Cybersecurity researchers at FortiGuard Labs have discovered a new threat called Vcurms malware that targets popular browsers and applications to steal login credentials and data. They highlight the importance of security updates and paying attention to emails.
See also: Malicious Google ads trick Mac users into installing Atomic Stealer malware

FortiGuard Labs recently discovered a new threat: a malware known as “Vcurms.” The attackers behind the Vcurms malware have employed sophisticated tactics, using email as their command and control center and leveraging public services like AWS and GitHub to store the malware. In addition, they have used a commercial protector to evade detection, suggesting a coordinated effort to maximize the malware’s impact.
This campaign primarily targets platforms with Java, posing a risk to any organization using such systems. The severity of the threat cannot be underestimated, as successful penetration gives attackers complete control over compromised systems.
The attackers’ methodology involves tricking users into downloading a malicious Java downloader, which helps spread the Vcurms malware and STRRAT, a trojan previously found to pose as a fake ransomware infection to steal data. These malicious emails typically pretend to be legitimate requests, prompting recipients to verify payment information and download malicious files hosted on AWS.
Once downloaded, the malware exhibits classic phishing, using fake names and encrypted strings to hide its malicious nature. In particular, it uses a class named “DownloadAndExecuteJarFiles.class” to facilitate the download and execution of additional JAR files, further extending the attacker.
The Remote Access Trojan (RAT) communicates with its command and control center via email, demonstrating a worrying level of sophistication. It establishes its persistence by copying itself to the Startup folder and uses various techniques to identify and track victims, including keystroke logging and password recovery functions.
See also: “TicTacToe Droppers” are used to distribute malware

Targets Popular Browsers and Applications
Additionally, Vcurms malware uses advanced obfuscation techniques, such as the Branchlock obfuscator, to evade detection and analysis. Despite these challenges, cybersecurity researchers continue to develop methods to decrypt and understand how Vcurms works.
Vcurms also exhibits significant similarities to the Rude Stealer, but differs in its unique transmission methods and targeted data acquisition. Its priority is to steal sensitive information from popular browsers such as Chrome, Brave, Edge, Vivaldi, Opera, OperaGX, Firefox, etc. and applications, including Discord and Steam.
In response to this threat, FortiGuard Labs recommends preventive measures, including installing up-to-date security solutions and network segmentation, as well as adhering to good password practices and being careful when handling email attachments, in a blog . post
See also: Malware families adapt to COM Hijacking technique
General malware protection guidelines
To protect your digital environment from malware, such as Vcurms, first, install a reliable antimalware program. This will help you detect and remove any malicious software that may have entered your system. Second, perform regular updates of your operating system and applications. Third, avoid downloading files from untrusted sources. Malware often hides inside files that seem harmless. Finally, use a virtual private network (VPN) to protect data . A VPN can hide your real IP address and encrypt your data, making it difficult for malware to work.
Source: hackread
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
