{"id":5412,"date":"2025-07-17T10:05:28","date_gmt":"2025-07-17T10:05:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/17\/infostealers-distributed-with-crack-apps-emerges-as-top-attack-vector-for-june-2025\/"},"modified":"2025-07-17T10:05:28","modified_gmt":"2025-07-17T10:05:28","slug":"infostealers-distributed-with-crack-apps-emerges-as-top-attack-vector-for-june-2025","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/17\/infostealers-distributed-with-crack-apps-emerges-as-top-attack-vector-for-june-2025\/","title":{"rendered":"Infostealers Distributed with Crack Apps Emerges as Top Attack Vector For June 2025"},"content":{"rendered":"<p>    Infostealers Distributed with Crack Apps Emerges as Top Attack Vector For June 2025<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The cybersecurity landscape in June 2025 was dominated by a surge of Infostealer malware masked as cracked or key-generated software, catapulting this tactic to the month\u2019s most prevalent attack vector.<\/p>\n<p>Fraudulent download portals advertising \u201cfree\u201d versions of popular tools lured victims through aggressive search-engine-optimization (SEO) poisoning, ensuring that malicious links ranked above legitimate sources and evaded routine scrutiny.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh2xegrBujHeTtjsIkXvA-3bLzpQDOxQ3effmbXWfyYn0FYvPUiECOg3vQF91bKgf9c1IWSVigPs2iIHHiY_2MyoXOthATTRoLrLpFGfhSLbMzlY-OVC3Gv8B3bmtvq_YPAbnJd_KXWoAqsigc0GA7Ka0Ns-p2RcT4f6i9bQGdI9R1snLciPkzGjNE3ZQQ\/s16000\/Page%2520distributing%2520malware%2520%28Source%2520-%2520ASEC%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Page distributing malware (Source \u2013 ASEC)<\/figcaption><\/figure>\n<\/div>\n<p>Once a user clicked a download banner, a password-protected archive\u2014its credentials sometimes hidden inside an image rather than a text file\u2014delivered the payload, complicating automated sandbox analysis.<\/p>\n<p>ASEC researchers <a href=\"https:\/\/asec.ahnlab.com\/en\/89033\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that threat actors posted these download links across reputable forums, Q&amp;A boards, and even political organizations\u2019 websites, bypassing traditional perimeter filtering.<\/p>\n<p>Although the long-dominant LummaC2 family receded, new builds of Rhadamanthys, Vidar, StealC, and especially a re-engineered ACRStealer filled the vacuum.<\/p>\n<p>The total volume of collected samples fell compared with May, yet ASEC\u2019s automated collection platform intercepted most binaries days before they appeared on VirusTotal, highlighting an accelerating detection\u2013distribution arms race.<\/p>\n<p>The economic impact is considerable. Infostealers exfiltrate browser cookies, <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency wallets<\/a>, and corporate credentials within seconds, facilitating follow-on ransomware or business-email-compromise attacks.<\/p>\n<p>Enterprises also face reputational damage as compromised employee devices become launchpads for lateral movement.<\/p>\n<p>With 94.4% of June samples packaged as standalone executables and 5.6% relying on <a href=\"https:\/\/cybersecuritynews.com\/hackers-employ-dll-side-loading\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL side-loading<\/a>, defenders must scrutinize both portable binaries and seemingly benign file pairs masquerading inside software cracks.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>Execution begins immediately after the victim unzips the archive and launches the <a href=\"https:\/\/cybersecuritynews.com\/malicious-chrome-installer-alert\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake installer<\/a>.<\/p>\n<p>For EXE-only campaigns, the binary drops itself into <code>%ProgramFiles(x86)%Windows NTTableTextServicesvchost.exe<\/code> and establishes persistence by writing a Run key\u2014an approach that blends into legitimate Windows services.<\/p>\n<pre class=\"wp-block-code\"><code>reg add \"HKCUSoftwareMicrosoftWindowsCurrentVersionRun\" ^\n \/v TableTextServiceStartup ^\n \/t REG_SZ ^\n \/d \"%ProgramFiles(x86)%Windows NTTableTextServicesvchost.exe\" ^\n \/f<\/code><\/pre>\n<p>DLL side-loading variants place a modified DLL next to a genuine signed executable; Windows\u2019 default search order then silently loads the malicious library, preserving the host file\u2019s signature and evading application-whitelisting engines.<\/p>\n<p>Once resident, the newest ACRStealer samples manually map <code>ntdll.dll<\/code>, invoke Heaven\u2019s Gate to switch to 64-bit mode on 32-bit processes, and disguise outbound traffic by spoofing host headers that point to <code>microsoft.com<\/code> while tunneling data to attacker-controlled domains.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhRtcb_PBrKmcGmHqYDVYZ2hYzld6xuh8U9OdcD82RA1DfqQtAwa08VVfMDNf6MrbMy6nxkA0ZKtp4UY4Y7mbrGKOtojEERPnZdlPpKu59-ySKjb9NT0_KIaLVfCKx7lMIK2NdUJUGlaVjJo_0qHlxfVdKNIfxqx-UNryUpe3SmV8cCSk4_EGial8K1GoM\/s16000\/C2%2520communication%2520record%2520of%2520ACRStealer%2520%28Source%2520-%2520ASEC%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">C2 communication record of ACRStealer (Source \u2013 ASEC)<\/figcaption><\/figure>\n<\/div>\n<p>These anti-analysis tricks frustrate heuristic detection, allowing the malware to siphon credentials and session tokens before many endpoint solutions trigger.<\/p>\n<p>Network defenders should monitor for anomalous connections to known cloud-storage services immediately after new executable launches, deploy YARA rules targeting password-protected archives shipped via search-engine links, and validate unsigned binaries in <code>Windows NT<\/code> subdirectories.<\/p>\n<p>Given the rapid appearance of <a href=\"https:\/\/cybersecuritynews.com\/researchers-obfuscated-weaponized-net-assemblies\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> ACRStealer builds and the proven efficacy of SEO poisoning, incident-response teams must prioritize web-filtering policies that demote crack-related content and accelerate sandboxing of any archive whose password is revealed only upon extraction.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_ciso_challenges&amp;utm_content=demo_1&amp;utm_term=160725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN Now<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/infostealers-distributed-with-crack-apps\/\">Infostealers Distributed with Crack Apps Emerges as Top Attack Vector For June 2025<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/infostealers-distributed-with-crack-apps\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infostealers Distributed with Crack Apps Emerges as Top Attack Vector For June 2025 The cybersecurity landscape in June 2025 was dominated by a surge of Infostealer malware masked as cracked or key-generated software, catapulting this tactic to the month\u2019s most prevalent attack vector. Fraudulent download portals advertising \u201cfree\u201d versions of popular tools lured victims through [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5412","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5412"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5412"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5412\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}