{"id":75880,"date":"2025-04-08T11:09:35","date_gmt":"2025-04-08T09:09:35","guid":{"rendered":"https:\/\/gulftech-news.com\/en\/?p=75880"},"modified":"2025-04-08T11:09:36","modified_gmt":"2025-04-08T09:09:36","slug":"kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software","status":"publish","type":"post","link":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/","title":{"rendered":"Kaspersky finds fake sites spreading Trojan-Downloader TookPS under the guise of popular software"},"content":{"rendered":"\n<p><strong>Kaspersky has uncovered that a Trojan-Downloader dubbed TookPS is being spread through malicious websites imitating popular remote access and 3D modeling software. First observed by Kaspersky experts in early March, this Trojan infects users\u2019 devices with backdoors, allowing for unauthorized stealth access to the victim\u2019s system.<\/strong><\/p>\n\n\n\n<p>Kaspersky Threat Research experts warn that users are being lured to fake websites that mimic official pages or falsely claim to offer free downloads of popular software, such as UltraViewer, AutoCAD, and SketchUp, commonly utilized both for business and personal purposes. <\/p>\n\n\n\n<p>However, when users click the \u2018download\u2019 buttons, they unknowingly get TookPS instead of the application they were looking for. The potential victims of this campaign could include both individuals and organizations.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"966\" height=\"397\" src=\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278\" alt=\"\" class=\"wp-image-75883\" srcset=\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278 966w, https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2-300x123.png?v=1744103278 300w, https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2-768x316.png?v=1744103278 768w\" sizes=\"auto, (max-width: 966px) 100vw, 966px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"950\" height=\"392\" src=\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image.png?v=1744103266\" alt=\"\" class=\"wp-image-75882\" srcset=\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image.png?v=1744103266 950w, https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-300x124.png?v=1744103266 300w, https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-768x317.png?v=1744103266 768w\" sizes=\"auto, (max-width: 950px) 100vw, 950px\" \/><\/figure>\n\n\n\n<p><em>Examples of malicious websites capitalizing on legitimate software brands<\/em><\/p>\n\n\n\n<p>Once on the device, TookPS runs a series of scripts and technical processes that allow attackers to install a backdoor on the victim\u2019s system, granting them hidden remote access and the ability to execute arbitrary commands.<\/p>\n\n\n\n<p>Based on technical analysis of the malicious files, Kaspersky researchers also believe that there may be other lures \u2014 for example, those capitalizing on well-known software brands such as Ableton (used for music production) or Quicken (used for personal finance management).<\/p>\n\n\n\n<p><em>\u201cEarlier, we discovered several malicious campaigns that used DeepSeek\u2019s brand as bait. One of the threats described was the TookPS. As we now observe, it isn\u2019t just pretending to be an AI tool, that was only the tip of the iceberg. This is a broader campaign, targeting both individuals and organizations, where malware is hidden under different guises to lure in as many potential victims as possible,\u201d explains Vasily Kolesnikov, security expert at Kaspersky. \u201cTo avoid falling victim to such attacks, we urge users to stay vigilant: always double-check links and websites, and avoid searching for pirated software online.\u201d<\/em><\/p>\n\n\n\n<p>Learn more in the technical report on <a href=\"https:\/\/securelist.com\/tookps\/116019\/\">Securelist<\/a>.<\/p>\n\n\n\n<p>Kaspersky shares the following recommendations to avoid general cyberthreats when surfing the internet:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Modern security solutions such as Kaspersky Next for organizations and Kaspersky Premium for individuals provide users with safe browsing features, protecting against dangerous websites, downloads and extensions.\u00a0<\/li>\n\n\n\n<li>It\u2019s safe practice to enter your web address directly into the web browser. If an email contains a link, instead of clicking the link, first hover over it to see if it looks accurate.\u00a0 If it looks okay, search for the link on your own versus linking to a website. Dangerous websites can look identical to authentic ones.\u00a0<\/li>\n\n\n\n<li>For organizations, Kaspersky advises implementing a robust security policy that prohibits downloading software from unverified or pirated sources. Regular cybersecurity training should also be conducted to ensure employees remain informed and alert to potential threats.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky has uncovered that a Trojan-Downloader dubbed TookPS is being spread through malicious websites imitating popular remote access and 3D modeling software. First observed by Kaspersky experts in early March, this Trojan infects users\u2019 devices with backdoors, allowing for unauthorized stealth access to the victim\u2019s system. Kaspersky Threat Research experts warn that users are being &hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1088,2034],"class_list":["post-75880","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-kaspersky-4","tag-tookps"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Kaspersky finds fake sites spreading Trojan-Downloader TookPS under the guise of popular software - Gulf Tech News<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Kaspersky finds fake sites spreading Trojan-Downloader TookPS under the guise of popular software - Gulf Tech News\" \/>\n<meta property=\"og:description\" content=\"Kaspersky has uncovered that a Trojan-Downloader dubbed TookPS is being spread through malicious websites imitating popular remote access and 3D modeling