Close Menu
  • Homepage
  • News
  • Cloud & AI
  • ECommerce
  • Entertainment
  • Finance
  • Opinion
  • Podcast
  • Contact

Subscribe to Updates

Get the latest technology news from TechFinancials News about FinTech, Tech, Business, Telecoms and Connected Life.

What's Hot

Salesforce Appoints Nick Christodoulou As Area VP Of Sales For Africa

2026-02-02

Why South Africa Cannot Afford To Wait For Healthcare Reform

2026-02-02

How is Technology Used in Cricket?

2026-02-02
Facebook X (Twitter) Instagram
Trending
  • Salesforce Appoints Nick Christodoulou As Area VP Of Sales For Africa
Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp RSS
TechFinancials
  • Homepage
  • News
  • Cloud & AI
  • ECommerce
  • Entertainment
  • Finance
  • Opinion
  • Podcast
  • Contact
TechFinancials
Home»Security»Surge In Malware Infections Linked To Malvertising Campaigns Distributing FakeBat Loader
Security

Surge In Malware Infections Linked To Malvertising Campaigns Distributing FakeBat Loader

NUMOZYLOD collects detailed system information, including operating system specifics, domain membership, and installed antivirus software.
Gugu LourieBy Gugu Lourie2024-08-20Updated:2024-08-20No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Malware
Malware. Image by DC Studio on Freepik
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

In a troubling development, cybersecurity experts have identified a sharp increase in malware infections, traced back to deceptive online ads that are spreading a malicious software loader known as FakeBat. These covert campaigns are catching users off guard, leading to widespread security breaches.

Since mid-2023, Mandiant Managed Defense has responded to a surge in malware infections originating from malvertising campaigns.

“These attacks are opportunistic in nature, targeting users seeking popular business software. The infection utilizes a trojanized MSIX installer, which executes a PowerShell script to download a secondary payload,” the Mandiant Managed Defense team said in a technical report.

“Our research into NUMOZYLOD reveals an interesting glimpse into the growing and thriving underground economy, where threat actors actively seek out partners to fulfill the supply and demand for specialized tools and services for their objectives. It also highlights how threat actors are exploiting MSIX to covertly bundle and distribute malware alongside legitimate software.”

Mandiant tracks this PowerShell script as NUMOZYLOD and attributes its distribution to UNC4536, a threat actor operating under the moniker “eugenfest.” The actor is part of a Malware-as-a-Service (MaaS) operation, distributing malware such as ICEDID, REDLINESTEALER, CARBANAK, LUMMASTEALER, or ARECHCLIENT2.

“Our research into NUMOZYLOD reveals an interesting glimpse into the growing and thriving underground economy, where threat actors actively seek out partners to fulfill the supply and demand for specialized tools and services for their objectives,” said Mandiant.

“It also highlights how threat actors are exploiting MSIX to covertly bundle and distribute malware alongside legitimate software.”

NUMOZYLOD is also known as FakeBat, EugenLoader and PaykLoader.

Mandiant added that UNC4536’s modus operandi involves leveraging malvertising to distribute trojanized MSIX installers disguised as popular software like Brave, KeePass, Notion, Steam, and Zoom. UNC4536 operates primarily as a malware distributor, with FakeBat serving as a vehicle to deliver next-stage payloads to their business partners, such as FIN7.

“These trojanized MSIX installers are hosted on websites designed to mimic legitimate software hosting sites, luring users into downloading them.”

NUMOZYLOD collects detailed system information, including operating system specifics, domain membership, and installed antivirus software. Some variants also capture the host’s public IPv4 and IPv6 addresses and transmit this data to its command and control (C2) server.

In some variants, NUMOZYLOD creates a shortcut(.lnk) in the StartUp folder as its persistence.

“As a part of a Malware-as-a-Service (MaaS) operation, NUMOZYLOD completes its mission upon the successful deployment of the second-stage malware from its C2 server and hands it over to its buyer for the subsequent mission,” said Mandiant.

