Kaspersky Report on Less Common Primary Infection Vectors

Updated on 2022-10-06

Researchers from Kaspersky recently looked into less-commonly used vectors of infection in malware campaigns. The methods include infection through malicious torrents (CLoader), infections through a fake TOR browser (OnionPoison), and as backdoored and signed benign tool (AdvancedIPSpyware).


Updated on 2022-10-05

A renowned Chinese language YouTube channel was found propagating a trojanized version of a Windows installer for Tor browser. Dubbed OnionPoison, the campaign has been going on since at least March. Read more: OnionPoison: infected Tor Browser installer distributed through popular YouTube channel

Overview: OnionPoison

Kaspersky researchers said they identified a campaign that distributed spyware-laced versions of the Tor Browsers via a popular Chinese YouTube channel. Named OnionPoison, the spyware collected data such as browsing history, social networking account IDsm and Wi-Fi network identifiers, but did not bother to collect more sensitive information such as user passwords, cookies, or wallet information. Read more: OnionPoison: infected Tor Browser installer distributed through popular YouTube channel

