Top software download site came with a backdoor for hackers

(Image credit: Pixabay)

One of the world's most popular software download sites was hijacked by hackers to deliver malware alongside commonly-used programs, researchers have claimed.

According to a Dr. Web report, a link to download the free VSDC video converter tool from CNET’s website was compromised, instead forcing users to download a modified installer which came bundled with a trojan. 

This malware then allowed hackers to bypass the preinstalled antivirus programs installed on a victim's device and take control of the system.

VSDC download compromised

The report claims that the hackers were able to compromise the downloads link on CNET's site to target victims based on the geographic location. Some users in certain markets were able to download the genuine software, while the others got the compromised one.

Once the malicious software was installed, it was able to connect to a remote server and download additional modules like a trojan for remote-control RDP protocol, Predator The Thief stealer, SystemBC trojan-proxy and an X-Key logger. 

Among other files on the server, the security agency, also traced a compromised NordVPN installer file. A spokesperson for the company said that "The NordVPN app has not been available for download from CNET for years; it has not been hosted there since around 2017. This whole case seems rather dubious, especially having in mind that the information on the matter is extremely vague; however, we have reached out to CNET and asked for their comment. We can only confirm that this has nothing to do with our service or the integrity of our applications. Meanwhile, we always strongly suggest our customers download our apps only from the official sources - https://nordvpn.com, Google Play Store, or Apple Store."

According to internet statistics, CNET’s download page has over 90 million users per month which allowed the hackers got access to a huge user-base to target. Since, VSDC is well known free software for video editing, video conversion and is used to burn files on CDs, the hackers decided to target the users looking to download it.

The security experts at Doctor Web have deleted the infected files from the server and the users who had downloaded the video editor using the link from CNET's websites are suggested to run an antivirus scan on their computers.

Via: Dr. Web

TOPICS
Jitendra Soni

Jitendra has been working in the Internet Industry for the last 7 years now and has written about a wide range of topics including gadgets, smartphones, reviews, games, software, apps, deep tech, AI, and consumer electronics.  

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does