#TookPS
🖥️ Kaspersky, UltraViewer ve AutoCAD gibi popüler yazılımları taklit eden sahte sitelerle yayılan TookPS Truva Atı tehdidine karşı kullanıcıları uyardı.

www.teknolojiningundemi.com/haber/244979...
Sahte yazılımlar üzerinden tehlike: TookPS Truva Atı yayılıyor
Kaspersky, UltraViewer ve AutoCAD gibi popüler yazılımları taklit eden sahte sitelerle yayılan TookPS Truva Atı tehdidine karşı kullanıcıları uyardı.
www.teknolojiningundemi.com
April 8, 2025 at 1:47 PM
TookPS, a malicious downloader, is being spread via fake websites by cybercriminals under the guise of software such as AutoCAD, SketchUp, Ableton, and UltraViewer.

#UltraViewer #AutoCAD #SketchUp #Ableton #TookPS #Malware
TookPS Malware Impersonates UltraViewer, AutoCAD, SketchUp, Ableton Software
Novel fake websites campaign advertises free downloads for apps such as remote desktop services, 3D modeling, and more to disseminate malware.
www.technadu.com
April 4, 2025 at 2:04 PM
Your printer shouldn't be delivering ransom notes. 🖨️🚨

The XEntry Team is taking ransomware to the physical world, hijacking network printers in Latin America to print out extortion demands after locking systems with BitLocker.

Beyond the encryption, they're using OkoSpyware and TookPS to steal...
Analog extortion: hackers hijack office printers to deliver ransom notes
Your printer shouldn't be delivering ransom notes. 🖨️🚨 The XEntry Team is taking ransomware to the physical world, hijacking network printers in Latin America to print out extortion demands after loc
www.alextech.ai
July 24, 2026 at 5:17 PM
Beveiligingsonderzoekers waarschuwen voor geavanceerde OkoBot-malware gericht op

Sinds januari 2026 waarschuwen beveiligingsonderzoekers voor de malware OkoBot. Deze malware wordt beschouwd als een doorontwikkeling van de TookPS-campagne, die in 2025 werd ontdekt. TookPS verspreidde schadel...
Beveiligingsonderzoekers waarschuwen voor geavanceerde OkoBot-malware gericht op cryptodiefstal
Sinds januari 2026 waarschuwen beveiligingsonderzoekers voor de malware OkoBot. Deze malware wordt beschouwd als een doorontwikkeling van de TookPS-campagne, die in 2025 werd ontdekt. TookPS verspreidde schadelijke software via nepwebsites, waarmee andere virussen werden geïnstalleerd. OkoBot is echter geavanceerder en makkelijker te hergebruiken, waardoor andere hackers het 'framework' kunnen kopiëren voor hun eigen aanvallen. Een besmetting met OkoBot kan beginnen met het uitvoeren van schadelijke opdrachten. Besmette apps die via platforms zoals GitHub worden verspreid, kunnen een 'achterdeur' op een computer installeren. OkoBot kan vervolgens schadelijke browser-extensies installeren en...
newsfacts.info
July 20, 2026 at 7:01 PM
OkoBot uses ClickFix lures and fake GitHub repos to deploy 20+ payloads stealing crypto seed phrases and credentials. The campaign evolved from TookPS and has heavily targeted Brazil. #OkoBot #Brazil #TookPS
New OkoBot framework deploys 20 payloads to steal data, crypto
OkoBot is a malicious framework that uses ClickFix attacks and fake GitHub software repositories to deliver more than 20 payloads aimed at stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. Kaspersky says the campaign evolved from TookPS, uses multiple stages including an SSH bot, and has heavily targeted users in Brazil while remaining active globally. #OkoBot #TookPS #Kaspersky #SeedHunter #Rilide
www.hendryadrian.com
July 16, 2026 at 11:30 PM
Kaspersky tracks OkoBot, a multi-stage malware framework using TookPS, SSH tunneling, keylogging, and spyware to steal crypto wallets and credentials. Active in 25+ countries, with 20+ payloads. #Russia #OkoBot #TookPS
OkoBot: new sophisticated malware framework targets cryptocurrency users
Kaspersky identified the active OkoBot campaign, a multi-stage framework that uses TookPS, SSH tunneling, browser extension theft, keylogging, and spyware to steal cryptocurrency wallets and other credentials. The operation has evolved since 2025, now distributing over 20 payloads and targeting victims in more than 25 countries while remaining active. #TookPS #OkoBot #TeviRAT #Rilide #Volume2 #SeedHunter #OkoSpyware
www.hendryadrian.com
July 15, 2026 at 7:00 PM
OkoBot hooks Ledger Live and Trezor Suite to slip a fake seed-phrase screen right into the real wallet app. https://intel.threadlinqs.com/threat/TL-2026-1383 #ThreatIntel #OkoBot #SeedHunter #TookPS
July 15, 2026 at 5:25 PM
OkoBot hides in a hijacked volume-control app and quietly harvests your crypto wallet seed phrases. https://intel.threadlinqs.com/threat/TL-2026-1363 #ThreatIntel #OkoBot #TookPS #TeviRAT
July 15, 2026 at 10:38 AM
Hackers spread TookPS malware via fake software sites, targeting users with backdoors for remote access under popular brand disguises.
Fake Software Sites Spreading Dangerous TookPS Trojan, Experts Warn
Hackers spread TookPS malware via fake software sites, targeting users with backdoors for remote access under popular brand disguises.
tech-ish.com
April 8, 2025 at 10:55 PM
TookPS distributed under the guise of UltraViewer, AutoCAD, and Ableton
TookPS distributed under the guise of UltraViewer, AutoCAD, and Ableton
securelist.com
April 5, 2025 at 6:39 PM
Kaspersky Uncovers Crypto Theft Malware on SourceForge

