Friday, December 20, 2019

Kaspersky sees a sky-rise of droppers with phishing and malware attacks surface amid premiere of famous space saga

According to research from Kaspersky, the latest and final film of the trilogy has drawn the attention of attackers even before the premiere, with fraudulent websites and malicious files of the yet-to-be-released film flooding the web. Popular films are often used by cybercriminals as bait to distribute malware, and the latest movie saga from ‘a galaxy far, far away’ is no exception. 

Films are one of the main forms of entertainment users seek to access for free, which creates fertile soil for cyberattacks. Online streaming, torrents and other methods of digital distribution often infringe upon content copyright, and yet they remain popular as a source of free content. 


Torrent-trackers and illegal streaming platforms pose a threat to users’ cyber-safety, since they can host malicious files, masked behind the name of movie files. Given this tendency, Kaspersky studied how the sci-fi franchise’s name is being abused by cybercriminals in order to fool fans.

Public attention on “Star Wars: The Rise of Skywalker,” which premieres Dec. 19, is already attracting cybercriminals. Kaspersky researchers found over 30 fraudulent websites and social media profiles disguised as official movie accounts (the actual number of these sites may be much higher) that supposedly distribute free copies of the latest film in the franchise. These websites collect unwary users’ credit card data, under the pretense of necessary registration on the portal.


The domains of websites used for gathering personal data and spreading malicious files usually copy the official name of the film and provide thorough descriptions and supporting content, thereby fooling users into believing that the website is, in some way, connected to the official film. 

Such practice is called “black SEO,” which enables criminals to promote phishing websites high up in search engine results (such results often show up for search terms such as ‘name-of-the-film watch free’).

To further support the promotion of fraudulent websites, cybercriminals also set up Twitter and other social media accounts, where they distribute links to the content. Coupled with malicious files shared on torrents, this brings the criminals results. So far, 83 users have already been affected by 65 malicious files disguised as copies of the upcoming movie.

Phishing is not the only way cybercriminals tend to utilize popular film franchises. Just as with TV shows, they often disguise malicious programs as yet another episode of the story. In 2019, Kaspersky detected 285,103 attempts to infect 37,772 users seeking to watch movies of the renowned space-opera series, a 10 percent rise compared to last year. The number of unique files used to target the users amounted to 11,499, a 30 percent drop from last year.

“It is typical for fraudsters and cybercriminals to try to capitalize on popular topics, and ‘Star Wars’ is a good example of such a theme this month,” said Tatiana Sidorina, security researcher at Kaspersky. “As attackers manage to push malicious websites and content up in the search results, fans need to remain cautious at all times. We advise users to not fall for such scams and instead enjoy the end of the saga on the big screen.”


Users have been advised to take the following steps by paying attention to the official movie release dates in theaters, on streaming services, TV, DVD, or other sources; avoid clicking on suspicious links, such as those promising an early view of a new film; and paying special attention to the downloaded file extension. The file should have an .avi, .mkv or .mp4 extension, among other video formats, and not the suspicious .exe extension.

Consumers must check the website’s authenticity, and avoid visiting websites to watch a movie until they are sure that they are legitimate and start with ‘https.’ Confirm that the website is genuine by double-checking the format of the URL or the spelling of the company name, reading reviews about it and checking the domains’ registration data before starting downloads. It also uses reliable security solution, such as Kaspersky Security Cloud, for comprehensive protection from a range of threats.

No comments:

Post a Comment

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...