Home Cyber Security News Hackers Use Fake Google Gemini App to Steal Windows Users’ Browser Credentials

Hackers Use Fake Google Gemini App to Steal Windows Users’ Browser Credentials

0
Fake Gemini Steals Credentials

Threat actors are increasingly abusing the growing popularity of generative AI tools to spread malware. In a recent incident observed by Darktrace, attackers used a fake Google Gemini installer to infect a Windows device with the Vidar information stealer.

The campaign targeted users actively looking for AI software rather than relying on traditional phishing emails.

The malicious file was named Download_Google_Gemini_For_Windows.exe and appeared to offer a Windows version of Google Gemini.

Darktrace detected suspicious activity after the executable launched from a user’s Downloads folder in an organization in the Europe, Middle East and Africa region in July 2026.

Fake Gemini Steals Credentials

Investigators found that searches for the suspicious filename led to a Google Colab page. Google Colab is a legitimate cloud-based platform used to run Jupyter notebooks and machine-learning workloads.

The page displayed a download prompt that redirected victims to micronsoftwares[.]com, a site posing as a “Windows Software Hub.”

The secondary site offered a ZIP archive containing the fake Gemini installer. The archive also included a README file that told users to run the executable with administrator privileges and add it to antivirus exclusion lists.

The secondary website posing as a “Windows Software Hub” download page, which likely hosted the fake Gemini installer (Source: darktrace)

These instructions are a major warning sign. Legitimate software installers should not require users to disable or weaken endpoint protection before installation.

By using Google branding and a legitimate Google-hosted platform, the operators made the download appear more trustworthy.

This tactic exploits the fact that employees now routinely search for AI assistants, coding tools, browser extensions, and productivity software for work.

Darktrace identified the payload as Vidar, a widely used information-stealing malware family. The sample was a newer Go-compiled variant that communicated with Telegram-based infrastructure.

Soon after execution, the malicious process connected to 91.98.98[.]86 over HTTPS on port 443. Researchers also linked 91.98.111[.]49 and dtm[.]kijangturbo88[.]top to the activity.

Darktrace’s detection of the unusual outbound connection associated with the fake Gemini installer (Source: darktrace)

Microsoft Defender for Endpoint telemetry later confirmed behavior associated with the theft of browser credentials and other sensitive information.

Vidar can target saved passwords, browser cookies, autofill data, cryptocurrency wallets, and other information stored on infected devices.

Stolen browser sessions and credentials can enable attackers to access corporate email, cloud applications, and internal services.

Darktrace contained the incident by blocking connections to the suspicious infrastructure and quarantining the compromised endpoint.

The case shows that security tools can detect an attack even when its initial delivery appears legitimate, because malware behavior such as unusual outbound connections and credential theft still differs from normal device activity.

Indicators of Compromise

IoCTypeDescription
Download_Google_Gemini_For_Windows.exeFileFake Google Gemini-themed installer used to deliver Vidar malware
GoogleAppInstaller.exeFileRelated executable identified through endpoint telem

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version