Ten years have passed since this technique was first observed online and used to spread a simple trojan, but it seems that the developers of this malware are still abusing it.
ten years ago , Windows users were surprised and annoyed to discover that Windows Media Player's DRM package could be used to deliver malware to its users.
Whenever the user tried to play a file that was DRM-protected in Windows Media Player, the application displayed a pop-up window, asking the user to access an official URL that would verify their license or allow them to purchase a license and view the file's content.
Scammers who pirate movies and songs via KaZaA or eMule discovered that they could lock their files with a DRM pop-up, but instead of the official URL, they could insert a link to the malware.
Ten years later, and according to a report from cybersecurity vendor Cyren, this technique is still in use today.
This time, a modified video file (“War-Dogs-2016-720p-BrRip-x264-SiNNERS”) is used for a pirated movie that asks users to verify their licenses.
When users click the “Yes” button to open the URL, another pop-up window will appear that uses a very convincing message, telling users that they need a newer code to view the video file.
For its part, Microsoft , addressing this attack, included a warning in the initial DRM pop-up window that reads as follows:
"Web pages can contain elements that could be harmful to your computer. It is important to be certain that the content is from a trustworthy source before continuing."
Technically, the company couldn't have done more than that, as any other modifications would have broken the DRM functionality. Microsoft needs to continue its efforts on this attack, and hopefully users will be smart enough to figure out where a potential social engineering scam is lurking.


