Cybercriminals steal passwords through movie websites

Last update: 11/03/2025
Author Isaac
  • A sophisticated malvertising attack has been detected by Microsoft, affecting nearly one million devices.
  • Attackers use GitHub repositories to deploy malware and obtain confidential information from users.
  • The main objective of the attack is to steal credentials stored in web browsers.
  • Microsoft has removed the malicious repositories and recommends security measures such as two-factor authentication and the use of VPNs.

Cyberattack on movie websites

The proliferation of cyber attacks has become a growing concern for Internet users, especially in unsafe sitesA new report from Microsoft has revealed a sophisticated strategy of Cybercrime that takes advantage of websites of downloads of movies and series to distribute malware in order to steal credentials stored in browsers.

According to the Microsoft Threat Intelligence team, a campaign has been identified malvertising, a method that employs malicious advertising to lure unsuspecting users and redirect them to fraudulent sites. In this case, the attackers used GitHub repositories as a malware distribution platform, which allowed compromising almost a million devices within a short period of time. This type of attack is similar to phishing that has been identified on other platforms, as explored in a recent article on the new password-stealing phishing attack.

How the attack works

How malware works on movie websites

The procedure used by cybercriminals follows a multi-stage structureIt all starts with ads infiltrated into websites offering free movies and TV shows. These malicious ads redirect users through multiple intermediary sites until they finally reach a fake website designed to trick them.

In this last phase, users are directed to a GitHub repository, where a malicious file disguised as a ransomware is hosted update or useful tool. When downloaded, a first code is executed that starts the infection, allowing the download of other files designed to gather informationIt is crucial for users to be on the lookout for this type of virus, as it is not the only one that has been detected recently; other cases include infected games that have compromised users' security.

  How to apply confidentiality labels to Microsoft 365 documents

The data obtained includes details such as the RAM system, graphics specifications, operating system and paths storage. In addition, the malware establishes a connection with controlled servers by attackers, allowing the download of new dangerous components.

malware-ridden game on Steam-0
Related articles:
Malware-infected game sneaks onto Steam before being removed

Objective: Obtain stored credentials

One of the main objectives of this attack is Steal credentials stored in browsers, such as social media passwords, emails and bank accounts. To achieve this, the malware implements a system of multi-level redirects, ensuring persistence and difficulty of detection.

After infection, attackers can access sensitive information and use it for various criminal purposes, from identity theft to the sale of credentials in the Dark webThese types of attacks are particularly dangerous because many people use the same passwords for different accounts, making it easy to access multiple compromised services. For this reason, it is advisable to use a good antivirus that can help prevent infections like this.

Additionally, it is always smart to check out the available protection methods, such as Windows Defender and other antivirus, to ensure your computer is protected against cyber threats.

windows defender is compatible with other antivirus-2
Related articles:
Is Windows Defender compatible with other antivirus?

Recommended protective measures

Given the increasing use of advanced tactics by cybercriminals, Microsoft has recommended several measures to mitigate these types of threats:

  • Avoid downloading content from unofficial sources: Free movie websites are often a hotbed of such attacks. It is best to stick to trusted platforms.
  • Use two-step authentication: This makes it difficult for third parties to access the accounts, even if they obtain the password.
  • Update systems and browsers: Keeping your software up to date helps reduce exploitable vulnerabilities.
  • Install reliable security software: A good antivirus can detect suspicious files before they are executed.
  • Review passwords stored in browsers and change them periodically: Additionally, it is advisable to use password managers to generate secure and unique passwords for each service.
free antivirus
Related articles:
The best free antivirus to protect your computer

With more and more sophisticated cyber threats on the rise, it is crucial for users to remain cautious and adopt safe browsing habits. This new attack demonstrates how cybercriminals are taking advantage of popular trends, such as free movie sites, to trick thousands of people into giving away valuable information. Raising awareness and implementing cybercriminals can help reduce the risk of cybercriminals from using their internet browsing habits. appropriate protective measures can make the difference between being the victim of an attack or staying safe online.

microsoft 365 password theft-0
Related articles:
Microsoft 365 in the spotlight: new phishing attack steals passwords