Cybercriminals exploit SourceForge’s open platform, using projects like officepackage to distribute crypto theft malware. Sophisticated malware like ClipBanker and TookPS is delivered through pirated software via redirects and nested files.…
Kaspersky Uncovers Crypto Theft Malware on SourceForge
Cybercriminals exploit SourceForge’s open platform, using projects like officepackage to distribute crypto theft malware. Sophisticated malware like ClipBanker and TookPS is delivered through pirated software via redirects and nested files. SourceForge maintains its position as a thriving center for developers and user as an open-source software platform. The hosting platform provides software distribution alongside project services, which draws multiple types of users to its platform. Open platforms like SourceForge and GitHub make software development accessible but expose users to potential security dangers. Kaspersky researchers found proof that cybercriminals have perfected their methods to steal cryptocurrencies while hijacking systems through the “officepackage” project on SourceForge.
buzzleaktv.com
April 10, 2025 at 3:03 AM
Beware fake AutoCAD, SketchUp sites dropping malware

Malware peddlers are saddling users with the TookPS downloader and the Lapmon and TeviRat backdoors via malicious sites that mimic official ones and ostensibly offer legitimate software for download, Kaspersky researchers have…

#hackernews #news
Beware fake AutoCAD, SketchUp sites dropping malware
Malware peddlers are saddling users with the TookPS downloader and the Lapmon and TeviRat backdoors via malicious sites that mimic official ones and ostensibly offer legitimate software for download, Kaspersky researchers have warned. Malicious websites (Source: Kaspersky) The list of impersonated software includes: UltraViewer (remote desktop software) AutoCAD (2D and 3D computer-aided design software app) SketchUp (3D modeling software) Ableton (music production software) Quicken (personal finance app) “To protect against these attacks, users are advised …
www.helpnetsecurity.com
April 4, 2025 at 5:51 AM
Kaspersky Temukan Malware Baru, Menyamar Jadi Aplikasi 3D Populer! – Viva – https://bit.ly/43OVXy7 – #Opsitek #Techno #Tekno

