New Vibe-Coded Malware Campaign Leverages Fake Tools, CDNs, and File Hosts
Key Takeaways A new malware campaign, dubbed “Vibe-Coded Malware,” is leveraging AI-assisted coding to rapidly generate diverse malicious tools. The campaign distributes over 443 fake...
Key Takeaways
- A new malware campaign, dubbed “Vibe-Coded Malware,” is leveraging AI-assisted coding to rapidly generate diverse malicious tools.
- The campaign distributes over 443 fake utility applications, including AI tools, game hacks, and VPNs, primarily via popular CDNs and file-sharing platforms.
- The core malware, WinUpdateHelper.dll, deploys cryptocurrency miners (Zephyr, Ravencoin), and in some cases, the SalatStealer infostealer or a Mesh Agent RAT.
- The United States, United Kingdom, and India are among the most affected countries.
The burgeoning field of AI-assisted coding, while offering substantial benefits to developers worldwide, has inadvertently opened new avenues for cybercriminals. A recent, large-scale malware campaign exemplifies this, demonstrating how threat actors are leveraging AI to accelerate malware creation and reduce the skill barrier required for sophisticated attacks.
Table Of Content
This emerging technique, colloquially known as “vibe coding”—where AI models generate code based on user descriptions—is now being weaponized against unsuspecting internet users. It enables malicious actors to rapidly produce a wide array of malware variants, fueling dangerous campaigns with unprecedented ease.
Campaign Uncovered: Scope and Distribution
In January 2026, cybersecurity analysts brought to light an extensive malware campaign involving over 443 malicious ZIP archives. These files were meticulously crafted to masquerade as legitimate and desirable software, such as AI image generators, voice changers, game cheats, Roblox script executors, VPN clients, graphics card drivers, ransomware decryptors, and even infostealer tools, enticing users to download them.
The distribution of these malicious files exploited widely-used and trusted platforms, including Discord, SourceForge, FOSSHub, MediaFire, and a dedicated site at mydofiles.com. This broad distribution strategy significantly amplified the campaign’s reach and made detection challenging.
McAfee analysts were instrumental in identifying this campaign, tracing its initial signs back to December 2024, with more recent observations indicating the incorporation of AI-generated scripting elements. Researchers uncovered 48 distinct variants of a malicious DLL named WinUpdateHelper.dll, which serves as the core infection engine across all instances.
These 48 variants are organized into 17 unique kill chains, each operating with its own command-and-control (C2) infrastructure. However, a critical error by the threat actors—sharing cryptocurrency wallet credentials across these chains—allowed researchers to track the financial proceeds of the operation.
The campaign demonstrated a global reach, impacting users in numerous countries. The United States experienced the highest infection rate, followed by the United Kingdom, India, Brazil, France, Canada, and Australia.
At the time of analysis, seven Bitcoin wallets linked to the operation held approximately $4,536 USD, with total received funds nearing $11,498 USD. Given that the campaign primarily targets privacy-focused cryptocurrencies like Monero and Zephyr, the actual financial gains are likely substantially higher.
More than 100 URLs were actively distributing this malware upon discovery, with approximately 61 hosted on Discord, 17 on SourceForge, and 15 on mydofiles.com. This extensive and fragmented distribution network poses significant challenges for containment efforts reliant solely on takedowns.
Inside the Infection Chain
The infection process begins when a user downloads and executes one of the trojanized ZIP archives. The initial executable within the archive is often benign, allowing it to bypass basic security scans. However, it surreptitiously loads WinUpdateHelper.dll, the malicious payload, in the background.
Upon execution, the DLL initiates a deceptive maneuver: it opens the victim’s web browser and redirects it to a page claiming a critical dependency is missing. The user is then prompted to download “DependencyCore.zip,” which installs unrelated third-party software, such as iTop Easy Desktop in one confirmed instance, serving as a diversion.
While the victim is preoccupied with the fake installation, WinUpdateHelper.dll establishes a connection to its command-and-control server. The C2 domain is dynamically generated using the system’s UNIX timestamp and refreshes every 58 days, a tactic designed to evade proactive blocking measures.
To maintain persistence on the compromised system, the malware registers a Windows service named “Microsoft Console Host,” configured to launch at every system boot. It then retrieves a PowerShell script that executes entirely in memory, a fileless technique that renders it invisible to disk-based antivirus scans.
The PowerShell script orchestrates a series of malicious actions. It first removes any older persistence entries to prevent conflicts. Subsequently, it adds the ProgramData folder to Windows Defender’s exclusion list, ensuring that subsequent malicious payloads can be deployed without detection.
The campaign’s primary objective then unfolds with the deployment of two cryptocurrency miners: one utilizes the CPU to mine Zephyr, while the other leverages the GPU to mine Ravencoin. The rewards from these mining operations are converted to Bitcoin before payout. In certain instances, the final payload observed has been the SalatStealer infostealer or a Mesh Agent remote access tool, indicating a diversified threat landscape.
What You Should Do
- Exercise extreme caution with downloads: Only download software from official vendor websites or trusted app stores. Avoid unofficial sources, torrents, or direct links from unverified websites.
- Verify software legitimacy: Before running any executable, especially after downloading a ZIP archive, consider checking file hashes against official sources if available, and scan with reputable antivirus software.
- Monitor system services: Regularly review active Windows services for unexpected or unfamiliar entries. Services like “Microsoft Console Host” that appear suspicious should be investigated.
- Be wary of dependency prompts: Treat unsolicited prompts to download “critical dependencies” as a significant warning sign, especially if they appear after running new software.
- Maintain updated security software: Ensure your antivirus and anti-malware solutions are always up-to-date with the latest definitions and configured for real-time protection.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.