Fake LetsVPN Installers Spread Malware That Can Take Over Your Computer — Here’s What Happened

Fake LetsVPN Installers Spread Malware That Can Take Over Your Computer — Here’s What Happened

Fake LetsVPN installers are spreading malware that can give hackers full control of a computer. Here’s how the attack works and how you can download software more safely each time.

What Happened?

According to Cybernews, hackers are using fake LetsVPN installers to spread GoodPersonRAT, malware that can take full control of a computer.

Cybernews reported the attack on July 9, 2026, based on research from cybersecurity company ThreatLocker.

Attackers hide the malware inside a fake Windows installer that also installs the real LetsVPN app. As a result, everything may appear normal.

Once active, the malware can record what you type, steal browser data, target Telegram Desktop, and let hackers control the device.

This kind of attack can put login details and other personal information in criminal hands.

It is also worth remembering that your data may already have been leaked in other incidents without you knowing.

If you are unsure whether your information was leaked, automatic monitoring can help you spot problems earlier.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Targeted and What Could Be Stolen?

ThreatLocker said the fake installer directly targets LetsVPN users, including people who use the service to reach blocked websites.

The report did not say how many people downloaded the file or how many computers were infected.

It also did not confirm which victims had specific information stolen.

Once active, the malware can record keystrokes, copy clipboard text, transfer files, and let attackers control the computer remotely.

It can also target Telegram Desktop account information and send Telegram traffic through attacker-controlled systems.

The malware can erase browser cookies (small files that remember website sessions) and saved login details.

That may force you to sign in again. A built-in keylogger, which records what you type, can then capture those details.

Login details and private messages can help criminals break into your account or make phishing messages more convincing.

How Fake LetsVPN Installers Take Over a Computer

The analyzed file was named “Kuailian_win-setup.86.msi.”

When a user opens it, a small malware loader runs before the real VPN installation starts.

The loader contacts a command-and-control server, or C2 server, which attackers use to send instructions remotely.

The final RAT, or remote access trojan, runs only in memory. This can make it harder for file-scanning tools to find.

The malware can choose from 40 sets of command servers.

Some server names included “Nishihaoren,” which means “you are a good person” in simplified Chinese.

That detail led ThreatLocker to call the malware GoodPersonRAT.

To stay active, it creates Windows services and scheduled tasks, which are automatic jobs that can start before you sign in.

ThreatLocker said the real VPN installer was digitally signed, meaning its publisher was verified. The harmful MSI package was not signed.

The report did not confirm how attackers delivered the fake installer to victims.

Cybernews noted that similar files often spread through fake ads, phishing links, fake download sites, forums, or direct messages.

Phishing links are fake links designed to trick you into opening harmful pages.

Search manipulation can also push harmful pages higher in results, but the route used here remains unconfirmed.