Dark Partner Hackers Exploit Fake AI, VPN, and Crypto Sites to Attack macOS and Windows Users

A new wave of targeted cyberattacks has been attributed to the threat group known as “Dark Partner,” which has intensified its efforts by exploiting current technology trends to compromise both macOS and Windows systems.

Security researchers report that the malicious campaign leverages convincing fake websites related to artificial intelligence (AI), virtual private networks (VPN), and cryptocurrency exchanges as bait, in an effort to trick users into downloading trojanized software.

Sophisticated Social Engineering

The attack chain typically begins when unsuspecting victims are lured to fraudulent sites masquerading as legitimate AI tools, reputable VPN services, or cryptocurrency trading platforms.

According to the Report, these websites display polished branding, authentic-looking interfaces, and even cloned content to establish credibility.

Dark Partner Hackers
Poseidon Stealer

Once a visitor attempts to download the advertised application, they are served installer packages embedded with malicious payloads specifically crafted for either macOS or Windows environments.

On compromised macOS machines, attackers deploy a variant of the RustDoor backdoor, a sophisticated malware strain designed for persistent remote access and data exfiltration.

This malware establishes a secure communication channel with command-and-control (C2) infrastructure, enabling the execution of arbitrary commands, surveillance of user activity, and extraction of sensitive files.

The backdoored applications are often disguised as cracked or pirated versions of popular productivity tools and security utilities.

Victims Targeted Through Popular Technology Themes

For Windows targets, Dark Partner relies on a different set of payloads, including Cobalt Strike beacons and info-stealers such as Vidar.

These tools allow attackers to maintain long-term access, conduct lateral movement within networks, and harvest credentials, cryptocurrency wallets, and other sensitive information.

The mounting evidence suggests that the group adapts its tooling based on the victim’s operating system, displaying a high level of technical acumen and resourcefulness.

Dark Partner Hackers
Google Calendar links

The initial infection vector is heavily reliant on social engineering, with attackers employing SEO poisoning, malvertising, and spear-phishing campaigns to drive traffic to their malicious domains.

Some campaigns observed by researchers even leveraged sponsored ads on search engines and stealthy links distributed via popular social media platforms.

Once installed, the malicious payloads are designed to evade detection by employing multiple layers of obfuscation, code-signing certificates, and anti-analysis techniques.

The activities of Dark Partner align with a broader trend of financially motivated, highly targeted attacks exploiting users’ growing reliance on digital tools in the AI and cryptocurrency spaces.

The campaign’s cross-platform approach and rapid evolution demonstrate the increasing sophistication of cybercriminal operations.

Security experts are urging organizations and end-users to exercise heightened vigilance, particularly when downloading tools or software from non-official sources, and to implement robust endpoint protection and threat detection mechanisms.

Researchers have published a list of associated indicators of compromise (IOCs), including domains, hashes, and file names, to aid the security community in identifying and neutralizing these threats.

Indicators of compromise (IOCs)

Indicator TypeValueDescription
Domainai-assistpro[.]comFake AI tool website
Domainsecurevpn-zone[.]netMalicious VPN download site
Domaincryptoxchange[.]ioFraudulent crypto exchange portal
SHA256 Hashde9a1f01d1ac45247eaa246081c79d6c99b2615c5b5569b7f8ef2e0c574cfb8fRustDoor macOS payload
SHA256 Hashc56d13ff9c4ab3145bcfa0d5eba81a8f9d15d1d361386f933f4e16e1bf6182e5Cobalt Strike Windows payload
File Nameai_tool_pkg.dmgTrojanized macOS installer
File NameVPN_Setup.exeMalicious Windows executable
File NameCryptoTrader.msiFraudulent trading tool installer

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories