Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

‘Vibe-Coded’ Malware Campaign Uses Fake Tools, CDNs and File Hosts to Infect Users

In January 2026, a significant malware campaign was identified. It involved over 443 malicious ZIP files disguised as software tools such as AI image generators, voice-changing tools, game hacks, Roblox script executors, VPN software, graphics card…

In January 2026, a significant malware campaign was identified. It involved over 443 malicious ZIP files disguised as software tools such as AI image generators, voice-changing tools, game hacks, Roblox script executors, VPN software, graphics card drivers, ransomware decryptors, and infostealer tools. These files were distributed across various platforms, including Discord, SourceForge, FOSSHub, MediaFire, and mydofiles.com.

The campaign utilized a file called WinUpdateHelper.dll, which was found in 48 unique variants. These variants fell into 17 distinct kill chains, each operated via separate command-and-control infrastructures. The shared use of cryptocurrency wallet credentials allowed for tracking of financial transactions.

McAfee analysts traced the origins of this threat back to December 2024, noting the incorporation of AI-generated scripting elements. The campaign primarily targeted users in the United States, followed by the United Kingdom, India, Brazil, France, Canada, and Australia.

The operation involved seven Bitcoin wallets, which collectively held approximately USD 4,536, with total received funds amounting to nearly USD 11,498. However, given the focus on mining privacy-oriented cryptocurrencies like Monero and Zephyr, the actual financial impact is likely higher.

These files were distributed across various platforms, including Discord, SourceForge, FOSSHub, MediaFire, and mydofiles.com.
Angela Waters · Thehackingpost

When a user executes a trojanized ZIP archive, the WinUpdateHelper.dll file loads silently alongside a legitimate executable. The DLL redirects the user's browser to a page prompting the download of DependencyCore.zip, which installs unrelated software to distract the user.

Meanwhile, WinUpdateHelper.dll connects to a command-and-control server. The C2 domain refreshes every 58 days, complicating efforts to block it proactively. The malware establishes persistence by registering a Windows service named "Microsoft Console Host" that executes a PowerShell script in-memory, evading file-based detection.

The PowerShell script executes several actions, including removing older persistence entries, adding exclusions to Windows Defender, and deploying two coin miners—one for CPU-based Zephyr mining and another for GPU-based Ravencoin mining. In some cases, the final payload is either SalatStealer or a Mesh Agent remote access tool.

Advertisement

Users are advised to avoid downloading software from unofficial sources, regularly inspect active Windows services, and treat unsolicited dependency prompts with caution.

For further insights, visit the McAfee blog .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories