The good news of the day: Hacker replaces malware with antivirus! 😉
The Dridex banking trojan , widely used by cyber criminals to distribute malware, has been found to distribute security software!
type=”button” https://www.secnews.gr/97727/dridex-botnet-is-running-again/Learn everything about Dridex: They thought they had defeated it… but the Dridex botnet strikes again

Part of the Dridex banking Trojan botnet may have been hacked by an unknown Whitehat Hacker, who has replaced the malicious links with Avira Antivirus installers.
https://www.secnews.gr/
“The content behind the malware download [link] has been replaced, and it now distributes the [legitimate], up-to-date Avira web installer instead of the usual Dridex loader,” explained Avira malware expert Moritz Kroll.
Avira believes that a white hat hacker or hackers may have hacked some of the infected web servers, using the same flaws that the malware authors used, and then replaced the malicious code with the Avira installer.
So, once someone gets infected, instead of “receiving” the Dridex malware, they will get a valid, signed copy of Avira antivirus software.
https://www.secnews.gr/101010/hacking-%cf%83%cf%84%ce%bf-%cf%85%cf%80%ce%bf%cf%85%cf%81%ce%b3%ce%b5%ce%af%ce%bf-%ce%b5%ce%bd%ce%ad%cf%81%ce%b3%ce%b5%ce%b9%ce%b1%cf%82-%cf%84%cf%89%ce%bd-%ce%b7%cf%80%ce%b1-%ce%b1%cf%80%cf%8c-%cf%85/See also: Hacking at the US Department of Energy by an employee!
“We still don’t know exactly who is doing this to our installer and why – but we have some theories,” Kroll said. “This is definitely not something we do ourselves.”
Although the motives behind this distribution of Avira software are still unclear, such actions are considered illegal in many countries, Kroll said.
