Threat actors have been using fake crack, keygen, pirated software, and bogus installer sites to infect users with information-stealing malware, often through SEO poisoning, redirect chains, and password-protected archives hosted on legitimate services such as MediaFire, Discord, and filesend.jp. Reported payloads include RedLine, RecordBreaker, Cryptbot, CopperStealer, Lightning Stealer, FFDroider, ZingoStealer, LUMMASTEALER, and IDATLOADER, with lures ranging from KMSpico activators and fake Telegram installers to cracked copies of TeamViewer, VueScan Pro, Movavi Video Editor, and other popular software. Several campaigns used anti-analysis techniques such as anti-VM checks, obfuscated loaders, process hollowing, DLL sideloading, and in-memory execution to evade detection.
The malware families stole browser credentials, cookies, credit card data, Discord tokens, Telegram data, screenshots, desktop files, and cryptocurrency wallet information, while some also hijacked clipboard wallet addresses, redirected exchange traffic through malicious proxy settings, abused stolen Facebook and Instagram business accounts, or downloaded follow-on payloads such as miners and additional stealers. Researchers warned that these infections are often opportunistic because victims actively seek pirated software, but the resulting foothold can enable broader compromise, including persistence, backdoor access, VPN abuse, lateral movement, and resale of access to other criminals or ransomware operators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
21 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC disclosed a breach investigation in which an employee-associated PC was infected via a fake Waves SoundShifter crack, leading to RedLine theft of browser-saved VPN credentials. Those stolen credentials were used several months later to compromise the company's internal network, and the fake installer also dropped DanaBot and Vidar.
Avast described the FakeCrack campaign, which used Black SEO, fake crack sites, redirect chains, and legitimate file-sharing services to deliver stealer malware disguised as pirated software. Some samples also deployed a clipboard hijacker and malicious proxy auto-configuration targeting cryptocurrency exchange traffic.
An update dated April 14, 2022 stated that ownership of the ZingoStealer project was being transferred to a new threat actor. The malware author also offered the source code for sale for $500.
The Hacker News reported on FFDroider and Lightning Stealer as active infostealers spread via cracked installers, freeware, and similar lures. The article highlighted FFDroider's theft of social-media and e-commerce cookies and Lightning Stealer's theft of browser, Discord, and cryptocurrency wallet data.
Cyble Research Labs reported on Lightning Stealer, a new .NET-based information stealer that harvested browser data, crypto-wallet data, Telegram and Discord data, desktop files, system information, and screenshots. The malware serialized stolen data to JSON and exfiltrated it to panelss[.]xyz.
Cisco Talos said ZingoStealer was first introduced in the wild in March 2022. The .NET stealer was released for free by Haskers Gang and targeted primarily Russian-speaking home users with pirated software and cheat-themed lures.
Trend Micro published research on a campaign using fake installers and cracked software such as TeamViewer, VueScan Pro, Movavi Video Editor, and Autopano Pro to deliver malware bundles. The activity was assessed as opportunistic initial infection that could later enable enterprise compromise, lateral movement, or resale to ransomware operators.
Proofpoint investigated CopperStealer after a sample shared on January 29, 2021 triggered an Emerging Threats network intrusion detection rule. The sample became the basis for the company's primary analysis.
Proofpoint noted that ESET created antivirus detections for the threat under the name Mingloa in January 2021. This marked a vendor detection milestone for the malware family.
Cisco Talos said the crimeware group Haskers Gang had been active since at least January 2020. The group used Telegram and Discord communities to distribute tooling, updates, and stolen logs.
Proofpoint and Emerging Threats had tracked the malware family as CopperStealer since November 2019. The name came from PDB and process-memory strings referencing DavidCopperfield.
Proofpoint identified the earliest CopperStealer samples as dating back to July 2019. The malware was distributed primarily through fake crack and keygen websites and functioned as a password and cookie stealer with downloader capability.
Zscaler ThreatLabz reported multiple ongoing campaigns using fake shareware and pirated software sites indexed in Google search results to distribute infostealers. The documented chains delivered RedLine Stealer and RecordBreaker Stealer through redirect infrastructure, password-protected archives, and in some cases trusted hosting services such as MediaFire and Discord.
Kroll responded to an incident in which a victim downloading content from a Bollywood pirate movie site was redirected through Bunny CDN and bit.ly to a ZIP archive that ultimately launched mshta.exe against a fake PGP Secret Key file. The chain downloaded additional archives, used BPL sideloading, and deployed IDATLOADER along with LUMMASTEALER and another password stealer.
Avast reported protecting roughly 10,000 users per day from the FakeCrack campaign, with victims primarily in Brazil, India, Indonesia, and France. Blockchain analysis also led researchers to estimate at least $50,000 in attacker earnings from wallet hijacking.
Cisco Talos said it had observed multiple new versions of ZingoStealer, indicating active development. Talos also documented campaigns using YouTube, Google Drive, Discord CDN, Bitly, and Mega.nz to distribute the malware and related payloads such as RedLine.
Red Canary identified a campaign distributing altered KMSpico installers that secretly deployed Cryptbot while also installing a working KMS emulator. The malware stole browser and cryptocurrency wallet data and used obfuscation, sandbox checks, and process hollowing.
Trend Micro said it observed incidents associated with this batch of fake installers around the world during August. The detections highlighted broad geographic spread of the campaign.
After about 28 hours of sinkhole operation, CopperStealer traffic declined sharply and distribution via keygenninja[.]com ceased. The disruption measurably reduced active malware delivery.
In the first 24 hours of sinkhole operation, researchers logged 69,992 HTTP requests from 5,046 unique IP addresses across 159 countries, representing 4,655 unique infections. India, Indonesia, Brazil, Pakistan, and the Philippines were the most affected countries by unique infections.
Proofpoint coordinated disruptive action with Facebook, Cloudflare, and other providers against CopperStealer. Cloudflare added warning interstitials to malicious domains and sinkholed two domains before the actor could register them.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcekroll.com
Open sourceasec.ahnlab.com
Open sourceblog.avast.com
Open sourceblog.cyble.com
Open sourcebleepingcomputer.com
Open sourcetrendmicro.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.