Attackers used compromised websites, especially WordPress installations, to display counterfeit browser and software update pages that tricked visitors into downloading malware. Researchers documented multiple variants of the tactic, including FakeUpdateRU, which replaced site files with a fake Google Chrome download page and distributed ZIP payloads tied to Zgrat and RedLine Stealer, and FakeSG, which injected JavaScript to serve browser-specific update lures that ultimately installed NetSupport RAT. In another related campaign, malicious code hidden in CSS through steganographic obfuscation reconstructed JavaScript that showed a fake Flash Player update and led victims to HTA/VBScript downloaders and PowerShell-based malware retrieval.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Sucuri described FakeUpdateRU as a widespread campaign compromising WordPress and other CMS sites to replace content with a fake Google Chrome update page. The campaign delivered ZIP archives linked by other researchers to Zgrat and RedLine Stealer, and attackers adapted after Google blocked many redirect domains.
Sucuri reported that intermediary domains used in the FakeUpdateRU delivery chain had all been registered within the prior two weeks. These chromium-themed domains were used to redirect victims from fake Chrome update pages to malware payloads.
Malwarebytes documented FakeSG as a distinct fake browser update campaign that mimicked SocGholish-style lures on hacked WordPress sites. The campaign used browser-specific templates and delivered NetSupport RAT through ZIP downloads or .url files that fetched obfuscated HTA payloads over WebDAV.
On June 22, AnFam17 observed a fake browser update campaign that leveraged Internet shortcut files as part of the delivery chain. Malwarebytes connected this activity to compromised WordPress sites and WebDAV-hosted HTA launchers delivering NetSupport RAT.
On June 5, SecurityAura described an unknown campaign using .hta payloads disguised as driver updates. Malwarebytes later cited this as related background to the broader fake-update activity around FakeSG.
Sucuri reported a campaign that hid malicious JavaScript in a CSS file fetched from polobear[.]shop, then displayed a fake Flash Player update lure from lopiax[.]us. The resulting ZIP/HTA/VBScript chain used PowerShell to download additional malware, including NetSupport RAT.
An archive named GeoIP.dat (1).zip was first uploaded to polobear[.]shop and contained scripts implementing a fake Flash Player update attack with bot, user-agent, and geographic filtering. The files suggested the operators were building reusable infrastructure for broad victim targeting.
The domain polobear[.]shop, later used to host a CSS-based steganographic malware delivery toolkit and related server-side components, was registered on this date. Sucuri linked it to fake Flash update activity that ultimately delivered malware including NetSupport RAT.
Hacked Steam accounts sent chat spam linking users to videomeo.pw, where a bogus Flash Player update executed a PowerShell-based infection chain. The final payload was a renamed NetSupport Manager client that connected to a NetSupport gateway for remote control.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
blog.sucuri.net
Open sourcemalwarebytes.com
Open sourceblog.sucuri.net
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.