Technology
New Harry Potter-named malware strikes, revealing global espionage campaign
A new malware has been detected by security researchers that is suspected of conducting espionage. Hackers infect devices by impersonating government agencies, usually tax agencies such as the Internal Revenue Service (IRS). Once the malicious software is on a PC, it can gather intelligence (collecting personal data, passwords and more), download additional malicious software and upload data to the hacker’s server. It does all this while using Google Sheets to avoid suspicion and store data.
GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE
Illustration of computer being hacked by malware (Kurt “CyberGuy” Knutsson)
It all starts with a fake email
The hackers behind the malware, called “Voldemort,” have cleverly designed it to avoid getting caught. Just like the name Voldemort spelled trouble in J.K. Rowling’s Harry Potter series, it’s causing issues in the cybersecurity world, too.
The cyberattack kicks off when you receive an email that looks like it’s from a government tax agency. According to Proofpoint, the hackers behind this campaign have been impersonating tax agencies in various countries, including the U.S. (IRS), the U.K. (HM Revenue & Customs), France (Direction Générale des Finances Publiques), Germany (Bundeszentralamt für Steuern), Italy (Agenzia delle Entrate) and, as of Aug. 19, India (Income Tax Department) and Japan (National Tax Agency). Each email lure was customized and written in the language of the tax authority being impersonated.
Proofpoint analysts found that the hackers tailored their phishing emails to match the target’s country of residence based on publicly available information rather than the organization’s location or the language suggested by the email address. For example, some targets in a European organization received emails impersonating the IRS because they were linked to the U.S. in public records. In some cases, the hackers mixed up the country of residence when the target shared a name with a more prominent individual.
The email also tries to mimic the email of the government agency. For example, the U.S. folks were sent fake emails using “no_reply_irs[.]gov@amecaindustrial[.]com.”
Email that tries to mimic the email of a government agency (Proofpoint) (Kurt “CyberGuy” Knutsson)
The attack cleverly unfolds on your device
In the fake email, hackers impersonating the government warn you about changes in the tax rates and tax systems and ask you to click a link to read a detailed guide. Clicking on the link brings you to a landing page, which uses Google AMP Cache URLs to redirect you to a page with a “Click to view document” button.
After you click the button, the hackers check if you’re using a Windows device. If you are, you’ll be redirected to another page. When you interact with that page, it triggers a download that looks like a PDF file in your PC’s download folder, but it’s actually an LNK or ZIP file hosted on an external server.
When you open the file, it runs a Python script from another server without actually downloading the script to your computer. This script collects system information to profile you, while a fake PDF opens to hide the malicious activity.
Download that looks like PDF file in your PC’s download folder (Proofpoint) (Kurt “CyberGuy” Knutsson)
Voldemort uses Google Sheets to store data
Once the malware has successfully infected your Windows device, it can:
- Ping: Check if it’s still connected to its control server
- Dir: Get a list of files and folders on your system
- Download: Send files from your system to the control server
- Upload: Put files from the control server onto your system
- Exec: Run specific commands or programs on your system
- Copy: Copy files or folders on your system
- Move: Move files or folders around on your system
- Sleep: Pause its activity for a set time
- Exit: Stop running on your system
The malware uses Google Sheets as its command center, where it gets new instructions and stores stolen data. Each infected device sends its data to specific cells in the Google Sheet, marked by unique IDs to keep everything organized.
Voldemort interacts with Google Sheets through Google’s API, using an embedded client ID, secret and refresh token stored in its encrypted settings. This method gives the malware a reliable way to communicate without raising suspicion since Google Sheets is widely used in businesses, making it hard for security tools to block it.
HOW TO RECOGNIZE AND AVOID BEING A VICTIM OF VACATION RENTAL SCAMS
4 ways to protect yourself from malware attacks
Hackers are releasing increasingly sophisticated malware, but that doesn’t mean you’re defenseless. Below are some tips to help protect yourself from such attacks.
1) Read sensitive emails carefully: The best way to spot fake emails that deliver malware is to check them carefully. While hackers may be tech-savvy, their language skills often aren’t perfect. For example, in the screenshots above, you can see typos like “Taxplayers” instead of “Taxpayers.” Government agencies don’t usually make these kinds of mistakes.
2) Check email domain: Verify that the email domain matches the organization it claims to represent. For example, an email from the IRS should come from an address ending in “@irs.gov.” Be cautious of slight misspellings or variations in the domain.
3) Invest in data removal services: Hackers target you based on your publicly available information. That could be anything from your leaked info through a data breach to the information you provided to an e-commerce shop. Check out my top picks for data removal services here.
