Home Malware Programs Rogue Anti-Spyware Programs AntiHacker

AntiHacker

Posted: August 20, 2012

Threat Metric

Ranking: 5,243
Threat Level: 2/10
Infected PCs: 11,034
First Seen: August 20, 2012
Last Seen: October 13, 2023
OS(es) Affected: Windows

AntiHacker Screenshot 1Although official development on the DarkComet RAT has ceased, hackers have felt free to make use of the RAT for backdoor Trojan purposes under the name AntiHacker. With an absolutely staggering amount of irony, AntiHacker is marketed as a PC security and anti-malware program – causing PC users in search of protection to compromise their own computers. AntiHacker's promotion uses both e-mail spam and the Facebook website, and, like Gauss and BlackShades, appears to target rebels fighting against the Syrian government. The AntiHacker variant of the DarkComet RAT includes keylogging functions, spyware-related attacks and the ability to block certain anti-virus features. As a result, AntiHacker should be considered a direct danger to your computer's security and privacy, and SpywareRemove.com malware researchers recommend AntiHacker's immediate deletion with any anti-malware program that can handle the job.

Take Away the 'Anti' for an Accurate Description of AntiHacker

With perhaps the most incongruous malware marketing campaign to date, AntiHacker is promoted as a hacking-protection application, but AntiHacker's real purpose is to install the DarkComet RAT on your PC. Besides using mass-mailed e-mail messages to promote awareness of its fake security services, AntiHacker is also promoted on a Facebook page that's identifiable by its tag line: 'We are here to save the world.' In this case, SpywareRemove.com malware researchers remind all PC users (but particularly those based in Syria) that downloading links from suspicious sources (including third-party Facebook pages) are prominent sources of infection by various PC threats. As usual, legitimate anti-malware and security software should always be acquired from trustworthy sources as a means of avoiding infection by AntiHacker's DarkComet RAT or other forms of hostile software.

The AntiHacker's version of the DarkComet RAT doesn't appear to make any effort at correcting the poor English previous variants of the DarkComet RAT were known for including. Pop-up alerts with contents such as 'You PC is Protect now thank for using our Product' or 'You Are Running On unprotected Conection You Maybe At Risk !!!!' are very prominent signs of a successful AntiHacker attack.

Where You Wind Up While Trusting AntiHacker to Save Your PC

As far as SpywareRemove.com malware researchers have determined, the DarkComet RAT that AntiHacker installs includes the same basic features that you would expect from most backdoor Trojans or Remote Administration Tools, such as:

  • The ability to record your keyboard input to a log file that's sent to criminals for later exploitation (AKA, keylogging).
  • Functions to monitor and steal potentially-confidential information, such as passwords and account names. Bank accounts, website accounts, FTP client accounts and e-mail accounts are often targeted by these attacks.
  • Taking screen grabs from your webcam as a means of visual surveillance.
  • Blocking anti-malware warning messages that are triggered by detection of various PC threats or malicious functions related to the DarkComet RAT.

AntiHacker and the DarkComet RAT should both be removed by actual anti-malware software whenever required to ensure your PC's safety. SpywareRemove.com malware experts also recommend taking precautions to protect potentially-compromised accounts following successful deletion of AntiHacker and the DarkComet RAT.

AntiHacker Screenshot 2AntiHacker Screenshot 3AntiHacker Screenshot 4

Technical Details

Additional Information

The following URL's were detected:
press-news-for.me

One Comment

  • Jana Moran says:

    I have been the victim of a hacker! I know who did it but cannot protect myself. Tried to have your scanner scan but it would not open. I am on an iPad use google and safari. Please help

Loading...