4 ms·
The topics seem interesting but I'm having a lot of trouble parsing the contents of the article > The malware launches a Powershell command, which then inserts
by tobias__ 8y ago
The topics seem interesting but I'm having a lot of trouble parsing the contents of the article
> The malware launches a Powershell command, which then inserts malicious code into the Firefox browser. The attack is designed to infect movie torrent files and is also meant to infect Windows computers in particular. The point of the attack is to phish for any Bitcoin or Ethereum addresses that the user might have. It’s an advanced virus as it then actually aims to replace these victims addresses with the hacker’s wallet.
Not sure where torrent come into this at all, for example
- themodelplumber 8y agoSo far I've got: Download a movie --> Magic Happens --> Powershell --> Firefox compromised! --> We infected your torrents! --> Ah, found your crypto. --> Your address is now replaced with my wallet!! Ha ha!
- Dylan16807 8y agoBased on the tweets, step two is that the "movie" is actually a shortcut file. The shortcut runs powershell with a short obfuscated command that downloads the malware payload. Then it does a variety of normal malware stuff.
- rasz 8y agoexcept there is no movie