Welcome to DU!
The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards.
Join the community:
Create a free account
Support DU (and get rid of ads!):
Become a Star Member
Latest Breaking News
Editorials & Other Articles
General Discussion
The DU Lounge
All Forums
Issue Forums
Culture Forums
Alliance Forums
Region Forums
Support Forums
Help & Search
Warning to CHaS DU'ers: "The Bizarro Streaming Site That Hackers Built From Scratch"
Note: There are no clickable links in my post of the article. If you go to that website, you bear 100% responsibility for all problems. In other words, do not go there !!
https://www.wired.com/story/bravomovies-fake-streaming-site-bazaloader/
The latest entrant in the streaming wars doesnt stock a deep library of classics, or buzzy original series. In fact, it wont play movies at all, no matter how many times you tap or click. But the creative minds behind BravoMovies likely arent deterred by those gaffes. Theyre criminal hackers, and their goal is not to deliver a rich home entertainment experience but to deposit malware on your computer.
The BravoMovies campaign, spotted by researchers at security firm ProofPoint, has been around since at least early May. While many of its elements seem absurd at a glancethe posters for nonexistent movies, the wince-inducing typosit shows just how far hackers are willing to go to ensnare their victims.
When you think of phishing campaigns, to the extent that you do at all, you probably picture email attachments laced with malware. Trouble is just one click away. But as email services get better at keeping suspicious messages out of your inbox in the first place, pulling off those campaigns isn't quite as simple anymore. Sidestepping those defenses takes increasing creativity.
And effort, if the group behind BravoMovies is any indication. Their fake streaming service is just one part of a convoluted, seven-step process to deliver a so-called backdoor called BazaLoader. They start with an email, sure. But it contains no malicious links, no tainted attachments that Gmail's sensors could sniff out. Instead, it simply informs you that your free trial period on BravoMoviesamongst the major streaming services on the planet!is coming to an end, and that your credit card is about to be charged for the premium plan. It helpfully provides a phone number to call if youd like to cancel.
The BravoMovies campaign, spotted by researchers at security firm ProofPoint, has been around since at least early May. While many of its elements seem absurd at a glancethe posters for nonexistent movies, the wince-inducing typosit shows just how far hackers are willing to go to ensnare their victims.
When you think of phishing campaigns, to the extent that you do at all, you probably picture email attachments laced with malware. Trouble is just one click away. But as email services get better at keeping suspicious messages out of your inbox in the first place, pulling off those campaigns isn't quite as simple anymore. Sidestepping those defenses takes increasing creativity.
And effort, if the group behind BravoMovies is any indication. Their fake streaming service is just one part of a convoluted, seven-step process to deliver a so-called backdoor called BazaLoader. They start with an email, sure. But it contains no malicious links, no tainted attachments that Gmail's sensors could sniff out. Instead, it simply informs you that your free trial period on BravoMoviesamongst the major streaming services on the planet!is coming to an end, and that your credit card is about to be charged for the premium plan. It helpfully provides a phone number to call if youd like to cancel.
Much more at link above
2 replies
= new reply since forum marked as read
Highlight:
NoneDon't highlight anything
5 newestHighlight 5 most recent replies
Warning to CHaS DU'ers: "The Bizarro Streaming Site That Hackers Built From Scratch" (Original Post)
steve2470
May 2021
OP
Wounded Bear
(61,108 posts)1. Thanks for the heads up...cross post in GD? nt
steve2470
(37,468 posts)2. feel free, I feel a bit hesitant about doing so
It's a bit geeky for GD.