CapCut Users Beware: Cybercriminals Using Malicious Software Distribution Tactics
Not too long ago, a friend of mine who works in the cybersecurity field decided to make videos to educate the public on the importance of cyber awareness. To do this, he needed a reliable video editing tool that could help him create engaging content.
After some research, he found that CapCut was the perfect free software that could meet his needs. He immediately began searching for it online and was surprised to find that there were numerous websites that claimed to offer the software for free.
Malicious Websites | Date of Registration |
capcut-desktop[.]com | 21 Feb 2023 |
capcutdesktop[.]net | 18 Feb 2023 |
capcutdesktop[.]com | 18 Feb 2023 |
capcut-pc[.]com | 14 Feb 2023 |
capcutoffice[.]com | 15 Feb 2023 |
capcutoffice[.]net | 15 Feb 2023 |
capcut-pc[.]net | 14 Feb 2023 |
capcutonline[.]net | 7 Feb 2023 |
However, upon closer inspection, he discovered that these websites had been registered using baesuzylananh@gmail[.]com around the same time. He also noticed the websites looked almost the same but they were not the same. They were, in fact, malicious sites that were spreading dangerous malware, which could wreak havoc on his computer and compromise his personal information.
An online service called VirusTotal analyzes files and URLs for viruses, worms, trojans, and other kinds of malicious content flagged the downloaded software as malicious.
A Segue in the Story
He discovered that two other websites had all been registered around the same time, and using the same email address - baesuzylananh@gmail[.]com. What made this, particularly concerning was that this same domain name had recently been mentioned in a Facebook post that was distributing malware under the name of OpenAI's ChatGPT chatbot for Windows and Android. Read here.
Malicious Website | Date of Registration |
chatgpt-pc[.]com | 25 Feb 2023 |
chatgpt-pc[.]net | 25 Feb 2023 |
Knowing the dangers of downloading software from untrustworthy sources, my friend immediately abandoned these websites and instead sought out legitimate sources for CapCut. He learned a valuable lesson about the importance of staying vigilant and always being cautious when downloading software from the internet. The legitimate CapCut website is - https://www.capcut.com/.
Always remember: whenever in doubt, simply step out.