US security firm InfoArmor has discovered an underground cyber-crime network called RAUM, which allows malware creators to pack their malicious payloads inside torrent files and automate their distribution.
The network is supposedly run by an Eastern European group calling itself the “Black Team.”
InfoArmor says Black Team monitors global piracy trends and uses fake or hacked accounts on popular torrenting portals to upload torrents containing the malware.
It then uses the same fake/hacked accounts, along with various distribution methods, to boost the reputation of malicious torrents, in order to appear at the top of users' searches and create more chances of spreading their malicious payload.
Malware writers can create accounts on the RAUM service by paying a small fee and going through a rigorous vetting and evaluation process. After that, they can use RAUM's automated processes to upload their malware into torrent files. RAUM suggests which torrent files are currently popular, so that the success rates are higher!
Fraudsters can use RAUM to distribute legitimate software, as part of a PPI (Pay-per-Install) scheme, or to distribute malware, such as the Dridex banking trojan, Pony infostealer, or the Cerber, CryptXXX, and CTB-Locker ransomware families.
InfoArmos says that around 12 million users are infected with malware from torrents every month, through abusive torrent sites including Pirate Bay, ExtraTorrent, Demonoid and Kickass Torrents, before it shuts down.
Due to the complex distribution system used by RAUM, torrents containing malware often survive for more than 1.5 months.
The most common infected torrents involve online games and files related to Microsoft Windows and Mac OS activation.
Additionally, InfoArmor reports that RAUM also offers fake torrent websites to spread malicious torrents. The scammers drive traffic to these websites by infecting search engine results.
On September 17, both Google and Mozilla blacklisted “The Pirate Bay” in their browsers. InfoArmor says this latest warning came after the Safe Browsing team detected malicious torrents on The Pirate Bay that were created through the RAUM service.



