Close Menu

    Stay Ahead with Exclusive Updates!

    Enter your email below and be the first to know what’s happening in the ever-evolving world of technology!

    What's Hot

    OpenAI signs strategic UK Partnership to build AI hubs in public services

    August 5, 2025

    China-linked hackers exploit SharePoint zero-day flaw to hit U.S. agencies

    August 3, 2025

    Zip Security raises $13.5M to help SMBs automate cybersecurity

    August 3, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter)
    PhronewsPhronews
    • Home
    • Big Tech & Startups

      OpenAI signs strategic UK Partnership to build AI hubs in public services

      August 5, 2025

      China-linked hackers exploit SharePoint zero-day flaw to hit U.S. agencies

      August 3, 2025

      Zip Security raises $13.5M to help SMBs automate cybersecurity

      August 3, 2025

      OpenAI prepares to launch GPT-5 model in August

      July 31, 2025

      Trump administration unveils AI Action Plan to cut red tape and boost infrastructure

      July 29, 2025
    • Crypto

      Crypto Markets Rally as GENIUS Act Nears Stablecoin Regulation Breakthrough

      July 23, 2025

      Lightchain and Ethereum Spark AI Chain Revolution

      July 23, 2025

      Agora Secures $50M Series A for White Label Stablecoin Infrastructure

      July 22, 2025

      Coinbase hack explained: lessons in crypto security

      May 24, 2025

      Coinbase responds to hack: customer impact and official statement

      May 22, 2025
    • Gadgets & Smart Tech
      Featured

      EV Giant Tesla opens first India showroom in Mumbai

      By preciousJuly 28, 20253
      Recent

      EV Giant Tesla opens first India showroom in Mumbai

      July 28, 2025

      Google rolls out Veo 3 video generator to Pro & Ultra users

      July 19, 2025

      DStv Eyes Weekly Subscription Model Amid Economic Headwinds 

      June 26, 2025
    • Cybersecurity & Online Safety

      China-linked hackers exploit SharePoint zero-day flaw to hit U.S. agencies

      August 3, 2025

      Microsoft July 2025 Patch Tuesday update: 128 security vulnerabilities including SQL Server flaws

      July 26, 2025

      Scattered Spider gang steps up SIM-swap attacks on airlines

      July 15, 2025

      Ransomware Terror: How SafePay Hijacked Ingram Micro

      July 15, 2025

      SmartAttack: New Smartwatch Attack Shows How Air-gapped Systems Can Be Breached

      June 24, 2025
    PhronewsPhronews
    Home»Cybersecurity & Online Safety»FBI Issues Alert: Free Document Converters Used to Spread Malware
    Cybersecurity & Online Safety

    FBI Issues Alert: Free Document Converters Used to Spread Malware

    preciousBy preciousMarch 24, 2025Updated:June 12, 2025No Comments0 Views
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Federal Bureau of Investigation (FBI) announced in a press release a new type of scam that involves threat actors using free online document converters to stealthily install malware into their victims’ computers or smartphones, leading to a theft of sensitive information and exploits such as ransomware.

    The FBI says, “In this scenario, criminals use free online document converter tools to load malware onto victims’ computers, leading to incidents such as ransomware.”

    “To conduct this scheme, cyber criminals across the globe are using any type of free document converter or downloader tool. This might be a website claiming to convert one type of file to another, such as a .doc file to a .pdf file,” says the press release. 

    “It might also claim to combine files, such as joining multiple .jpg files into one .pdf file. The suspect program might claim to be an MP3 or MP4 downloading tool.”

    This report comes from the FBI Denver Field Office who says agents are becoming increasingly aware of these types of attacks. It is explained that many ransomware attacks are often initiated on users who searched for “free online file converters” on popular search engines such as Google, Safari, Edge, etc. These users often click on paid advertisements that appear prominently in the search results, which direct them to websites distributing ransomware.

    The FBI says that inasmuch as the converter and downloading tools will initially do the intended assignment by reading through the file and converting as per the instruction of the user, it is the resulting file that deploys the malware attack. 

    “The resulting file can contain hidden malware giving criminals access to the victim’s computer. The tools can also scrape the submitted files for Personal Identifying Information (PII), Banking Information, Cryptocurrency Information (Seed phrases, Wallet Addresses), Email Addresses, and Passwords,” adds the report.

