
FakeCrack: Malware that passwords, credit cards, and crypto wallets your is promoted through search results for a pirated copy of the Windows optimization program CCleaner Pro.
This new malware campaign is called “FakeCrack” and was discovered by Avast analysts, who report that they detect an average of 10,000 infection attempts every day from their customers’ telemetry data. Most of these victims are based in France, Brazil, Indonesia, and India.
The malware distributed in this campaign is a powerful information stealer that can collect personal data and cryptocurrency assets and route internet traffic through data extraction servers.
Black Hat SEO
Hackers follow Black Hat SEO to rank malware high in Google search results so that more people can be scammed.

Thelure Avast sees is a cracked version of Windows CCleaner Pro, a popular Windows system cleaner and performance optimizer that is still considered a “must-have” utility by many users.
The poisoned search results lead the victim to various websites that eventually display a landing page offering to download a ZIP file. This landing page is usually hosted on a legitimate file hosting platform such as filesend.jp or mediafire.com. The ZIP is password protected using a weak PIN, such as “1234”, which exists simply to protect the payload from virus detection. The file is usually named “setup.exe”
Dangerous malware steals information via Windows CCleaner Pro
Malware victims are tricked into installing attempts to steal information stored in web browsers, such as account passwords, saved credit cards , and cryptocurrency wallet credentials.
Additionally, it monitors the clipboard for copied wallet addresses and replaces them with those under the control of the malware operators to divert payments. This clipboard hijacking feature works with various cryptocurrency addresses, including those for Bitcoin, Ethereum, Cardano, Terra, Nano, Ronin, and Bitcoin Cash
