Malicious actors are bundling a Trojan that looks like a virtual private network (VPN) tool into adware to install malware on infected machines. The Trojans operators distribute the supposed VPN tool through adware bundles and bogus Adobe Flash Player updates. It appears the perpetrators are targeting users in specific geographies, since the payload is not executed if the IP address is based in Ukraine, Belarus, Kazakhstan or Russia. It also steers clear of users running certain kinds of virtualization applications, including HyperV, Virtualbox.”]