Watch out — those movie downloads could actually just be vicious new Windows malware
Be careful when looking for pirated movies online – experts have warners many files are out there just to infect your Windows PCs with dangerous malware and infostealers.
Cybersecurity researchers from Mandiant have recently discovered a new malware dropper, infecting victims with Lumma Stealer, Hijack Loader, and CryptBot.
Lumma, for example, is a known piece of malware that’s been extensively covered by the media. It is capable of grabbing passwords stored in popular browsers, cookies, credit card information, and data related to cryptocurrency wallets. Lumma is offered as a service, for a subscription fee ranging between $250 and $1,000.
Downloading malware
The dropper is dubbed PEAKLIGHT. It appears to be brand new, and works as a memory-only dropper: “This memory-only dropper decrypts and executes a PowerShell-based downloader,” Mandiant said in a technical write-up.
The researchers saw the dropper in .ZIP archives on the internet, pretending to be pirated movies. These archives contained a Windows shortcut file (.LNK) which, when ran, connects to a content delivery network (CDN) hosting an obfuscated, memory-only, JavaScript.
“PEAKLIGHT is an obfuscated PowerShell-based downloader that is part of a multi-stage execution chain that checks for the presence of ZIP archives in hard-coded file paths,” Mandiant added. “If the archives do not exist, the downloader will reach out to a CDN site and download the remotely hosted archive file and save it to disk.”
Pirated content, including movies, music, software, and books, have been used to distribute malware for years. During the Covid lockdowns, as people were stuck inside and looking for ways to kill the time, many turned to pirated content – and hackers took advantage, distributing malicious cryptocurrency-mining malware via fake film torrents.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The movie John Wick: Chapter 3 – Parabellum – which was a blockbuster hit at the time, was one of the movies used to distribute malware.
Via The Hacker News
More from TechRadar Pro
Be careful when looking for pirated movies online – experts have warners many files are out there just to infect your Windows PCs with dangerous malware and infostealers. Cybersecurity researchers from Mandiant have recently discovered a new malware dropper, infecting victims with Lumma Stealer, Hijack Loader, and CryptBot. Lumma, for…
Recent Posts
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
- Wave Cash App’s Magic Wand to Pay for Stuff
- Marshall Milton ANC review: Making the rare case for premium on-ear headphones
- Belkin’s new Joy-Con grips also boost the Switch 2’s battery life
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023