Hackers are creating fake websites hosting trojanized software installers to trick unsuspecting users into downloading a malware downloader called Fruity, with the aim of installing remote trojan tools like the Remcos RAT.
See also: The race against time in ransomware attacks

The exact initial access vector used in the campaign is unclear, but could range from phishing to drive-by file downloads or malicious advertisements. Users who land on the fake website are prompted to download a ZIP installer package.
In addition to triggering the standard installation process, the installer secretly installs the Fruity malware, a Python-based malicious application that decompresses an MP3 file (“Idea.mp3”) to load an image file (“Fruit.png”) and trigger the multi-stage infection.
See also: Ukrainian hackers troll Russian navy, send malware to their phones
Fruity is also designed to bypass antivirus detection on the compromised host and ultimately launch the Remcos RAT payload using a technique called doppelgänging.

The attack sequence could be exploited to distribute all kinds of malware. Therefore, it is essential to adhere to the rule of downloading software only from trusted sources.
The development comes as Bitdefender revealed details of a malspam campaign that delivers the Agent Tesla malware to collect sensitive data from compromised endpoints.
See also: Android malware CherryBlos steals passwords using OCR
It also follows a rise in malicious advertising operations that have targeted customers and businesses with infected software that is promoted through search engine ads.
This includes a wave of new attacks called Nitrogen, which distribute fake ISO files using fake ads that pretend to be download pages for applications such as AnyDesk, WinSCP, Cisco AnyConnect, Slack , and TreeSize.
Information source: thehackernews.com
