Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Cybereason found new malware, Fauxpersky that disguised as Kaspersky anti-virus software
  • Malware

Cybereason found new malware, Fauxpersky that disguised as Kaspersky anti-virus software

Do Son March 30, 2018 3 minutes read
Add Daily CyberSecurity as a preferred source on Google

Cybersecurity company Cybereason wrote on Wednesday that they have discovered a new type of keylogger malware. Although technically speaking, the malware is far from being advanced, it has shown high efficiency in stealing passwords. Cybereason named the malware “Fauxpersky” because it disguised itself as the world-famous Russian anti-virus software Kaspersky.

According to a Cybereason researcher, Fauxpersky builds on the popular application AutoHotKey (AHK). The application allows users to write a variety of graphical user interfaces (GUI) and small scripts for the keyboard to automate tasks on Windows, and to compile these scripts into executable files.

For Fauxpersky developers, the application is used to build keyloggers. The keylogger propagates through a USB drive to infect a Windows computer and is able to self-replicate when any removable drive (such as a USB flash drive) is connected to the infected computer.

Specifically, after the first execution of Fauxpersky, it scans all removable drives attached to the computer, renaming them, and then copying all of their files.

For example, when an 8GB USB drive named “Pendrive” is connected to an infected computer, Fauxpersky will rename it “Pendrive 8GB (Secured by Kaspersky Internet Security 2017))”, translated as “Pendrive 8GB (by Kaspersky Internet Security Company 2017 Protection)”.

The researchers stated that they found a total of six files in a directory named “Kaspersky Internet Security 2017”, including four executable files, and each executable file has a name similar to that of a Windows system file: Explorers.exe, Spoolsvc.exe, Svhost.exe, and Taskhosts.exe.

 

Two other files, one is a picture file named “Logo.png” (used to forge a Kaspersky Anti-Virus startup screen), and the other is a text file named “Readme.txt”.

 

The four executables are the core components of Fauxpersky, which respectively carry different functions: Explorers.exe is used to complete the USB drive propagation; Svhost.exe is used to complete the key record and write the keyboard record data to the file (Log. Txt); Taskhosts.exe is used to establish the persistence mechanism; Spoolsvc.exe is used for the final data upload.

All data recorded in the Log.txt file will eventually be submitted to the attacker’s inbox via Google Forms. This is a simple but effective method, which means that an attacker does not need to deploy any command and control (C&C) servers. In addition, the data transmitted via Google Forms has already been encrypted, which makes Fauxpersky’s data uploads appear to be not suspicious in various traffic monitoring solutions.

 

Cybereason does not indicate in the article how many computers have been infected, but given that Fauxpersky’s intelligence is spread through the outdated method of sharing USB drives, it may not be widely disseminated.

Related coverage

  • Aurora Ransomware Targets VMware ESXi and Abuses Cursor Agent
  • Inside the AI-Driven “Lure Factory” Flooding GitHub with Trojans
  • CISA/NSA Warn of BRICKSTORM Backdoor: China APT Targets VMware and ADFS for Long-Term Espionage
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Fauxpersky

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90937CVSS 9.9
    froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect...
  • CVE-2026-90919CVSS 9.8
    LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config...
  • CVE-2026-90898CVSS 9.8
    Bifrost registers MCP clients through its management API. A stdio client is...
  • CVE-2026-90703CVSS 9.1
    A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element...
  • CVE-2026-90702CVSS 9.1
    A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the...
  • CVE-2026-90699CVSS 9.9
    A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects...
  • CVE-2026-90693CVSS 9.9
    A flaw has been found in D-Link DIR-878 120B05. This impacts the...
  • CVE-2026-90692CVSS 9.9
    A vulnerability was detected in D-Link DIR-878 120B05. This affects the function...
  • CVE-2026-82787CVSS 9.8
    Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability...
  • CVE-2026-90680CVSS 9.9
    A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.