الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Cybercriminals use popular Turkish and Arabic books as bait to steal personal data

Kaspersky Global Research & Analysis Team uncovers malware-as-a-service campaign targeting ebook readers across Turkey, Egypt, Bangladesh and Germany. Cybercriminals are disguising sophisticated malware as bestselling Turkish and Arabic books, tricking hundreds of readers into downloading files that steal passwords, cryptocurrency wallets and other sensitive information from their computers.
Kaspersky identified a malware-as-a-service (MaaS) campaign that is using LazyGo, a newly discovered Go-based loader that delivers multiple information-stealing programs. The campaign targets users searching for popular titles ranging from John Buchan’s “The Thirty-Nine Steps” in Turkish to Arabic texts on poetry, folklore and religious practices. The fake ebooks span diverse interests, including also Turkish business management texts like Tamer Koçel’s “İşletme Yöneticiliği,” contemporary fiction, and Arabic literary criticism such as “The Literary and Linguistic Movement in the Sultanate of Oman.”
The malicious files masquerade as PDF ebooks but are actually executable programs with PDF icons. When users download and open these fake books, the LazyGo loader deploys infostealers including StealC, Vidar and ArechClient2. Kaspersky researchers identified three variants of LazyGo, each employing different evasion techniques such as API unhooking, AMSI bypass, ETW disabling and anti-virtual machine detection.

The information that the attackers steal includes:
• Browser data: saved passwords, cookies, autofill information and browsing history from Chrome, Edge, Firefox and other browsers.
• Financial assets: cryptocurrency wallet extensions, configuration files and storage data.
• Developer credentials: AWS credentials, Azure CLI tokens and Microsoft Identity Platform tokens.
• Communication platforms: Discord tokens, Telegram Desktop data and Steam session files.
• System information: hardware specifications, installed software and running processes.
Victims infected with ArechClient2/SectopRAT face additional risk as attackers gain complete remote control over compromised machines.
“What makes this campaign particularly concerning is its use of a malware-as-a-service model combined with highly targeted social engineering,” said Yossef Abdelmonem, Senior Security Researcher at Kaspersky GReAT. “The LazyGo loader’s multiple variants and sophisticated evasion techniques show this isn’t opportunistic cybercrime – it’s a structured operation designed to harvest credentials at scale. Organizations should be especially vigilant as stolen developer tokens and cloud credentials can provide attackers with deep access to corporate infrastructure.”
Kaspersky telemetry shows that the campaign is affecting government agencies, educational institutions, IT services and other sectors. The campaign remains active with threat actors continuously uploading new malicious ebooks to GitHub and compromised websites.
Kaspersky experts recommend users verify ebook sources before downloading, carefully examine file properties, and maintain updated security software capable of detecting evasive malware techniques. When selecting a security solution, it’s advisable to choose one with robust anti-malware capabilities that have been validated through independent testing. According to a recent evaluation by AV-Comparatives, Kaspersky Premium demonstrated strong performance with a malware protection rate of 99.99% on a test collection of 9,995 files, proving high-level defense against malicious software.

Related Posts:

Madinet Masr Awards EGP 1.38 Billion for Origami at Taj City

إدراج 47 جامعة مصرية في تصنيف UI GreenMetric للاستدامة لعام 2026

حجر أساس لمشروع أعلاف باستثمارات صينية.. والزراعة تؤكد دعم الشراكة مع القطاع الخاص

Zoho Launches Agent-Ready Catalyst Platform for AI App Development

Turkish Airlines Named Europe’s Best Airline for the 11th Time

NILEWOOD Expands in Saudi Arabia at Saudi Wood Show 2026

Turkish Airlines and Air China Expand Codeshare Agreement

PATRIZIA appoints Hassan Awada as Senior Executive Officer to lead and accelerate Middle East expansion

آخر الأخبار
اورنچ مصر ووادي دجلة تطلقان منظومة حلول ذكية بــ«نيو» في مستقبل سيتي أورنچ مصر وهواوي تطلقان أول تجربة عالمية لتقنية CCIC على شبكات الميكروويف بنك saib يرفع العائد على شهادة Excellence الثلاثية إلى 18.25% كوربوريت ستاك تنفذ مشروعًا لرقمنة 1000 مصنع بالتعاون مع مركز تحديث الصناعة الذكاء الاصطناعي في الفصول الدراسية.. كيف يتخيل الجيل Z مستقبل التعليم؟ ڤاليو تنجح في إتمام إصدار سندات توريق بقيمة 945.8 مليون جنيه إم إن تي-حالاࣧ تنجح فى إتمام مجموعة من إصدارات سندات التوريق بقيمة تتجاوز 4 مليار جنيه بنهاية الربع ... تنميه تتعاون مع«ايسكور»و«سينابس أناليتكس»لتطوير قرارات الائتمان بالذكاء الرقمي مع هيونداي توسان.. راحة بالك تمتد لـ3 سنوات أو 60 ألف كيلومتر مع باقة الصيانة الخاصة من جي بي أوتو قمة الابتكار الجامعي 2026 تعلن الفرق الفائزة بمشاركة 100 مشروع من 30 جامعة سالي سلامة أمام الاختبار الأصعب في نيسان مصر.. هل تعود الثقة من بوابة العميل والأمان؟ محافظ البنك المركزي يبحث مع مسؤول «التمويل الدولية» تعزيز التعاون المشترك وزير الأوقاف يلتقي المشرفات من الواعظات عبر تقنية الاتصال المرئي لمتابعة العمل الدعوي مصر تدين اقتحام المستوطنين الإسرائيليين للمسجد الأقصى المبارك بنك القاهرة وشركة فيزا يوقعان اتفاقية تعاون لدعم تطوير حلول ومنتجات دفع جديدة محافظ البنك المركزي ووزير الصناعة يطلقان صندوق إعادة هيكلة المصانع المتعثرة برأسمال مليار جنيه إف سي بايرن ميونخ يؤسس أكاديمية تعمل على مدار العام في الشرق الأوسط، ويقدّم نموذجه المتميز لتطوير ال... دولة الإمارات تجدد التزامها بالتنمية المستدامة خلال الاجتماع السنوي لمجلس محافظي البنك الآسيوي للاس... المكتب الطبي يعلن حصول «مستشفيات الشيخ خليفة» على اعتماد «مسار التميّز بامتياز» من «المركز الأمريكي ... مجموعة دلسكو تطلق برنامج «خطوة» للمواهب الوطنية لتطوير وتمكين الكفاءات الإماراتية