A single mistyped web address or a click on the wrong search result is now all it takes to hand your entire computer to a stranger. Security researchers just flagged a fake VPN installer that does exactly that, and it targets people who are only trying to protect their privacy in the first place.

That is exactly why we always tell folks to only use a trusted VPN from the source, never a random link. Unfortunately these types of issues are common among free VPNs.
A cybersecurity report found attackers distributing trojanized installers dressed up as Kuailian VPN (LetsVPN), a popular tool for getting around internet censorship in China. This VPN provider has millions of downloads from Google Play and the Apple App Store.

Install one of these fakes and you don’t just get the VPN. You get a hidden remote access trojan that quietly seizes total control of your machine. What makes this even sneakier is that it still installs the real, signed VPN app after dropping the malware, so the victim thinks everything worked fine.
Details of This Fake VPN Malware (GoodPersonRAT)
The malware starts as a shellcode loader that phones home to a command-and-control server. The final payload loads straight into memory and never touches the disk, which lets it slip right past file-based antivirus scans.

To stay reachable, it rotates through a network of 40 possible C2 servers. Several of those domains riff on “Nishihaoren,” which translates from simplified Chinese as “you are a good person,” so researchers nicknamed the threat GoodPersonRAT.
The feature list reads like a full surveillance kit. It watches your screen, logs keystrokes, grabs clipboard content, and scans local browsers for cookies, saved logins, profiles, and history.
It also targets Telegram Desktop and hands the attacker free rein to run any command they want. Even with no files left behind, it digs in through service registration and SYSTEM-level scheduled tasks that fire up before you ever log in.
Hide Your Digital Fingerprint
Final Thoughts from Troy
This story is saddening because it preys on privacy-minded folks, many of them stuck behind the Great Firewall in China. I’ve seen crooks clone legit apps for years now, and they keep pushing these fakes through search poisoning, sketchy ads, and copycat download sites.
Only grab apps from the official developer, never a random search result. Before you install anything from an unverified source, scan it first with VirusTotal. I also suggest visiting our VPN tutorial for instructions on how to setup a legitimate VPN app.
For more details on this story, refer to the original report from ThreatLocker.
Have you ever caught a fake app before installing it? Tell us how in the comments below.
Stay ahead of threats like this one by joining our free TROYPOINT Advisor newsletter.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.




