‘What started with someone trying to potentially remove the background from a selfie ended with a custom .NET thief checking your browser passwords’: Experts warn free image editing tool could actually be dangerous malware



  • Fake photo tool ranking high in search results tricks users into running malware using ClickFix tactics
  • Victims are first infected with CastleLoader, which then deploys NetSupport RAT and a custom CastleStealer.
  • The campaign highlights how SEO poisoning and social engineering can turn simple tasks into credential theft and remote compromise.

A website that promises to remove backgrounds from selfie photos is actually simply dropping malware to steal information on people’s computers, security researchers say.

Cybersecurity experts at Huntress described how they discovered a website that, through SEO poisoning, managed to reach the top of search engine results pages. Therefore, when people search for background removal tools, they are very likely to land on this particular malicious site.

Leave a Comment

Your email address will not be published. Required fields are marked *