software. First observed by Kaspersky experts in early March, this Trojan infects users\u2019 devices with backdoors, allowing for unauthorized stealth access to the victim\u2019s system. Kaspersky Threat Research experts warn that users are being &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/\" \/>\n<meta property=\"og:site_name\" content=\"Gulf Tech News\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-08T09:09:35+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-08T09:09:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278\" \/>\n\t<meta property=\"og:image:width\" content=\"966\" \/>\n\t<meta property=\"og:image:height\" content=\"397\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"bessan helmi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"bessan helmi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/\",\"url\":\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/\",\"name\":\"Kaspersky finds fake sites spreading Trojan-Downloader TookPS under the guise of popular software - Gulf Tech News\",\"isPartOf\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278\",\"datePublished\":\"2025-04-08T09:09:35+00:00\",\"dateModified\":\"2025-04-08T09:09:36+00:00\",\"author\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\"},\"breadcrumb\":{\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#primaryimage\",\"url\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278\",\"contentUrl\":\"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278\",\"width\":966,\"height\":397},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/gulftech-news.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Kaspersky finds fake sites spreading Trojan-Downloader TookPS under the guise of popular software\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#website\",\"url\":\"https:\/\/gulftech-news.com\/en\/\",\"name\":\"Gulf Tech News\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/gulftech-news.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c\",\"name\":\"bessan helmi\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g\",\"caption\":\"bessan helmi\"},\"url\":\"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Kaspersky finds fake sites spreading Trojan-Downloader TookPS under the guise of popular software - Gulf Tech News","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/","og_locale":"en_US","og_type":"article","og_title":"Kaspersky finds fake sites spreading Trojan-Downloader TookPS under the guise of popular software - Gulf Tech News","og_description":"Kaspersky has uncovered that a Trojan-Downloader dubbed TookPS is being spread through malicious websites imitating popular remote access and 3D modeling software. First observed by Kaspersky experts in early March, this Trojan infects users\u2019 devices with backdoors, allowing for unauthorized stealth access to the victim\u2019s system. Kaspersky Threat Research experts warn that users are being &hellip;","og_url":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/","og_site_name":"Gulf Tech News","article_published_time":"2025-04-08T09:09:35+00:00","article_modified_time":"2025-04-08T09:09:36+00:00","og_image":[{"width":966,"height":397,"url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278","type":"image\/png"}],"author":"bessan helmi","twitter_card":"summary_large_image","twitter_misc":{"Written by":"bessan helmi","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/","url":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/","name":"Kaspersky finds fake sites spreading Trojan-Downloader TookPS under the guise of popular software - Gulf Tech News","isPartOf":{"@id":"https:\/\/gulftech-news.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#primaryimage"},"image":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#primaryimage"},"thumbnailUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278","datePublished":"2025-04-08T09:09:35+00:00","dateModified":"2025-04-08T09:09:36+00:00","author":{"@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c"},"breadcrumb":{"@id":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#primaryimage","url":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278","contentUrl":"https:\/\/gulftech-news.com\/en\/wp-content\/uploads\/2025\/04\/image-2.png?v=1744103278","width":966,"height":397},{"@type":"BreadcrumbList","@id":"https:\/\/gulftech-news.com\/en\/2025\/04\/08\/kaspersky-finds-fake-sites-spreading-trojan-downloader-tookps-under-the-guise-of-popular-software\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gulftech-news.com\/en\/"},{"@type":"ListItem","position":2,"name":"Kaspersky finds fake sites spreading Trojan-Downloader TookPS under the guise of popular software"}]},{"@type":"WebSite","@id":"https:\/\/gulftech-news.com\/en\/#website","url":"https:\/\/gulftech-news.com\/en\/","name":"Gulf Tech News","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gulftech-news.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/c033626e357b2f7e127eac0570ddc05c","name":"bessan helmi","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gulftech-news.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bb1e09a6f094e0fa605073926f8ad9eb228a8b0aacd381fda782c562612428cf?s=96&d=mm&r=g","caption":"bessan helmi"},"url":"https:\/\/gulftech-news.com\/en\/author\/bessan-helmi\/"}]}},"_links":{"self":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/75880","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/comments?post=75880"}],"version-history":[{"count":1,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/75880\/revisions"}],"predecessor-version":[{"id":75884,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/posts\/75880\/revisions\/75884"}],"wp:attachment":[{"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/media?parent=75880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/categories?post=75880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gulftech-news.com\/en\/wp-json\/wp\/v2\/tags?post=75880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}