Open Menu
AllLocalCommunitiesAbout
lotide
AllLocalCommunitiesAbout
Login

Fake ‘One Battle After Another’ torrent hides malware in subtitles

⁨68⁩ ⁨likes⁩

Submitted ⁨⁨2⁩ ⁨days⁩ ago⁩ by ⁨cm0002@suppo.fi⁩ to ⁨cybersecurity@infosec.pub⁩

https://www.bleepingcomputer.com/news/security/fake-one-battle-after-another-torrent-hides-malware-in-subtitles/

source

Comments

Sort:hotnewtop
  • someguy3@lemmy.world ⁨2⁩ ⁨days⁩ ago

    When the CD shortcut is executed, it launches Windows commands that extract and run a malicious PowerShell script embedded in the subtitle file between lines 100 and 103.

    This PowerShell script will then extract numerous AES-encrypted data blocks from the subtitles file again to reconstruct five PowerShell scripts that are dropped to ‘C:\Users<USER>\AppData\Local\Microsoft\Diagnostics.’

    The extracted PowerShell scripts act as a malware dropper, performing the following actions on the host:

    …

    source
    • RunJun@lemmy.dbzer0.com ⁨2⁩ ⁨days⁩ ago

      Very interesting. Since I left windows, this isn’t an issue for me but I will be more aware that this can happen now.

      source
      • FlexibleToast@lemmy.world ⁨2⁩ ⁨days⁩ ago

        Kind of makes me want to install Clam AV just to watch for viruses I wouldn’t otherwise know about because I’m using Linux everywhere.

        source
        • -> View More Comments
      • Decq@lemmy.world ⁨1⁩ ⁨day⁩ ago

        There isn’t really anything new to learn here. It’s still the same old, don’t run an executable to watch a movie. That the code is partly hidden in the srt/jpg is just a minor implementation detail.

        source
  • asbestos@lemmy.world ⁨2⁩ ⁨days⁩ ago

    Very interesting approach

    source
  • altkey@lemmy.dbzer0.com ⁨2⁩ ⁨days⁩ ago

    She said what now?

    surprised penguin

    source
    • REDACTED@infosec.pub ⁨2⁩ ⁨days⁩ ago

      We get it, you vape use arch

      source
  • chicken@lemmy.dbzer0.com ⁨2⁩ ⁨days⁩ ago

    So wait, literally all it took was putting command line commands on their own line in a subtitles file? Am I interpreting this right

    source
    • ticoombs@reddthat.com ⁨2⁩ ⁨days⁩ ago

      No/yes. in a text file, there are commands to run, and then made a script to run those commands. They then make the script look like a “double click this to get it to work”. Nothing new

      source
      • chicken@lemmy.dbzer0.com ⁨2⁩ ⁨days⁩ ago

        oh, so it wasn’t a video player having an absurd exploit then

        source
  • Mongostein@lemmy.ca ⁨1⁩ ⁨day⁩ ago

    Why would you try to open a movie with .m2ts ??

    source