Skip to content
October 6, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • Cybereason found new malware, Fauxpersky that disguised as Kaspersky anti-virus software
  • Malware

Cybereason found new malware, Fauxpersky that disguised as Kaspersky anti-virus software

Do Son March 30, 2018 3 minutes read
Add Daily CyberSecurity as a preferred source on Google

Cybersecurity company Cybereason wrote on Wednesday that they have discovered a new type of keylogger malware. Although technically speaking, the malware is far from being advanced, it has shown high efficiency in stealing passwords. Cybereason named the malware “Fauxpersky” because it disguised itself as the world-famous Russian anti-virus software Kaspersky.

According to a Cybereason researcher, Fauxpersky builds on the popular application AutoHotKey (AHK). The application allows users to write a variety of graphical user interfaces (GUI) and small scripts for the keyboard to automate tasks on Windows, and to compile these scripts into executable files.

For Fauxpersky developers, the application is used to build keyloggers. The keylogger propagates through a USB drive to infect a Windows computer and is able to self-replicate when any removable drive (such as a USB flash drive) is connected to the infected computer.

Specifically, after the first execution of Fauxpersky, it scans all removable drives attached to the computer, renaming them, and then copying all of their files.

For example, when an 8GB USB drive named “Pendrive” is connected to an infected computer, Fauxpersky will rename it “Pendrive 8GB (Secured by Kaspersky Internet Security 2017))”, translated as “Pendrive 8GB (by Kaspersky Internet Security Company 2017 Protection)”.

The researchers stated that they found a total of six files in a directory named “Kaspersky Internet Security 2017”, including four executable files, and each executable file has a name similar to that of a Windows system file: Explorers.exe, Spoolsvc.exe, Svhost.exe, and Taskhosts.exe.

 

Two other files, one is a picture file named “Logo.png” (used to forge a Kaspersky Anti-Virus startup screen), and the other is a text file named “Readme.txt”.

 

The four executables are the core components of Fauxpersky, which respectively carry different functions: Explorers.exe is used to complete the USB drive propagation; Svhost.exe is used to complete the key record and write the keyboard record data to the file (Log. Txt); Taskhosts.exe is used to establish the persistence mechanism; Spoolsvc.exe is used for the final data upload.

All data recorded in the Log.txt file will eventually be submitted to the attacker’s inbox via Google Forms. This is a simple but effective method, which means that an attacker does not need to deploy any command and control (C&C) servers. In addition, the data transmitted via Google Forms has already been encrypted, which makes Fauxpersky’s data uploads appear to be not suspicious in various traffic monitoring solutions.

 

Cybereason does not indicate in the article how many computers have been infected, but given that Fauxpersky’s intelligence is spread through the outdated method of sharing USB drives, it may not be widely disseminated.

Related coverage

  • Bypassing Terminal Protections: New SHub “Reaper” Variant Abuses AppleScript to Loot macOS Endpoints
  • The Hidden Threat in Man Pages: Kinsing Malware Targets Apache Tomcat Servers
  • Qilin Ransomware Attack Exploits MSP Vulnerability to Target Downstream Customers
  • Stealc Malware: The Infostealer Targeting Credentials, Crypto Wallets, and More
  • UAT-11587 Targets Asian Governments With Antino Backdoor
  • The Rise of Payouts King and the Resurrection of BlackBasta
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Fauxpersky

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-104019CVSS 9.3
    OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x...
    📅 Updated: Oct 6, 2026
  • CVE-2026-105778CVSS 9.4
    A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of...
    📅 Updated: Oct 6, 2026
  • CVE-2026-105794CVSS 9.1
    MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust....
    📅 Updated: Oct 6, 2026
  • CVE-2026-105851CVSS 9.3
    Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.90.0 and...
    📅 Updated: Oct 6, 2026
  • CVE-2026-87830CVSS 9.1
    In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that...
    📅 Updated: Oct 6, 2026
  • CVE-2026-89238CVSS 9.1
    WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality...
    📅 Updated: Oct 6, 2026
  • CVE-2026-94293CVSS 9.3
    An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all...
    📅 Updated: Oct 6, 2026
  • CVE-2026-88424CVSS 9.8
    FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability...
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.