Fake CNN and Avast downloads hand PCs to attackers

A website that copies CNN's homepage closely enough that most visitors would not look twice is telling them to install "the new CNN app". The download has nothing to do with CNN. It is O&O Syspectr, a genuine, digitally signed remote administration tool that IT departments buy to manage staff computers, and the copy being handed out is already registered to somebody else's account.

Researchers at Malwarebytes found the same installer behind lookalike pages for the antivirus vendor Avast and the media centre app Stremio, and behind a fake cryptocurrency mining browser game. Anyone who runs it gives the operator of that Syspectr account remote control of their Windows PC: the ability to browse files, run commands, install more software and change the system as though sitting in front of it.

Why antivirus does not stop it

Every file in the campaign is real, signed software from O&O Software GmbH, a legitimate German company. Nothing is patched, packed or trojanised, so there is no malicious code for a scanner to find. Security software is built to detect malware, not to flag a properly signed business tool because of the page it arrived from. That is the whole point of the technique, and it is the same logic behind the ransomware crews who bring their own remote monitoring tools into a network rather than write an implant.

The remote control features are not available on free Syspectr accounts, so the operators were paying for a subscription to run this.

How the sites are linked

Each Syspectr installer carries the account ID of whoever generated it, embedded in the filename, which is what let Malwarebytes tie the lures together. The CNN, Avast and Stremio files all share one account ID, so they came from a single account and were simply reskinned for different audiences. The fake mining game distributes an installer carrying a second, different ID, which points either to another operator copying the playbook or to the same group running a spare account. Malwarebytes set out the full picture in the original report.

The pattern is now routine on the download side of the criminal economy. IntelFusions covered fake Mac download pages that hide themselves from security scanners last week, and a campaign using fake game downloads to spread an infostealer in July.

The ten second check

Right click any installer you are unsure about, open Properties, then the Details tab, and read the File description and Product name fields. On every file in this campaign both say O&O Syspectr, next to a copyright notice for O&O Software GmbH. A filename can be changed by anyone passing the file around; those embedded fields come from the signed software itself, and editing them would break the signature.

What to do

Download software only from the vendor's own site rather than from a search result or an ad. If you find O&O Syspectr installed and did not set it up, remove it through Settings then Apps and run a full antivirus scan, and change the passwords for anything you used on that machine afterwards, from a different device. Defenders should treat an unexpected Syspectr install the way they would any unauthorised remote management agent.

O&O moved quickly once told. The company disabled Remote Desktop and Remote Console for free accounts within days, restricting both to paid plans, then identified and suspended the abusive accounts and blocked them from adding new devices. Its own analysis found the attackers used only Remote Console.

Indicators of compromise

Account ID 4693fd-d903-4791-8f58-975261c93ca2: app[.]cnn-news[.]net serving CNN_App.setupad4693fd-d903-4791-8f58-975261c93ca2.exe, avast-premium[.]shop serving AVAST_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe, and stremiotv[.]online serving Stremio_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe. Account ID 9158bf2a-ff25-4290-b96c-2dc5eb310391: syncminer[.]xyz and idleminer[.]pro, both serving oo-syspectr-setup9158bf2a-ff25-4290-b96c-2dc5eb310391.exe.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions