downloaded files

Winsage
September 2, 2026
An active malware campaign is using counterfeit software-download websites to distribute malicious installers, primarily targeting users seeking popular software. This campaign has significantly affected China-based operations of multinational corporations and Chinese-speaking users. The malware, once executed, can establish persistence, undermine security measures, and communicate with attacker-controlled infrastructure. Victims span various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft associates this campaign with a Chinese threat cluster called Silver Fox, known for using spoofed vendor download pages to spread Gh0st RAT and ValleyRAT. The malicious websites are hosted on .com.cn and .hl.cn domains, featuring Chinese-language content. The downloaded files are dynamically generated, and upon execution, they deploy a wrapper installer that initiates the malware payload. The malware achieves persistence through scheduled tasks and interferes with Windows Update services. The campaign establishes command-and-control communication over non-standard ports, with two identified domains linked to the activity. Microsoft Defender has detected the threat and initiated containment procedures. Kaspersky reported a related malicious installer exploiting a legitimate adware application to execute a backdoor, which captures keystrokes and clipboard contents. ValleyRAT, a sophisticated implant, can collect system information, reboot the computer, capture screenshots, and transmit logs. The attackers are motivated by cyber espionage and financial gain, targeting organizations globally. A subgroup within GoldenEyeDog, known as CuboidalCanine, has also been linked to the use of ValleyRAT, particularly in the gambling industry. In June 2026, Chinese authorities addressed cybercrime cases involving a new variant of the Silver Fox trojan.
TrendTechie
September 2, 2026
Sony Music Publishing and Warner Chappell Music have filed a lawsuit against Anthropic, claiming that the company used pirated songbooks and song lyrics from "shadow libraries" to train its AI model, Claude. The lawsuit cites approximately 7 million books obtained through torrent downloads and web scraping, including unauthorized sheet music and songbooks. The plaintiffs are seeking statutory damages of up to 0,000 for each work that is found to have been willfully infringed. The lawsuit was filed on August 28, 2026, in the U.S. District Court for the Northern District of California, naming Anthropic and its co-founders as defendants. The plaintiffs allege that the data sources used for training included 5 million books downloaded from Library Genesis and 2 million from Pirate Library Mirror, as well as scraped song lyrics from licensed platforms Musixmatch and LyricFind. The use of BitTorrent for downloads introduces legal risks due to the simultaneous distribution of files. The lawsuit emphasizes the distinction between legally purchased and pirated materials, with prior cases indicating that downloads from pirate libraries constitute significant copyright infringement.
Tech Optimizer
August 31, 2026
A fake Chrome update scam has emerged, linked to a Chrome extension called Enable Right Click & Copy - Smart Unlock + OCR, which was initially legitimate but later compromised. The extension had around 70,000 users before being removed from the Chrome Web Store on August 14 due to its malicious nature. Users may encounter deceptive warnings while browsing benign sites, urging them to download files instead of using Chrome's built-in update mechanism. Google advises against engaging with suspicious pop-ups requesting software installations. The scam highlights that trusted extensions can become threats without warning, and users should regularly review their installed extensions and check for updates directly within Chrome. Similar fake update alerts have also been reported in other Chromium-based browsers. Users are encouraged to adopt safety measures, such as using strong antivirus software, reviewing browser extensions, and being cautious with downloaded files. If a suspicious file has been executed, users should treat their computer as potentially compromised and take appropriate security actions.
Tech Optimizer
August 24, 2026
Overall Rating: 4.3/5 ⭐ Protection: 4.3 ⭐ Performance: 3.9 ⭐ Features: 4.4 ⭐ Support: 4.8 ⭐ Value: 4.2 ⭐ Pricing starts at .99 for the first year, verified August 2026. Malwarebytes earned the AV-TEST TOP PRODUCT award in March-April 2026, scoring 17.5 out of 18 points. It successfully removed all infections in remediation tests and had no false detections across 1.5 million legitimate samples at AV-TEST. The software can coexist with other antivirus solutions and offers a free version with limited features. The free version lacks ongoing protection after 14 days, while the paid version provides real-time protection. Malwarebytes has a privacy policy stating it does not sell customer data and collects only necessary identifiers. The company was founded in 2008 and is headquartered in Santa Clara, California, having raised a total of 0 million, including a recent investment from Vector Capital in September 2022. It acquired AzireVPN in November 2024. Malwarebytes offers various plans, including Standard, Plus, and Total, with consistent renewal pricing. The Windows version includes comprehensive features, while the Mac version targets adware and browser hijackers. The Android app provides scanning capabilities and phishing protection, and the iPhone app focuses on scam text filtering. Customer support is efficient, with quick responses.
Winsage
August 24, 2026
Windows 11 will reintroduce the “Preview anyway” button for downloaded files in File Explorer, enhancing functionality and convenience. This update is expected to roll out in the coming weeks. The Preview pane in File Explorer stopped displaying previews for downloaded files on October 14, 2025, due to a security measure implemented by Microsoft to protect users from potential threats associated with previewing unsafe files. Users received warnings when attempting to preview downloaded files, advising them to trust the source. The restriction affects files marked with the Mark of the Web, including various downloads from browsers and email attachments. Previously, users could unblock files manually or through PowerShell scripts. The new “Preview anyway” button will allow users to override the warning for trusted files while still receiving a cautionary message.
Search