CapCut Users Beware: Cybercriminals Using Malicious Software Distribution Tactics

Photo by RoonZ nl on Unsplash

CapCut Users Beware: Cybercriminals Using Malicious Software Distribution Tactics

Not too long ago, a friend of mine who works in the cybersecurity field decided to make videos to educate the public on the importance of cyber awareness. To do this, he needed a reliable video editing tool that could help him create engaging content.

After some research, he found that CapCut was the perfect free software that could meet his needs. He immediately began searching for it online and was surprised to find that there were numerous websites that claimed to offer the software for free.

Malicious WebsitesDate of Registration
capcut-desktop[.]com21 Feb 2023
capcutdesktop[.]net18 Feb 2023
capcutdesktop[.]com18 Feb 2023
capcut-pc[.]com14 Feb 2023
capcutoffice[.]com15 Feb 2023
capcutoffice[.]net15 Feb 2023
capcut-pc[.]net14 Feb 2023
capcutonline[.]net7 Feb 2023

However, upon closer inspection, he discovered that these websites had been registered using baesuzylananh@gmail[.]com around the same time. He also noticed the websites looked almost the same but they were not the same. They were, in fact, malicious sites that were spreading dangerous malware, which could wreak havoc on his computer and compromise his personal information.

Fake vs original CapCut website

An online service called VirusTotal analyzes files and URLs for viruses, worms, trojans, and other kinds of malicious content flagged the downloaded software as malicious.

VirusTotal flagged the capcut software as malicious

A Segue in the Story

He discovered that two other websites had all been registered around the same time, and using the same email address - baesuzylananh@gmail[.]com. What made this, particularly concerning was that this same domain name had recently been mentioned in a Facebook post that was distributing malware under the name of OpenAI's ChatGPT chatbot for Windows and Android. Read here.

Malicious WebsiteDate of Registration
chatgpt-pc[.]com25 Feb 2023
chatgpt-pc[.]net25 Feb 2023


Knowing the dangers of downloading software from untrustworthy sources, my friend immediately abandoned these websites and instead sought out legitimate sources for CapCut. He learned a valuable lesson about the importance of staying vigilant and always being cautious when downloading software from the internet. The legitimate CapCut website is - https://www.capcut.com/.

Always remember: whenever in doubt, simply step out.