Microsoft Warns of Malware Hidden in Pirated Film Files

An active campaign inserts malicious VBScript into ZIP files posing as downloads for "John Wick 3," "Contagion," and other popular movies.



Microsoft researchers have detected an active malware campaign in which attackers embed a malicious payload into files bundled with pirated movies including "John Wick 3," "Contagion," and other popular films. The threat has reached at least tens of thousands of people in Spain, Mexico, and South America.

Attackers hide a malicious VBScript in the same ZIP folder as a movie download, Microsoft Security Intelligence wrote in a Twitter thread. These ZIP files have names including "contagio-1080p," "John_Wick_3_Parabellum," "Punales_por_la_espalda_BluRay_1080p," as well as Spanish titles like "La_hija_de_un_ladron" and "Lo-dejo-cuando-quiera." When someone clicks on one of these ZIP files, a VBScript is launched that runs a command to download more components, including an AutoIT script. This decodes a second-stage DLL, which aims to inject coin-mining code directly into memory. 

It's unclear who is behind the campaign, which began to appear in bootleg film files on April 11, CyberScoop reports. Microsoft says the use of torrent downloads is consistent with observations that indicate attackers are reusing old techniques to take advantage of the coronavirus pandemic. With more people staying at home to stop the spread of COVID-19, attackers are using popular movies as bait. It seems the focus here is distribution in Spain and Spanish-speaking countries such as Mexico and Chile; attackers don't seem to be hitting US film pirates with this campaign.

Read more details here.

A listing of free products and services compiled for Dark Reading by Omdia analysts to help meet the challenges of COVID-19. 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Email This  | 
Print  | 
RSS
More Insights
Copyright © 2020 UBM Electronics, A UBM company, All rights reserved. Privacy Policy | Terms of Service