216.73.217.80

From a Fake AnyDesk Installer to MetaStealer

· Published 30/08/2025 09:10 · Modified 01/09/2025 08:29

Export JSON

Essential information

Published
30/08/2025 09:10
Modified
01/09/2025 08:29
Tags
2025-08-30 anydesk clickfix cloudflare turnstile filefix metastealer social engineering windows file explorer
Related entities
4 techniques (mitre), 1 malware

Description

A recent attack mimicking tactics used a fake installer to deploy . The infection chain involved a fake lure, Windows search protocol, and an MSI package disguised as a PDF. Unlike traditional attacks, this variant redirected users to instead of the Run dialog box. The attack cleverly grabbed the victim's hostname and ultimately aimed to drop , a commodity infostealer known for harvesting credentials and stealing files. This incident highlights the evolving nature of attacks and the need for updated security measures and user education.

External references