Tendvane

← All articles

SecurityAugust 11, 2026

Criminals are hiding inside a real, signed app your antivirus won't question

Most malware tries to sneak past your antivirus. A campaign Malwarebytes detailed on August 11 does something smarter: it installs a program that isn't malware at all. The download pages impersonate names you'd trust - CNN, the antivirus maker Avast, the media app Stremio - and the file they hand you is O&O Syspectr, a genuine, digitally signed remote-management tool that IT teams use to run computers from afar. Because it's legitimate, signed software, antivirus lets it straight through.

The catch is who's holding the other end. The attackers pre-register their own Syspectr accounts, so the moment their copy lands on your PC, it quietly links to a console they control - handing them remote desktop access and an administrator command line on your machine. From there they can read your files, install more, and watch what you type. Researchers have been tracking this trick all year: a separate campaign called SeasonalInvite, running since January, abused four such tools - ConnectWise ScreenConnect, LogMeIn Resolve, Kaseya and O&O Syspectr - the same way, precisely because a validly signed installer sails past the checks that catch ordinary viruses.

The defence hasn't changed, and it's a habit worth keeping: get software from the maker's own website, not from a search result, an ad, or a link someone sent you. If you never went looking for a remote-management tool, you have no reason to install one - and if a program like Syspectr turns up on your PC unexpectedly, remove it and change your passwords from a machine you trust.

This is exactly the blind spot Tendvane is built for. Its Safety check flags programs that have quietly installed themselves or set to launch at startup - including legitimate-but-unexpected tools like this - and its app updates come through Windows' own package manager (winget) instead of the fake download pages the scam relies on.

Sources

Download Tendvane