Microsoft Warns of Malware Hidden in Pirated Film FilesMicrosoft Warns of Malware Hidden in Pirated Film Files
An active campaign inserts malicious VBScript into ZIP files posing as downloads for "John Wick 3," "Contagion," and other popular movies.
April 30, 2020
Microsoft researchers have detected an active malware campaign in which attackers embed a malicious payload into files bundled with pirated movies including "John Wick 3," "Contagion," and other popular films. The threat has reached at least tens of thousands of people in Spain, Mexico, and South America.
Attackers hide a malicious VBScript in the same ZIP folder as a movie download, Microsoft Security Intelligence wrote in a Twitter thread. These ZIP files have names including "contagio-1080p," "John_Wick_3_Parabellum," "Punales_por_la_espalda_BluRay_1080p," as well as Spanish titles like "La_hija_de_un_ladron" and "Lo-dejo-cuando-quiera." When someone clicks on one of these ZIP files, a VBScript is launched that runs a command to download more components, including an AutoIT script. This decodes a second-stage DLL, which aims to inject coin-mining code directly into memory.
It's unclear who is behind the campaign, which began to appear in bootleg film files on April 11, CyberScoop reports. Microsoft says the use of torrent downloads is consistent with observations that indicate attackers are reusing old techniques to take advantage of the coronavirus pandemic. With more people staying at home to stop the spread of COVID-19, attackers are using popular movies as bait. It seems the focus here is distribution in Spain and Spanish-speaking countries such as Mexico and Chile; attackers don't seem to be hitting US film pirates with this campaign.
Read more details here.
A listing of free products and services compiled for Dark Reading by Omdia analysts to help meet the challenges of COVID-19.
About the Author(s)
You May Also Like
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication MethodsOct 26, 2023
Modern Supply Chain Security: Integrated, Interconnected, and Context-DrivenNov 06, 2023
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023
Passwords Are Passe: Next Gen Authentication Addresses Today's Threats
How to Deploy Zero Trust for Remote Workforce Security
What Ransomware Groups Look for in Enterprise Victims
How to Use Threat Intelligence to Mitigate Third-Party Risk
Securing the Remote Worker: How to Mitigate Off-Site Cyberattacks