‘What started with someone potentially trying to remove the background from a selfie ended up with a custom .NET thief ripping through their browser passwords’: Experts warn that free photo editing tool may actually be dangerous malware


  • A fake photo tool ranked high in search results tricks users into running malware via ClickFix tactics
  • Victims are first infected with CastleLoader, which then deploys the NetSupport RAT and a customized CastleStealer
  • The campaign highlights how SEO poisoning and social engineering can turn simple tasks into credential theft and remote compromise

A website that promises to remove backgrounds from selfie photos is actually just dropping info-stealing malware on people’s computers, security researchers say.

Cyber ​​security experts at Huntress outlined how they discovered a website which, through SEO poisoning, managed to work its way to the top of search engine results pages. Therefore, when people search for background removal tools, there’s a good chance they’ll land on this particular, malicious website.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top