Skip to main content

Adware posing as a private network client secretly takes screenshots

Adware stuffed into software you can freely download from the internet can secretly take screenshots of your desktop among other sneaky spyware-like capabilities. Dubbed as Zacinlo by Bitdefender, the adware first surfaced in 2012 and mostly targets Windows 10 PCs in North America. The adware was in its most “active” state at the beginning of 2018 since it emerged six years ago. 

Software you can download and use for free sometimes present free secondary software options during installation that you can use or decline. This secondary software is typically bundled to appease “sponsors” supposedly backing the free program you set out to download and install. Although free software can be good for your wallet, bundled software presented during installation could prove catastrophic.  

Recommended Videos

In this case, the adware poses as a free anonymous virtual private network (VPN) client called s5Mark you can install alongside the original software you intended to use. This VPN client provides a simple easy-to-read interface designed for non-technical web surfers. 

Please enable Javascript to view this content

But that client is just a decoy. When the Windows 10 device owner runs the fake VPN client for the first time, it downloads the actual adware components along with a rootkit: Malware that resides at the root of your PC before loading Windows 10. There is also another component called an “updater” that receives instructions and makes updates to the adware and rootkit when needed. 

During installation, the adware will temporarily disable Windows Defender. It can also detect and temporarily disable antivirus solutions from 13 different providers including Bitdefender, Kaspersky, Malwarebytes, Panda, Symantec, and more. The rootkit component is what scans the PC for an antivirus client in the initial installation stages and temporarily shuts them down so the remaining adware components download to the PC. 

The list of what Zacinlo can do is rather lengthy outside the screen capture component. It can stop processes in Windows 10 it deems as “dangerous” to its overall functionality. It can also inject custom JavaScript into secure HTTPS webpages visited by the device owner, re-direct web pages, send information about the desktop environment back to the hackers in charge of the campaign, uninstall and delete any Windows 10 service, and more. 

“We have identified at least 25 different components found in almost 2,500 distinct samples,” the security firm states. “While tracking the adware, we noticed some of the components were continuously updated with new functionalities, dropped altogether or integrated entirely in other components. This once again reinforces our initial assumption that the adware is still being developed as of the writing of this paper.” 

According to Bitdefender’s whitepaper, the winscr.exe component installed by the adware is what takes screenshots of your desktop. It can also send the hackers a list of the file locations of the applications that are set to run automatically when Windows starts and delete files used by processes and services. Other components in the adware’s payload include dataup.exe, regtool.exe, homepageoptimizer.exe, and more. 

The big red flag here is that despite infecting Windows-based PCs since 2012, the spyware won’t infest your PC unless you allow its installation. 

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
This cybersecurity disaster made Google’s top 10 searches of 2024
The blue screen of death in Windows.

Google recently released its Year in Search 2024, with a wide range of different topics reaching the top 10. Among major events like the Olympics and the U.S. presidential election is one name you may have forgotten about, but will remember for the chaos it caused. I'm talking, of course, about CrowdStrike, the cybersecurity firm founded in 2011 in Austin, Texas — the same one that was (at least partially) responsible for the largest IT outage ever.

So, what did CrowdStrike do exactly to earn its spot on the list? In a nutshell, it's responsible for the faulty code that meddled with core functions on the affected Windows computers. The error displayed messages on users' PCs saying: "Your PC ran into a problem and needs to restart." The result was downed PCs across the country, affecting a wide range of industries, but most notably, airports. From an IT perspective, this was a nightmare scenario.

Read more
Get a MacBook Air M2 for a massive $500 off at Best Buy
A woman working on a 2023 MacBook Air with M2 chip.

For great laptop deals, Best Buy is always a good place to look. Right now, it has one of the best MacBook deals with a chunky $500 off the Apple MacBook Air M2 with 15-inch screen. The laptop normally costs $1,899, but right now you can buy it for $1,399, saving a huge $500. The laptop might not have the latest processor, but it’s still highly competent for many, many purposes. It’ll make a great gift for a loved one, but also a useful productivity tool for you too. Here’s all you need to know.

Why you should buy the Apple MacBook Air M2 15-inch
Still featuring in our look at the best MacBooks, the Apple MacBook Air M2 is a great laptop for experienced macOS users or anyone new to the ecosystem. This particular model has the M2 chip with an 8-core CPU and up to 10-core GPU. It also has a 16-core Neural Engine for advanced machine learning tasks. Besides the CPU, the Apple MacBook Air M2 15-inch also has 16GB of RAM and 1TB of SSD storage, so it’s all set for providing everything you need.

Read more
Save $600 on the stylish Samsung Galaxy Book4 Pro at Best Buy today
The Samsung Galaxy Book4 Pro 360 2-in-1 laptop on a white background.

For super stylish laptop deals, check out what Best Buy has to offer. Today, you can buy the MacBook Pro rival — the Samsung Galaxy Book4 Pro 360 2-in-1 laptop — for $1,300 instead of $1,900. That’s a sizeable saving of $600, which makes this laptop far more tempting than it was at its regular price. The deal is unlikely to stick around for long, so hit the button fast if you know it’s for you. If you still want to know more, read on while we take you through what it offers.

Why you should buy the Samsung Galaxy Book4 Pro
You won’t see Samsung among the best laptop brands because the company mostly focuses on just a few models. However, that doesn’t mean the Samsung Galaxy Book4 Pro should be overlooked. We reviewed the Samsung Galaxy Book4 Ultra model and found it able to compete with the MacBook Pro in many ways.

Read more