TookPS distributed under the guise of UltraViewer, AutoCAD, and Ableton
April 3, 2025, 6:31 p.m.
Description
A malware campaign is distributing the TookPS downloader by impersonating popular software like UltraViewer, AutoCAD, SketchUp, Ableton, and Quicken. The malware establishes an SSH tunnel for remote access and deploys additional payloads like TeviRat and Lapmon backdoors. The attackers gain full system control through various methods. The campaign targets both individuals and organizations, using domains registered in early 2024. Users are advised to avoid downloading pirated software, while organizations should implement strict security policies and conduct regular awareness training.
Tags
Date
- Created: April 3, 2025, 3:03 p.m.
- Published: April 3, 2025, 3:03 p.m.
- Modified: April 3, 2025, 6:31 p.m.
Indicators
- 99bdf65cd25e4c9accfa75df21137f503a0460f46f9c606f9732f26546238e9d
- 62c78826159ab95695740cf00c1a48b7365048a8db6556fe6b272dcd1796c1d6
- 435f44f8a3d5cc03d6a95d5295dc8a7ecf44ade26add5c9ac1f47f8a609a36dd
- 3e3e34d158db5a552483e76bb895b9d6e275b8c2c41058f87e0462e2b9a4b842
- 88.119.175.190
- 88.119.175.184
- 88.119.175.187
- ultraviewer.icu
- ultraview-ramotepc.top
- twomg.xyz
- tukeps2ld.online
- sketchup-i3dmodels-download.top
- pstuk.xyz
- polysoft.org
- inreport2.xyz
- inrep.xyz
- autocad-cracked.com
Additional Informations
- tuntun2.digital
- tu02n.website
- downloader.monster
- download.monster
- bsrecov4.digital