Trojan horses and malware that we commonly see on the Internet, or are generally familiar with, are either for money or for users’ personal information. Their goals are very clear and easy for people to understand (understand, not understand). Recently, a security research unit discovered a piece of malware that seems to be the strangest in recent times. Its motivation and purpose are completely beyond our understanding of viruses. Instead, it makes people feel that this is justice for the villagers.

The weirdest malware that prevents users from accessing websites where pirated software can be downloaded
exist A recent report from SophosLabsShared this malware similar to “lynching”, researchers pointed out that this malware pretends to be a pirated software executable file and spreads through Discord or pirated download websites. It does not try to get the password from your computer, nor does it ask you for ransom. Instead, it modifies the host file of the infected device to prevent users from accessing the most popular pirated software download websites, such as The Pirate Bay.

Its propagation method is modeled after the file model on pirated software download websites. The entire file contains reload files, NFO files, shortcut files to return to The Pirate Bay, and readme files. However, many files included in it have no function and are only used to fill in the files to make it look like ordinary pirated software files. Once the user downloads and executes it, it will modify the Windows host file to add a lot of code and blacklist many pirated software download websites. When you try to access a URL in the list, you will be redirected to the attacker’s local host and unable to connect to the actual IP address of the target URL, effectively preventing users from going to pirated software websites.

▲ Host file modified by vigilante malware
Worse yet, when the malware is executed, it connects to a remote host controlled by the attacker and sends false reports of the name of the pirated software that infects the user. Since web servers usually record the IP address of visitors, an attacker can obtain both your IP and the name of the software and video you are trying to download. Although we don’t know what this information is used for, if it falls into the wrong hands, it can become a vector for further attacks, such as email scams.
◎Data source:Bleeping Computer
Source: KOCPC Chinese