April 11, 2025 at 02:59AM Aplikasi, Kaspersky Temukan Malware Baru, Menyamar Jadi Aplikasi 3D Populer!  Gadget Jumat, 11 April 2025 - 01:00 WIB Gadget – Serangan siber…
Kaspersky Temukan Malware Baru, Menyamar Jadi Aplikasi 3D Populer! – Viva – https://bit.ly/43OVXy7 – #Opsitek #Techno #Tekno
April 11, 2025 at 02:59AM Aplikasi, Kaspersky Temukan Malware Baru, Menyamar Jadi Aplikasi 3D Populer!  Gadget Jumat, 11 April 2025 - 01:00 WIB Gadget – Serangan siber kembali mengintai pengguna perangkat lunak dengan metode yang semakin canggih. Kaspersky baru-baru ini menemukan situs web palsu yang menyebarkan malware berbahaya berkedok perangkat lunak desain 3D populer. Malware yang diberi nama Trojan-Downloader Tookps ini mulai terdeteksi sejak Maret 2025, dan telah menargetkan pengguna individu hingga organisasi bisnis.
pastikubisa9.wordpress.com
April 10, 2025 at 8:04 PM
#TookPS malware abuses TeamViewer via DLL sideloading—evades detection while stealing credentials. Active in enterprise networks.

Tactics: securityonline.info/dll-sideload... #CyberSecurity #Malware
DLL Sideloading Exposed: TookPS Hides with TeamViewer
Uncover the threat posed by the TookPS downloader, a malware strain exploiting popular software and fraudulent websites.
securityonline.info
April 3, 2025 at 9:17 AM
Feed: "Techish Kenya"
By: The Analyst on Tuesday, April 8, 2025
Fake Software Sites Spreading Dangerous TookPS Trojan, Experts Warn
Hackers spread TookPS malware via fake software sites, targeting users with backdoors for remote access under popular brand disguises.
tech-ish.com
April 9, 2025 at 1:10 AM
Hackers Leveraging DeepSeek & Remote Desktop Apps to Deliver TookPS Malware Cybersecurity exp...

https://cybersecuritynews.com/hackers-leveraging-deepseek-to-deliver-tookps/

#cyberf="/hashtag/Cyber" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Cyber #security/hashtag/Security" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Security #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Threats #cyber #security #cyber #security #news

Event Attributes
Hackers Leveraging DeepSeek & Remote Desktop Apps to Deliver TookPS Malware
cybersecuritynews.com
April 3, 2025 at 1:15 PM
Hackers Exploit DeepSeek and RDP Tools to Spread TookPS Malware Cybersecurity researchers have un...

https://cyberpress.org/hackers-exploit-deepseek-and-rdp-tools/

#Cyber #security/hashtag/Security" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#Security #newsef="/hashtag/News" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#News #Cybersecurity #DeepSeek #Malware #Cyber #Security #Cyber #security #news

Event Attributes
April 2, 2025 at 7:07 PM
Hackers Use DeepSeek and Remote Desktop Apps to Deploy TookPS Malware A recent investigation by c...

https://gbhackers.com/hackers-use-deepseek-and-remote-desktop-apps/

#Cyberf="/hashtag/cyber" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#cyber #Security/hashtag/security" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#security #Cyber #Security #News #DeepSeek #Malware

Event Attributes
April 2, 2025 at 6:18 PM
📢 TookPS: DeepSeek isn’t the only game in town
https://securelist.com/tookps/116019/
April 2, 2025 at 10:02 AM
No solo DeepSeek: TookPS también se propaga por otras vías

Vía: @kasperskylab.bsky.social
TookPS se camufla como UltraViewer, AutoCAD y Ableton
El cargador malicioso TookPS no solo se distribuye bajo la apariencia de DeepSeek, sino que también se camufla como UltraViewer, AutoCAD, SketchUp, Ableton y otros programas populares.
securelist.lat
April 3, 2025 at 3:52 PM