Researchers Warn of Growing Phishing Campaigns with Hidden Malware
A recent phishing campaign is targeting users by pretending to be Ukrainian government agencies. Hackers send emails with malicious SVG files that start a chain of downloads, eventually installing malicious software like Amatera Stealer (which steals personal data and login info) and PureMiner (which secretly mines cryptocurrency using the victim’s computer). These malicious software tools are part of a larger set created by a group known as PureCoder. The malware runs directly in memory, making it harder to detect. Similar attacks have also been reported using fake copyright notices to trick users into downloading malicious files.
Safety Tips:
- Don’t open email attachments from unknown sources – especially ZIP, CHM, or SVG files.
- Verify the sender – double-check email addresses and look out for suspicious language or errors.
- Use updated antivirus software – make sure real-time protection is on.
- Keep your system and software updated – install security patches regularly.
- Avoid clicking unknown links – especially those claiming urgent action or legal warnings.
- Use strong, unique passwords – and enable two-factor authentication where possible.
Source: https://thehackernews.com/2025/09/researchers-expose-svg-and-purerat.html