Skip to main content

Downloaders beware! Hackers just released StrongPity, a fake file-compression tool

New malware called StrongPity targets web surfers looking for the popular tools WinRAR and TrueCrypt, Security firm Kaspersky Lab revealed on Monday. The former is a file compression program, and the latter was once an open-source, on-the-fly encryption tool. StrongPity poses as installers for these two tools, and will provide attackers complete control of the victim’s system once installed.

According to Kaspersky Lab, the StrongPity attack is found mainly in Italy and Belgium, but the malware has also hit people in Turkey, North Africa, and the Middle East. On the WinRAR front, the malware is served up on fake websites that use two transposed letters in their domain names to resemble an authentic installer site. The file’s link on the fake domain is then provided to a legitimate WinRAR distributor site.

Recommended Videos

“Kaspersky Lab data reveals that in the course of a single week, malware delivered from the distributor site in Italy appeared on hundreds of systems throughout Europe and Northern Africa/Middle East, with many more infections likely,” the firm said. “Over the entire summer, Italy (87 percent), Belgium (5 percent) and Algeria (4 percent) were most affected. The victim geography from the infected site in Belgium was similar, with users in Belgium accounting for half (54 percent) of more than 60 successful hits.”

Please enable Javascript to view this content

Kaspersky Lab first saw this method taking place in Belgium on May 28. Prior to that, the security firm witnessed an Italian WinRAR distribution site directly handing out the fake WinRAR installer instead of linking to an impostor site. The good news here is that all affected WinRAR distribution sites have removed the infected file and/or fraudulent mirror links. The bad news is that the StrongPity attack is still ongoing.

What’s surprising it that StrongPity is presently attacking its victims through TrueCrypt installers. Development of this tool ended in May 2014 once Microsoft pulled the plug on Windows XP’s life support. TrueCrypt was no longer needed because Microsoft baked support for encrypted disks and virtual disk images into Windows Vista and newer versions. Thus, the only service the TrueCrypt developer provides now concerns the steps involved in migrating from the TrueCrypt format to BitLocker.

The firm said on Monday that the infected TrueCrypt installer was still active at the end of September. Apparently there is only one fraudulent TrueCrypt website handing out the infected installer, which experienced increased activity in May, claiming 95 percent of its victims in Turkey.

Kurt Baumgartner, principal security researcher at Kaspersky Lab, made the initial announcement regarding StrongPity’s discovery in a paper presented during the Virus Bulletin 2016 conference. He said that StrongPity is similar to Crouching Yeti/Energetic Bear that trojanized legitimate IT software installers and compromised “genuine distribution sites.” This type of attack is an “unwelcome and dangerous” trend that needs to be addressed by the security industry, he added.

In addition to completely taking over a victim’s computer, hackers behind the StrongPity attack can also steal the contents of a hard drive, and download additional modules that will scoop up the infected PC’s communications and contacts. Naturally, Kaspersky Lab software will detect and remove the StrongPity malware.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Need a budget-friendly laptop? Get this Asus deal at Walmart
The Asus VivoBook 15 laptop open on a white background.

You don't need to spend over a thousand dollars to end up with a dependable device from laptop deals -- you just need to be patient in waiting for a budget-friendly offer that will still provide reliable performance. Here's one: the Asus Vivobook 15 for only $299 from Walmart, following a $100 discount on its original price of $399. We're not sure when it will go back to its regular price though, so we highly recommend finishing your purchase quickly as that could happen at any moment.

Why you should buy the Asus Vivobook 15 laptop
Let's get this out of the way -- at its affordable price, you can't expect the Asus Vivobook 15 to match the performance of the best laptops. The device, however, will prove to be a trustworthy daily companion for regular tasks such as doing online research and typing documents, as well as watching some streaming shows when you're taking a break. It runs on the 12th-generation Intel Core i5 processor, Intel UHD Graphics, and 8GB of RAM, which will be more than enough for these activities. The laptop also ships with a 256GB SSD for ample storage space for your files, and it's got Windows 11 Home pre-installed.

Read more
Apple CEO should do a Steve Jobs on Siri delay, analyst says
Invoking Siri on iPhone.

Apple CEO Tim Cook should go public to explain the delay in integrating advanced Siri capabilities across its ecosystem, rather than Apple releasing the news quietly via a tech site last week, according to prominent Apple analyst Ming-Chi Kuo.

The tech giant showcased an AI-powered Siri at its WWDC event in 2024, as part of its Apple Intelligence initiative. While the virtual assistant does now have some AI smarts, the more advanced features -- including personalized responses, task completion across multiple apps, and on-screen awareness --have been delayed until next year at the earliest.

Read more
Nvidia claims RTX 5000 shipped better than 4000 but gamers are still waiting
The RTX 5090 sitting on a pink background.

Nvidia is trying to make its GeForce RTX 5000 series seem more impressive to the media by suggesting that the latest GPUs are selling better than the previous generation. However, many pundits aren’t buying the claim.

PC Mag pondered whether Nvidia has orchestrated a “paper launch” of the RTX 5000 series, suggesting that there might not be much of a product available for consumers. The majority of the people with their hands on the GPUs, especially the high-end models such as the 5090 and 5080 appear to be reviewers, influencers, and other determined enthusiasts as opposed to everyday gamers, who are still using prior generation GPUs at higher rates.

Read more