Researchers at Kaspersky have found malware hidden in a modified version of the anonymity-preserving Tor Browser, distributed in a way that specifically targets users in China.Beneath the video, one URL links to the official Tor website (which is blocked in China); another provides a link to a cloud-sharing service that hosts an installer for Tor, modified to include malicious code.When the second-stage malware is installed on a target machine, it retrieves details like the computer’s GUID — a unique identifying number — along with system name, current user name, and MAC address (which identifies the machine on a network).All of this information is sent to a remote server, and according to Kaspersky’s analysis, this server can also request data on the system’s installed applications, browser history — including the fake Tor Browser — and the IDs of any WeChat and QQ messaging accounts present on the computer.The best protection against this kind of attack is to download software only from a trusted source — in this case, the official Tor Project portal — but China’s extensive internet censorship makes this difficult for many users in the country."