Cybercriminals FakeBat Loader Malvertising Malware Infections online ads
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Gugu Lourie
  • Website

Related Posts

South Africa’s New Immigration Policy Takes A Digital Direction – Will It Succeed?

2026-01-29

South Africa Enters 2026 with a More Stable and Reliable Power System

2026-01-12

ShoveBike Electric Bikes Power Township-Owned Supply Chain Pilot

2025-12-19

Australia’s Social Media Ban Is Now In Force. Other Countries Are Closely Watching What Happens

2025-12-11

Tshepo Khoza Gets 6-Year Sentence In SAPS DNA Tender Tax Fraud

2025-12-09

Get S-Class Tech For Less: Chinese Cars Challenge R3M Luxury

2025-12-04

Humanising Tech Means Designing For African Reality, Says Telkom CMO

2025-12-01

Africa’s Graduate Talent: The Future Of Early-Career Hiring In A Remote World

2025-11-26

Volvo Car South Africa Unveils The New XC60

2025-11-14
Leave A Reply Cancel Reply

DON'T MISS
Breaking News

SA Auto Industry At Crossroads: Cheap Imports Threaten Future

Government must urgently finalise new energy vehicles policy, refine tariffs and deploy anti-dumping measures to…

Paarl Mall Gets R270M Mega Upgrad

2026-02-02

Huawei Says The Next Wave Of Infrastructure Investment Must Include People, Not Only Platforms

2026-01-21

South Africa: Best Starting Point In Years, With 3 Clear Priorities Ahead

2026-01-12
Stay In Touch
  • Facebook
  • Twitter
  • YouTube
  • LinkedIn
OUR PICKS

What’s Stopping Sunny South Africa’s Solar Industry?

2026-02-02

How a Major Hotel Group Is Electrifying South Africa’s Travel

2026-01-29

The EX60 Cross Country: Built For The “Go Anywhere” Attitude

2026-01-23

Mettus Launches Splendi App To Help Young South Africans Manage Their Credit Health

2026-01-22

Subscribe to Updates

Get the latest tech news from TechFinancials about telecoms, fintech and connected life.

About Us

TechFinancials delivers in-depth analysis of tech, digital revolution, fintech, e-commerce, digital banking and breaking tech news.

Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp Reddit RSS
Our Picks

Salesforce Appoints Nick Christodoulou As Area VP Of Sales For Africa

2026-02-02

Why South Africa Cannot Afford To Wait For Healthcare Reform

2026-02-02

How is Technology Used in Cricket?

2026-02-02
Recent Posts
  • Salesforce Appoints Nick Christodoulou As Area VP Of Sales For Africa
  • Why South Africa Cannot Afford To Wait For Healthcare Reform
  • How is Technology Used in Cricket?
  • SA Auto Industry At Crossroads: Cheap Imports Threaten Future
  • Stablecoins: The Quiet Revolution South Africa Can’t Ignore
TechFinancials
RSS Facebook X (Twitter) LinkedIn YouTube WhatsApp
  • Homepage
  • Newsletter
  • Contact
  • Advertise
  • Privacy Policy
  • About
© 2026 TechFinancials. Designed by TFS Media. TechFinancials brings you trusted, around-the-clock news on African tech, crypto, and finance. Our goal is to keep you informed in this fast-moving digital world. Now, the serious part (please read this): Trading is Risky: Buying and selling things like cryptocurrencies and CFDs is very risky. Because of leverage, you can lose your money much faster than you might expect. We Are Not Advisors: We are a news website. We do not provide investment, legal, or financial advice. Our content is for information and education only. Do Your Own Research: Never rely on a single source. Always conduct your own research before making any financial decision. A link to another company is not our stamp of approval. You Are Responsible: Your investments are your own. You could lose some or all of your money. Past performance does not predict future results. In short: We report the news. You make the decisions, and you take the risks. Please be careful.

Type above and press Enter to search. Press Esc to cancel.

Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.