Microsoft Warns of Malware Hidden in Pirated Film Files
An active campaign inserts malicious VBScript into ZIP files posing as downloads for "John Wick 3," "Contagion," and other popular movies.
Microsoft researchers have detected an active malware campaign in which attackers embed a malicious payload into files bundled with pirated movies including "John Wick 3," "Contagion," and other popular films. The threat has reached at least tens of thousands of people in Spain, Mexico, and South America.
Attackers hide a malicious VBScript in the same ZIP folder as a movie download, Microsoft Security Intelligence wrote in a Twitter thread. These ZIP files have names including "contagio-1080p," "John_Wick_3_Parabellum," "Punales_por_la_espalda_BluRay_1080p," as well as Spanish titles like "La_hija_de_un_ladron" and "Lo-dejo-cuando-quiera." When someone clicks on one of these ZIP files, a VBScript is launched that runs a command to download more components, including an AutoIT script. This decodes a second-stage DLL, which aims to inject coin-mining code directly into memory.
It's unclear who is behind the campaign, which began to appear in bootleg film files on April 11, CyberScoop reports. Microsoft says the use of torrent downloads is consistent with observations that indicate attackers are reusing old techniques to take advantage of the coronavirus pandemic. With more people staying at home to stop the spread of COVID-19, attackers are using popular movies as bait. It seems the focus here is distribution in Spain and Spanish-speaking countries such as Mexico and Chile; attackers don't seem to be hitting US film pirates with this campaign.
Read more details here.
A listing of free products and services compiled for Dark Reading by Omdia analysts to help meet the challenges of COVID-19.
About the Author(s)
You May Also Like
Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024Safeguarding Political Campaigns: Defending Against Mass Phishing Attacks
May 16, 2024Why Effective Asset Management is Critical to Enterprise Cybersecurity
May 21, 2024Finding Your Way on the Path to Zero Trust
May 22, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024