand search traffic and piracy demand to scale malware infections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A fake site, openew[.]app, impersonated OpenAI’s ChatGPT download page and served different malware by platform: a credential-stealing loader to Windows users and Atomic Stealer (AMOS) to macOS users. The macOS payload also attempted to replace Ledger and Trezor wallet apps with trojanized versions.
In late April 2026, responders investigated a campaign in which piracy-related websites used fake plugin or browser update prompts to deliver a ZIP archive that deployed a modified SilentCryptoMiner-based payload, RAT components, and CPU/GPU miners.
The malware campaign tied to illegal movie, TV, and pirated digital library websites appears to date back to at least 2022, indicating a long-running operation targeting piracy users with malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.