HomeSecurityMegaupload domains "serve" malware

Megaupload domains are “serving” malware

Megaupload domains are “serving” malware

Three years ago, the US government seized some of Megaupload's domains, which now direct visitors to malware scams and ads.

These domains  Megaupload[dot]com and Megavideo[dot]com are used by cybercriminals to distribute malware and carry out scams.

Megaupload domains "serve" malware

The domains redirect visitors to Zero-Click advertising feeds, which are loaded with malicious links to malware installers and other malicious ads.

Many of these redirects try to "trap" visitors by telling them they have a chance to win an iPhone in a very simple way. One of these malicious ads promotes a link that is allegedly from a BBC article, and which offers an iPhone 6 for just one dollar!!

It is said that the reason behind the exploitation of these domains is the failure of the FBI's cybercrime unit to check the main nameserver, which was previously registered with the Cyber ​​Initiative and Resource Fusion Unit (CIRFU).

Megaupload domains "serve" malware

CIRFU.biz, the domain name for Megaupload.com, is on a server in the Netherlands and hosted by LeaseWeb, and the domain CIRFU.net has Syndk Media Limited as the registrant.

It appears that Megaupload and Megavideo serve malicious ads, which are made by third parties, since the domain used as a nameserver by the Ministry of Justice has either expired or has been taken over by other means, and is no longer part of the government.

In addition to these domains, a few poker sites have been hijacked in the past. These domains are absolutepoker.com and ultimatebet.com, which are now linked and serving malicious content.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS