DN

Aliases: Fake

Malware type
ransomware
Last IoC activity
2026-07-22 00:33:36
Profile updated
2026-07-07 13:26:11

Context

It’s directed to English speaking users, therefore is able to infect worldwide. Uses the name “Chrome Update” to confuse its victims. Then imitates the chrome update process ,while encrypting the files. DO NOT pay the ransom, since YOUR COMPUTER WILL NOT BE RESTORED FROM THIS MALWARE!!!!

Detection coverage

  • 12 YARA rules

Used by threat actors

  • APT28 Router Compromise Attacks (campaign)
  • "Fake CAPTCHA" Lumma Stealer Distribution Campaign (campaign)
  • Lumma Stealer Distribution via Spoofed Webpages (campaign)
  • Operation Dream Job (campaign)
  • Operation In(ter)ception (campaign)
  • Operation Sharpshooter (campaign)
  • PowerShell User Execution Social Engineering Campaign (TA571, ClearFake, ClickFix) (campaign)
  • TA455 Iranian Dream Job Campaign (campaign)

Detection rules

  • TELEKOM_SECURITY_Fake_Gzip_Bokbot_202104 (yara-rule)
  • VOLEXITY_Apt_Malware_Macos_Vpnclient_Cc_Oct23 (yara-rule)
  • VOLEXITY_Apt_Delivery_Win_Charming_Openvpn_Client (yara-rule)
  • SECUINFRA_RANSOM_Magniber_LNK_Jan23 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Fakecaptcha_Downloader (yara-rule)
  • SEKOIA_Downloader_Mac_Rustbucket (yara-rule)
  • SEKOIA_Downloader_Win_Fake_Tor_Browser (yara-rule)
  • SIGNATURE_BASE_MAL_Fake_Document_Software_Indicators_Nov23 (yara-rule)
  • SIGNATURE_BASE_SUSP_Fake_AMSI_DLL_Jun23_1 (yara-rule)
  • SIGNATURE_BASE_Socgholish_JS_22_02_2022 (yara-rule)
  • SIGNATURE_BASE_SUSP_Nimbus_Manticore_PDF_Indicators_May26 (yara-rule)
  • SIGNATURE_BASE_MAL_Icedid_GZIP_LDR_202104 (yara-rule)

Reports & references

  • id-ransomware.blogspot.co.il — Dn Donotopen (report)

External references