Back to Intel

Intel Node

Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years

lowapt2026-05-28T06:55:11+00:00source excerpt
aptmalwaretradecraft

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Our experts continue to track attacks targeting consumers of pirated content, both books and movies. 2026 saw the discovery of new target sites with tens of millions of visitors, while the miner gained a RAT module.

Introduction In late April 2026, a client reached out to us for incident response support after discovering a miner running on users’ computers. We later discovered that the malware was being distributed via illegal movie and TV show streaming sites. The infection chain leveraged a fake update for a video player plugin. When the user attempted to watch a video, the player displayed a message saying the plugin version was outdated and asking to install an update to continue. Clicking the link downloaded a ZIP archive with the following contents: The archive contained a legitimate executable, HLS Installer. 874.

exe , alongside a malicious DLL. Launching the EXE triggered a DLL side-loading mechanism, injecting the malicious module into a legitimate program process and executing code within its context.

Read Original Source