Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware
OnlyFans – an attractive brand for hopeful users and their attackers.
CRPx0 is a complex, stealthy and persistent malware campaign. It currently targets MacOS and Windows systems, and appears to have Linux capabilities in development. It currently comprises cryptocurrency theft followed by large scale data exfiltration and ransomware.
The campaign has been analyzed (PDF) in detail by Aryaka Threat Research Labs.
The initial social engineering lure is the offer of a free OnlyFans account. Users interested in free access to OnlyFans might actively search for available options, and stumble across the threat actors’ OnlyfansAccounts.zip. By looking for unauthorized free access to paid-for content, these users have already demonstrated a willingness to be risk takers open to less than legitimate activity. They would be more willing to download the zip, and to accept that acquiring a free account might require some non-standard activity. That’s a good start for any...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE