• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • Cybereason found new malware, Fauxpersky that disguised as Kaspersky anti-virus software
  • Malware

Cybereason found new malware, Fauxpersky that disguised as Kaspersky anti-virus software

Ddos March 30, 2018 3 minutes read

Cybersecurity company Cybereason wrote on Wednesday that they have discovered a new type of keylogger malware. Although technically speaking, the malware is far from being advanced, it has shown high efficiency in stealing passwords. Cybereason named the malware “Fauxpersky” because it disguised itself as the world-famous Russian anti-virus software Kaspersky.

According to a Cybereason researcher, Fauxpersky builds on the popular application AutoHotKey (AHK). The application allows users to write a variety of graphical user interfaces (GUI) and small scripts for the keyboard to automate tasks on Windows, and to compile these scripts into executable files.

For Fauxpersky developers, the application is used to build keyloggers. The keylogger propagates through a USB drive to infect a Windows computer and is able to self-replicate when any removable drive (such as a USB flash drive) is connected to the infected computer.

Specifically, after the first execution of Fauxpersky, it scans all removable drives attached to the computer, renaming them, and then copying all of their files.

For example, when an 8GB USB drive named “Pendrive” is connected to an infected computer, Fauxpersky will rename it “Pendrive 8GB (Secured by Kaspersky Internet Security 2017))”, translated as “Pendrive 8GB (by Kaspersky Internet Security Company 2017 Protection)”.

The researchers stated that they found a total of six files in a directory named “Kaspersky Internet Security 2017”, including four executable files, and each executable file has a name similar to that of a Windows system file: Explorers.exe, Spoolsvc.exe, Svhost.exe, and Taskhosts.exe.

 

Two other files, one is a picture file named “Logo.png” (used to forge a Kaspersky Anti-Virus startup screen), and the other is a text file named “Readme.txt”.

 

The four executables are the core components of Fauxpersky, which respectively carry different functions: Explorers.exe is used to complete the USB drive propagation; Svhost.exe is used to complete the key record and write the keyboard record data to the file (Log. Txt); Taskhosts.exe is used to establish the persistence mechanism; Spoolsvc.exe is used for the final data upload.

All data recorded in the Log.txt file will eventually be submitted to the attacker’s inbox via Google Forms. This is a simple but effective method, which means that an attacker does not need to deploy any command and control (C&C) servers. In addition, the data transmitted via Google Forms has already been encrypted, which makes Fauxpersky’s data uploads appear to be not suspicious in various traffic monitoring solutions.

 

Cybereason does not indicate in the article how many computers have been infected, but given that Fauxpersky’s intelligence is spread through the outdated method of sharing USB drives, it may not be widely disseminated.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. TA402 Uses IronWind Malware in Targeted Attacks
  2. Malware Exploiting IoT Devices on the Rise, SonicWall Warns
  3. Mint Stealer: New MaaS Malware Threatens Confidential Data
  4. Fake Game Hacks on YouTube Target Kids with Malware
  5. Meet ZynorRAT: The New Cross-Platform Malware Controlled via Telegram
Tags: Fauxpersky

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.