Microsoft Warns of Malware Hidden in Pirated Film FilesMicrosoft Warns of Malware Hidden in Pirated Film Files
An active campaign inserts malicious VBScript into ZIP files posing as downloads for "John Wick 3," "Contagion," and other popular movies.
April 30, 2020

Microsoft researchers have detected an active malware campaign in which attackers embed a malicious payload into files bundled with pirated movies including "John Wick 3," "Contagion," and other popular films. The threat has reached at least tens of thousands of people in Spain, Mexico, and South America.
Attackers hide a malicious VBScript in the same ZIP folder as a movie download, Microsoft Security Intelligence wrote in a Twitter thread. These ZIP files have names including "contagio-1080p," "John_Wick_3_Parabellum," "Punales_por_la_espalda_BluRay_1080p," as well as Spanish titles like "La_hija_de_un_ladron" and "Lo-dejo-cuando-quiera." When someone clicks on one of these ZIP files, a VBScript is launched that runs a command to download more components, including an AutoIT script. This decodes a second-stage DLL, which aims to inject coin-mining code directly into memory.
It's unclear who is behind the campaign, which began to appear in bootleg film files on April 11, CyberScoop reports. Microsoft says the use of torrent downloads is consistent with observations that indicate attackers are reusing old techniques to take advantage of the coronavirus pandemic. With more people staying at home to stop the spread of COVID-19, attackers are using popular movies as bait. It seems the focus here is distribution in Spain and Spanish-speaking countries such as Mexico and Chile; attackers don't seem to be hitting US film pirates with this campaign.
Read more details here.
A listing of free products and services compiled for Dark Reading by Omdia analysts to help meet the challenges of COVID-19.
About the Author(s)
You May Also Like
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication Methods
Oct 26, 2023Modern Supply Chain Security: Integrated, Interconnected, and Context-Driven
Nov 06, 2023How to Combat the Latest Cloud Security Threats
Nov 06, 2023Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and Phishing
Nov 01, 2023SecOps & DevSecOps in the Cloud
Nov 06, 2023