Think twice before installing this device promising free movies
摘要
安全研究人员发现,一类以提供免费影视资源为卖点的流媒体设备(如SuperBox)正被恶意攻击者利用。这些设备通过住宅代理网络,在用户不知情的情况下,将其家庭网络带宽用于转发犯罪甚至国家级攻击的恶意流量。用户虽获得免费内容,但设备极易被远程植入恶意应用,且攻击可在路由器后悄然完成。研究警告,市面上数十款类似设备均存在同等风险,用户应谨慎安装。
As online services get better at blocking malicious traffic, the attackers and scammers behind them have been forced to find new ways to reach their targets. The alternative of choice is now what are known as residential proxy networks. These systems funnel millions of home Internet connections into a unified network, and the proxy operators allow attackers to route their malicious traffic through these connections for a fee. The online services see only IP addresses with good reputations and geolocations that don’t stand out.
More often than not, the home users have no idea that their connections are being used to facilitate crime and occasionally even nation-state attacks. Users who do know often don’t care much. In exchange for leasing out part of their unlimited bandwidth to others, many get free movie and TV show streaming. Several less tech-savvy people I know who own such digital media players have told me, after I explain how the media players piggyback off their connections, that the bonanza of content is worth it. They find the tangible benefits outweigh the abstract harm they pose.
Infecting already compromised devices
Research published Monday brings the threat into much clearer view. Security firm Plume cataloged a vast ecosystem of malware that preys squarely on users of SuperBox, just one of many media players offering pirated content. These malicious apps can be surreptitiously installed by remote attackers even when the devices are positioned behind a router. While Monday’s deep-dive analysis focused exclusively on SuperBox, Plume warned that dozens of similar streaming devices pose precisely the same threat.
转载信息
评论 (0)
暂无评论,来留下第一条评论吧