Symantec security researchers are warning of an ongoing malware distribution campaign that is interested in pirated games to install PUAs (Potentially Unwanted Applications) on users' computers.
The company identified websites offering popular games for download in the form of a fake torrent file. When users tried to download this fake torrent file, they received a small script that attempted to run automatically.
This file uses an icon that resembles the regular uTorrent BitTorrent client, leading users to believe that it is a legitimate torrent file.
Under normal circumstances, the script should be stopped by the Windows UAC (User Access Control) system. The hackers took precautions by providing instructions before downloading the script, telling users that they should allow the script to run, despite the UAC warning.
If users allow it, the script will open the user's browser, navigate to a URL, and download another file.
This file contains the name of the game that the user tried to download via the torrent file, but it was "packaged" as an EXE file.
As usual, technically savvy users would have spotted something wrong with this torrent download routine a long time ago, but these campaigns are not targeting them.
Scammers successfully use these tactics against users with less knowledge of modern technologies or, in this case, those who are not regular users of BitTorrent software.
Symantec reports that the specific EXE file distributed through this recent campaign installs PUAs on users' computers, in the form of applications that change the browser and install custom browsers that insert advertisements on every page.
For this campaign, cheaters using lures for games such as World of Warcraft: Legion (Blizzard Entertainment), Assassin's Creed Syndicate (Ubisoft), The Witcher 3: Wild Hunt (CD Projekt), Tom Clancy's The Division (Ubisoft), Just Cause 3 (Square Enix) and The Walking Dead: Michonne (Telltale Games).
“ Symantec believes that the perpetrators behind this campaign are trying to stay under the radar by abusing the numerous pay-per-install corporate programs,” explains . “Although this campaign only spreads PUA downloaders, the same distribution model can also be used to deliver additional security risks or even malware.”

