Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
GoBotKR Targets Pirate Torrents to Build a DDoS Botnet
#1
Quote:A botnet dubbed GoBotKR is targeting fans of Korean TV, compromising computers via pirated copies of South Korean movies, games and TV shows available via Korean and Chinese torrent sites. Ultimately, the cybercriminals are building a network that can then be used to perform DDoS attacks of various kinds, according to an analysis from ESET.
 
While the torrents purport to be pirate versions of real content, they actually contain two malicious files (with deceptive filenames, extensions and icons), in addition to the expected MP4 file. The first is a malicious executable masked as a PMA archive file, with a filename mimicking various codec installers, according to ESET. The second is a malicious LNK file with a filename and icon mimicking the expected video file.
 
Clicking on the latter executes the malware, while also opening the MP4 and playing the expected content. “Directly opening the intended MP4 file will not result in any malicious action,” the researchers said in a posting on Monday. “The catch here is that the MP4 file is often hidden in a different directory, and users might encounter the malicious LNK file mimicking it first. Further increasing the chance of users falling for the lure is the fact that the extension of the LNK file is normally not displayed when viewed in Windows Explorer.”

SOURCE: https://threatpost.com/gobotkr-pirate-to...et/146285/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] EaseUS Todo Backup Home...
"Share feedback...dhruv2193 — 15:36
Brave 1.67.115
Release Channel 1....harlan4096 — 10:12
AV-Comparatives: Consumer Real-World Pro...
AV-Comparatives: Co...harlan4096 — 09:10
Microsoft Edge 126.0.2592.56
Version 126.0.2592...harlan4096 — 09:09
Google Chrome 126.0.6478.61/.62
Google Chrome 126....harlan4096 — 09:08

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (37)Tedscolo
avatar (44)brakasig
avatar (43)JamesReshy
avatar (45)Francisemefe
avatar (38)leoniDup
avatar (37)Patrizaancem
avatar (37)biobdam
avatar (38)storoBox
avatar (46)kinotHeemn
avatar (37)Ceballos1976
avatar (38)efynu

[-]
Online Staff
There are no staff members currently online.

>