FakeBat Malware Weaponizing AnyDesk, Zoom, Teams & Chrome

Hackers target and weaponize AnyDesk, Zoom, Teams, and Chrome as these applications are widely used in a multitude of sectors.

Not only that, but even these widely used applications also provide access to many users and sensitive information.

Cybersecurity researchers at Sekoia identified that FakeBat malware has been actively weaponizing widely used applications, AnyDesk, Zoom, Teams, and Chrome.

FakeBat Malware Loader

In 2024, FakeBat loader malware has become a major threat that uses drive-by-download methods for propagation.

This is sold as Loader-as-a-Service on dark web platforms and masquerades itself through malvertising and social engineering tricks.

Mostly, it is used for launching various payloads such as botnets and infostealers, which have been also associated with ransomware attacks.

The malware’s operators have updated its capabilities to include MSIX format builds and digital signatures to bypass security measures.

"Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!"- Free Demo

The prices of FakeBat range from $1,000-$5,000 per week or month, depending on the package. Sekoia said that FakeBat deliberately restricts its customer base to maintain control over distribution and reduce the risks of detection.

FakeBat’s distribution has evolved into a sophisticated operation that involves different strategies such as malvertising, software impersonation, and social engineering on social networks.

Compromised website displaying a fake web browser update popup (Source – Sekoia)

Another way this malware is distributed is through compromised websites, fake browser updates, and targeted campaigns such as the “getmess.io” web3 chat app scam.

Fake web3 chat application (Source – Sekoia)

FakeBat’s infrastructure consists of many C2 servers with changing communication patterns and obfuscation techniques.

The operators use specific domain naming conventions and host their servers on select ASNs.

They have implemented traffic filtering based on user attributes and recently enhanced evasion by anonymizing their domain registrations.

This shows how Fakebat’s conspirators are adaptable while seeking evasion from detection during expansion.

Researchers observed that the following software were targeted by the FakeBat malvertising campaigns:-

  • 1Password
  • Advanced SystemCare
  • AnyDesk
  • Bandicam
  • Blender
  • Braavos
  • Cisco Webex
  • Epic Games
  • Google Chrome
  • Inkscape
  • Microsoft OneNote
  • Microsoft Teams
  • Notion
  • OBS Studio
  • OpenProject
  • Play WGT Golf
  • Python Shapr3D
  • Todoist
  • Trading View
  • Trello
  • VMware
  • Webull
  • WinRAR
  • Zoom

Nowadays, threat actors prefer making use of fake software landing pages to share malware, and this is done through the practice of tracking campaigns.

Other observed sets contain entities like FIN7 and Nitrogen campaigns which circulate different kinds of malicious codes.

FakeBat, a widely distributed loader marketed as Malware-as-a-Service, uses multiple means of distribution and constantly modifies itself to avoid being identified.

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files

Tushar Subhra

Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Recent Posts

Tails 6.14.2 Released with Critical Fixes for Linux Kernel Vulnerabilities

The Tails Project has urgently released Tails 6.14.2, addressing critical security vulnerabilities in the Linux kernel…

1 minute ago

APT29 Hackers Use GRAPELOADER in New Attack Against European Diplomats

Check Point Research (CPR) has uncovered a new targeted phishing campaign employing GRAPELOADER, a sophisticated…

55 minutes ago

Chinese Hackers Unleash New BRICKSTORM Malware to Target Windows and Linux Systems

A sophisticated cyber espionage campaign leveraging the newly identified BRICKSTORM malware variants has targeted European…

1 hour ago

Hacktivist Group Becomes More Sophisticated, Targets Critical Infrastructure to Deploy Ransomware

A recent report by Cyble has shed light on the evolving tactics of hacktivist groups,…

1 hour ago

CISA Issues 9 New ICS Advisories Addressing Critical Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released nine new advisories detailing severe…

2 hours ago

10 Best Email Security Solutions in 2025

Email security solutions are critical for protecting organizations from the growing sophistication of cyber threats…

3 hours ago