4) Have strong antivirus software: If you have strong antivirus software installed on your device, it can protect you when you receive these types of scam emails or accidentally open the attachment or click a link. The best way to protect yourself from clicking malicious links that install malware that may get access to your private information is to have antivirus protection installed on all your devices. This can also alert you of any phishing emails or ransomware scams. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android and iOS devices.
SUBSCRIBE TO KURT’S YOUTUBE CHANNEL FOR QUICK VIDEO TIPS ON HOW TO WORK ALL OF YOUR TECH DEVICES
Kurt’s key takeaway
While researchers can’t say for sure, many of the techniques used by the malware are similar to those employed by hackers suspected of espionage. Even if this assessment turns out to be incorrect, the scale and sophistication of the attack are concerning. Anyone without technical knowledge could easily fall victim and lose personal data and money. This attack specifically targets Windows users, which also raises questions about Microsoft’s security framework.
What measures do you think organizations should implement to better protect individuals from malware attacks? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover.
Follow Kurt on his social channels:
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
Tenways’ compact e-bike twists and folds to go flat
Tenways just launched its new CGO Compact electric bike in Europe that’s designed to fit into tight spaces like car trunks, apartment hallways, and train compartments.
To achieve this, the CGO Compact is fitted with small 20-inch wheels, folding pedals, and a handlebar fitted with a twistable stem to create a slim, wall-hugging profile. The adjustable steering column and low-step through frame also make it suitable for a wide range of rider heights, so it could be a good shareable e-bike for families. And its MIK HD rear carrier system is good for hauling up to 27kg (almost 60 pounds) around town, with mounting points for additional accessories like a crate or child seat.
Tenways might not be a household name globally, but the Chinese e-bike company headquartered in the Netherlands is making a name for itself in Europe thanks to aggressive pricing, sleek designs, and over 1,500 shops and service centers. And while the CGO Compact’s €1,999 (about $2,365) price tag isn’t cheap, it’s well below the €2,681 average for European e-bikes.
The company does sell e-bikes in the US, but the CGO Compact is only for sale in Europe as of today. It features a 250W rear-hub motor connected to a Gates Carbon belt drive for maintenance-free propulsion. It promises a range of up to 100km from its 500Wh removable battery, but its single-speed drivetrain produces only 45Nm of torque so it’s best suited for relatively flat cities. If your commute does stray from asphalt then the suspension seat post should help absorb bumps. There’s also an integrated torque sensor to ensure the smooth delivery of pedal-assisted power, and Tektro hydraulic disc brakes should keep any sudden stops under control.
The CGO Compact lives up to its name regarding size, but it’s not all that lightweight. Stripped down it weighs 19.8kg (almost 44 pounds), or 22.1kg (almost 49 pounds) with all the accessories you’ll want in wet urban environments. That makes it heavier than many full-sized e-bikes, even from Tenways, and less versatile than the excellent 20-inch Brompton G foldable which also weighs less but costs more than twice as much.
Technology
Fox News AI Newsletter: Trump activates ‘tech force’
President Donald Trump’s administration is tasking an AI “tech force” to modernize systems. (Stefani Reynolds/Bloomberg via Getty Images)
NEWYou can now listen to Fox News articles!
Welcome to Fox News’ Artificial Intelligence newsletter with the latest AI technology advancements.
IN TODAY’S NEWSLETTER:
– Inside Trump administration’s AI tech force designed to modernize government
– Elon Musk slams Anthropic AI models as ‘misanthropic’ and ‘evil’ in scathing social media post
– AI power players pour cash into competitive primaries as 2026 midterms heat up
‘TECH FORCE’: Inside Trump administration’s AI initiative designed to modernize government – FOX Business reports on the Trump administration’s latest initiative to overhaul federal efficiency, detailing an internal AI “tech force” tasked with modernizing antiquated government systems and streamlining operations.
TECH ALLIANCE: War Department to partner with OpenAI to integrate ChatGPT, GenAI for military use – The Department of Defense is reportedly strengthening its technological arsenal through a strategic partnership with OpenAI, aiming to integrate ChatGPT and generative AI capabilities into military operations to maintain a strategic edge.
SCATHING POST: Elon Musk slams Anthropic AI models as ‘misanthropic’ and ‘evil’ – Tech billionaire Elon Musk took to social media to unleash a scathing attack on rival AI firm Anthropic, characterizing their models as “misanthropic” and “evil” in a post that highlights the intensifying ideological rift within Silicon Valley.