    On how the attack is further carried out, Vikki Migoya, the Public Affairs Office for FBI Denver tells Bleeping Computer that, “The scammers try to mimic URLs that are legit – so changing just one letter, or ‘INC’ instead of ‘CO.’”

    Malwarebytes also explains how the cyberattack might be carried out in many ways, one of which is that “in the most sophisticated scenario, the so-called converted file contains malware code that downloads and installs an information stealer and everyone who opens it will get their device infected.”

    In their report, they listed a number of domains that are examples of IOCs involved in this type of scam:

    • Imageconvertors[.]com (phishing)
    • convertitoremp3[.]it (Riskware)
    • convertisseurs-pdf[.]com (Riskware)
    • convertscloud[.]com (Phishing)
    • convertix-api[.]xyz (Trojan)
    • convertallfiles[.]com (Adware)
    • freejpgtopdfconverter[.]com (Riskware)
    • primeconvertapp[.]com (Riskware)
    • 9convert[.]com (Riskware)
    • Convertpro[.]org (Riskware)

    To be safe against these types of attacks, it is advised to have an active anti-malware protection on your devices and a browser extension that blocks malicious sites.

    The FBI also advises that people should be increasingly aware of their actions online as well as the types of risks they could be exposed to. And in a case of an attack, the Denver Field Office recommends that an immediate report should be made to the victim’s financial institutions in order to protect their identity and accounts, as well as a report made to IC3.gov.

    It is also advised that a password change should take place on a clean and trusted device, and an up-to-date scan for a virus software should be done, checking for potential malicious software installed by scammers.

    adware anti-malware protection banking information theft browser extensions cryptocurrency seed phrase theft cybercriminals cybersecurity awareness cybersecurity threats document converter scam FBI cyber scam FBI Denver Field Office file conversion tools financial institution report free online document converters IC3.gov identity theft information stealer malicious download tools malicious URL mimicking malware installation malwarebytes report online file converters online security risks password change advice personal identifying information theft phishing domains phishing scams phishing websites PII theft ransomware attack ransomware distribution ransomware protection riskware scam awareness scam prevention trojan download Trojan malware
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    precious
    • LinkedIn

    I’m Precious Amusat, Phronews’ Content Writer. I conduct in-depth research and write on the latest developments in the tech industry, including trends in big tech, startups, cybersecurity, artificial intelligence and their global impacts. When I’m off the clock, you’ll find me cheering on women’s footy, curled up with a romance novel, or binge-watching crime thrillers.

    Related Posts

    China-linked hackers exploit SharePoint zero-day flaw to hit U.S. agencies

    August 3, 2025

    Microsoft July 2025 Patch Tuesday update: 128 security vulnerabilities including SQL Server flaws

    July 26, 2025

    Scattered Spider gang steps up SIM-swap attacks on airlines

    July 15, 2025

    Comments are closed.

    Top Posts

    MIT Study Reveals ChatGPT Impairs Brain Activity & Thinking

    June 29, 202596

    From Ally to Adversary: What Elon Musk’s Feud with Trump Means for the EV Industry

    June 6, 202558

    Coinbase Hack 2025: Everything we know so far.

    May 21, 202551

    Coinbase responds to hack: customer impact and official statement

    May 22, 202548
    Don't Miss
    Artificial Intelligence & The Future

    OpenAI signs strategic UK Partnership to build AI hubs in public services

    By preciousAugust 5, 20257

    OpenAI, the company behind ChatGPT, and the UK government have entered into a partnership that…

    China-linked hackers exploit SharePoint zero-day flaw to hit U.S. agencies

    August 3, 2025

    Zip Security raises $13.5M to help SMBs automate cybersecurity

    August 3, 2025

    OpenAI prepares to launch GPT-5 model in August

    July 31, 2025
    Stay In Touch
    • Facebook
    • Twitter
    About Us
    About Us

    Evolving from Phronesis News, Phronews brings deep insight and smart analysis to the world of technology. Stay informed, stay ahead, and navigate tech with wisdom.
    We're accepting new partnerships right now.

    Email Us: info@phronews.com

    Facebook X (Twitter) Pinterest YouTube
    Our Picks
    Most Popular

    MIT Study Reveals ChatGPT Impairs Brain Activity & Thinking

    June 29, 202596

    From Ally to Adversary: What Elon Musk’s Feud with Trump Means for the EV Industry

    June 6, 202558

    Coinbase Hack 2025: Everything we know so far.

    May 21, 202551
    © 2025. Phronews.
    • Home
    • About Us
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.