.jpg)
Image: James Pond
Attackers are actively exploiting the hype around the new Star Wars: The Rise of Skywalker movie as a bait designed to lure potential victims on fake streaming sites and steal their credit card data.
Given that the movie will be released in theaters on December 20, phishers have the perfect decoy to attract fans who would want to get an early look at the new Star Wars movie.
Highly popular films are often used as baits in social engineering attacks that would draw the attention fans with the promise of an early preview either on decoy streaming sites or with the help of malicious files camouflaged as early release movie copies.
Over 30 sites used in credit card phishing attacks
"Kaspersky researchers found over 30 fraudulent websites and social media profiles disguised as official movie accounts (the actual number of these sites may be much higher) that supposedly distribute free copies of the latest film in the franchise," a press release published today says.
"These websites collect unwary users’ credit card data, under the pretense of necessary registration on the portal."
Kaspersky's research team also found 65 malicious files that were camouflaged as copies of the Star Wars: The Rise of Skywalker movie, as well as several profiles on Twitter and other social media platforms disguised as official accounts that distribute free copies of the movie and promote the malicious streaming sites.
Actually, instead of getting a free pirated copy of the new Star Wars installment, the victims would get their computers infected with malware.
"Coupled with malicious files shared on torrents, this brings the criminals results," Kaspersky says. "So far, 83 users have already been affected by 65 malicious files disguised as copies of the upcoming movie."
| “Star Wars”-themed malware attacks | |||
| 2018 | 2019 | Change | |
| Attacks detected | 257580 | 285103 | 10.00% |
| Number of unique files | 16395 | 11499 | -30.00% |
| Users targeted | 50196 | 37772 | -25.00% |
Star Wars fans advised to proceed with caution
The researchers also found that the hype surrounding this movie franchise fueled such attacks throughout 2019, with 285,103 attempts to infect 37,772 users seeking to watch Star Wars movies being detected by Kaspersky this year, accounting for a 10% rise compared to last year.
Overall, the number of unique malicious files used by attackers to target Star Wars fans reached 11,499 in 2019, representing a 30% drop from 2018.
Kaspersky recommends movie and TV show fans to follow the following guidelines to avoid getting infected with malware or getting their credit card data stolen:
• Don’t click on suspicious links, such as those promising an early view of a new film
• Look at the downloaded file extension. Even if you are going to download a video file from a source you consider trusted and legitimate, the file should have a .avi, .mkv or .mp4 extension, among other video formats, definitely not .exe
• Check the website’s authenticity. Do not visit websites allowing you to watch a movie until you are sure that they are legitimate and start with ‘https.’ Confirm that the website is genuine by double-checking the format of the URL or the spelling of the company name, reading reviews about it and checking the domains’ registration data before starting downloads
• Use a reliable anti-malware solution
"It is typical for fraudsters and cybercriminals to try to capitalize on popular topics, and ‘Star Wars’ is a good example of such a theme this month," Kaspersky security researcher Tatiana Sidorina states.
"As attackers manage to push malicious websites and content up in the search results, fans need to remain cautious at all times. We advise users to not fall for such scams and instead enjoy the end of the saga on the big screen."