Elon Musk, chief executive officer of Tesla Inc., during the US-Saudi Investment Forum at the Kennedy Center in Washington, DC, US, on Wednesday, Nov. 19, 2025 (Stefani Reynolds/Bloomberg via Getty Images)
POWER PLAYERS: AI execs pour cash into competitive primaries as 2026 midterms heat up – With the 2026 midterm elections on the horizon, deep-pocketed investors and executives from the artificial intelligence sector are pouring cash into competitive primaries, hoping to shape the regulatory landscape for the booming technology.
OPINION: AI raises the stakes for national security — here is how to get it right – In this opinion piece, OpenAI’s Chris Lehane argues that the rapid advancement of artificial intelligence has dramatically raised the stakes for American national security, outlining a strategic framework to ensure the U.S. maintains its dominance without compromising safety.
OPINION: The 2028 election will be a referendum on our future in an AI-dominated world – As technology accelerates, this op-ed contends that the 2028 presidential election will serve as a critical referendum on humanity’s future, forcing voters to decide how the nation should navigate an increasingly AI-dominated world.
Children forming deep emotional connections with AI companions is raising questions among parents. (StockPlanets/Getty Images)
BATTLE FOR DOMINANCE: AI wars begin in new Super Bowl commercials – The battle for artificial intelligence dominance has moved to the advertising stage, as tech giants unleash a wave of new Super Bowl commercials designed to capture the public imagination and assert their position in the “AI wars.”
BOT TO THE FUTURE: Humanoid robots are getting smaller, safer and closer to home – Recent advancements in robotics are making humanoid machines smaller, safer, and more viable for domestic use, suggesting that a future where robots assist with daily household tasks is getting closer to reality.
MOYA’S DEBUT: ‘Warm-skinned’ AI robot with camera eyes is seriously creepy – A new development in robotics featuring “warm skin” and camera eyes has sparked a mix of fascination and unease, with many observers describing the lifelike yet artificial creation as “seriously creepy.”
Moya’s humanlike appearance is intentional, from her warm skin to subtle facial details designed to feel familiar rather than mechanical. (DroidUp)
DIGITAL DANGER: AI companions are reshaping teen emotional bonds – A growing trend of teenagers forming deep emotional connections with AI companions is raising questions among parents and psychologists about the long-term impact of synthetic relationships on social development and mental health.
Subscribe now to get the Fox News Artificial Intelligence Newsletter in your inbox.
FOLLOW FOX NEWS ON SOCIAL MEDIA
Facebook
Instagram
YouTube
X
LinkedIn
SIGN UP FOR OUR OTHER NEWSLETTERS
Fox News First
Fox News Opinion
Fox News Lifestyle
Fox News Health
DOWNLOAD OUR APPS
Fox News
Fox Business
Fox Weather
Fox Sports
Tubi
WATCH FOX NEWS ONLINE
Fox News Go
STREAM FOX NATION
Fox Nation
Stay up to date on the latest AI technology advancements and learn about the challenges and opportunities AI presents now and for the future with Fox News here.
Technology
A surprise God of War prequel is out on the PS5 right now
To close out its February 2026 State of Play presentation, Sony revealed God of War Sons of Sparta, a new prequel 2D side scroller in the God of War franchise, and announced that it’s out right now on PlayStation 5.
”God of War Sons of Sparta is a 2D action platformer with a canon story set in Kratos’ youth during his harsh training at the Agoge alongside his brother Deimos,” Sony says. Over the course of the game, Kratos will “learn deadly skills using his spear and shield, as well as harness powerful divine artifacts known as the Gifts of Olympus to take on a wide array of foes.”
Sony’s Santa Monica Studio collaborated on the game with Mega Cat Studios. It costs $29.99, with a Digital Deluxe version available for $39.99.
Sony also announced that it’s working on a remake of the original God of War trilogy, with TC Carson set to return as the voice of Kratos. However, the project is “still very early in development, so we ask for your patience as it will be a while before anything else can be shared,” according to Sony. “When we can come back with an update, we aim to make it a big one!”
-
Politics1 week agoWhite House says murder rate plummeted to lowest level since 1900 under Trump administration
-
Alabama6 days agoGeneva’s Kiera Howell, 16, auditions for ‘American Idol’ season 24
-
Politics1 week agoTrump unveils new rendering of sprawling White House ballroom project
-
San Francisco, CA1 week agoExclusive | Super Bowl 2026: Guide to the hottest events, concerts and parties happening in San Francisco
-
Ohio1 week agoOhio town launching treasure hunt for $10K worth of gold, jewelry
-
Culture1 week agoAnnotating the Judge’s Decision in the Case of Liam Conejo Ramos, a 5-Year-Old Detained by ICE
-
Culture1 week agoIs Emily Brontë’s ‘Wuthering Heights’ Actually the Greatest Love Story of All Time?
-
News1 week agoThe Long Goodbye: A California Couple Self-Deports to Mexico