Adware bundles are installing a VPN software called Pirate Chick, which then connects to a remote server to download and install malicious payloads such the AZORult password-stealing Trojan. This is a Trojan that pretends to be a legitimate VPN software, but in the background downloads and installs a malware payload on a victim. The payload is process monitor, which could be a temporary filler while they launch another campaign. This is becoming more normal, as we are finding most signed malware to be associated with UK businesses.
Source: https://www.bleepingcomputer.com/news/security/fake-pirate-chick-vpn-pushed-azorult-info-stealing-trojan/

