fake update

AppWizard
September 1, 2026
Cybercriminals are targeting Android users with deceptive advertisements for malicious applications disguised as pornographic content on platforms like Facebook and Instagram. The National Cybercrime Threat Analytics Unit (NCTAU) has reported that these ads lead users to phishing traps or malware downloads that can compromise banking credentials. Malicious applications linked to this threat include “Night Play,” “Reloop,” “Kyss,” “Vimo,” “Rivo,” “Nexo,” and “Vixa.” The scam involves promoting these apps through enticing ads, redirecting users to websites offering pornographic content, and prompting them to download APK files directly from these sites, often using “.live” domains. The initial app may request users to download a second package disguised as an update, which can exploit permissions granted to the first app. This malware can gain extensive control over the device, potentially installing a VPN that routes internet traffic through attackers' servers. To protect against this threat, users should download apps only from trusted sources, avoid installing APK files from ads or suspicious links, refrain from granting Accessibility access to unknown apps, regularly review installed apps, keep Google Play Protect enabled, and monitor bank accounts for unusual activity. If a suspicious app cannot be uninstalled, users can try Safe Mode, remove special permissions, or perform a factory reset as a last resort.
Tech Optimizer
August 31, 2026
A fake Chrome update scam has emerged, linked to a Chrome extension called Enable Right Click & Copy - Smart Unlock + OCR, which was initially legitimate but later compromised. The extension had around 70,000 users before being removed from the Chrome Web Store on August 14 due to its malicious nature. Users may encounter deceptive warnings while browsing benign sites, urging them to download files instead of using Chrome's built-in update mechanism. Google advises against engaging with suspicious pop-ups requesting software installations. The scam highlights that trusted extensions can become threats without warning, and users should regularly review their installed extensions and check for updates directly within Chrome. Similar fake update alerts have also been reported in other Chromium-based browsers. Users are encouraged to adopt safety measures, such as using strong antivirus software, reviewing browser extensions, and being cautious with downloaded files. If a suspicious file has been executed, users should treat their computer as potentially compromised and take appropriate security actions.
Tech Optimizer
August 13, 2026
Users of Chromium-based browsers, including Google Chrome, Brave, and Opera, are experiencing deceptive pop-ups that falsely claim a "Critical Update Required" or "Update available." These notifications are part of a scam designed to trick users into downloading malware disguised as software updates. Clicking on these prompts can lead to the download of harmful scripts, such as .vbs or .exe files, which traditional antivirus software often fails to detect. The issue is linked to compromised browser extensions that fetch malicious scripts from external servers. A specific extension, QuickLens – Search Screen with Google Lens, has been identified as a source of these pop-ups and has been removed from the Web Store. Other extensions, like “Enable Right Click & Copy Smart Unlock + OCR,” have also been implicated despite their popularity. Users are advised not to click on any links or run downloaded files and to check their browser settings for legitimate updates, as well as to audit and disable suspicious extensions.
Tech Optimizer
August 8, 2026
Securonix Threat Research has identified a cyber campaign called SMOKE#SCREEN that uses deceptive tactics to trick users into installing weaponized versions of ScreenConnect, a legitimate remote monitoring software. The attackers disguise their malicious intent with fake update notifications for applications like Zoom and Adobe, as well as counterfeit business documents. This campaign allows attackers to gain persistent remote access to victims' systems, disable security protections, and exploit trusted services like Dropbox and Cloudflare for delivering malicious payloads. Victims have been reported on both Windows and macOS platforms. Businesses are advised to verify updates through official channels and train staff on the risks of unexpected software installations.
AppWizard
March 11, 2026
A newly identified Android malware called BeatBanker disguises itself as a Starlink application on fake Google Play Store websites. It functions as a banking trojan and includes Monero mining capabilities, allowing it to steal credentials and manipulate cryptocurrency transactions. Researchers at Kaspersky traced BeatBanker to campaigns targeting users in Brazil. The latest version uses the BTMOB RAT for remote access, enabling keylogging, screen recording, camera access, GPS tracking, and credential capture. BeatBanker is distributed as an APK file that decrypts and loads hidden code into memory, conducting environment checks before activation. It presents a fake Play Store update screen to trick users into granting permissions for additional payloads. To avoid detection, it delays malicious operations and plays a nearly inaudible MP3 file to maintain persistent activity. The malware uses a modified version of the XMRig miner to mine Monero on Android devices, connecting to mining pools through encrypted TLS connections. It can start or stop mining based on device conditions and uses Firebase Cloud Messaging to relay device information to its command-and-control server. Currently, BeatBanker infections have only been observed in Brazil, but there are concerns about its potential spread. Users are advised to avoid side-loading APKs from untrusted sources and to review app permissions regularly.
Search