What's Happening?
Censys has identified a new cyberattack method where malicious payloads are delivered through seemingly legitimate MP4 video files. These fake MP4s, while structurally valid enough to pass basic file-type checks, are unplayable and contain encrypted NetSupport
client data. The attack chain begins with a PowerShell loader served as raw text/html, which then retrieves the fake MP4 from the same host. This MP4 file, typically 6.5 MB, embeds a 16.8 MB compressed PowerShell script within a 'uuid' box, which constitutes 99.95% of the file. The script then deploys the NetSupport client, a legitimate remote administration tool often abused by threat actors, and establishes persistence on the victim's system. The delivery infrastructure involves Cloudflare-fronted hosts and command-and-control (C2) domains registered in close succession, often using Russian-language business sites as decoys.
Why It's Important?
This method of malware delivery is significant because it leverages a common file type (MP4) to bypass traditional security measures that might only perform superficial file-type checks. The use of a legitimate remote administration tool like NetSupport Manager for malicious purposes makes detection and attribution more challenging, as its presence might not immediately trigger alarms. The attack's ability to establish persistence and communicate with C2 servers through seemingly innocuous channels poses a substantial threat to data security and privacy for individuals and organizations. The coordinated infrastructure deployment, including decoy websites, indicates a sophisticated and organized threat actor, highlighting the evolving landscape of cyber threats and the need for advanced detection capabilities beyond basic file validation.
What's Next?
Organizations and cybersecurity professionals will need to enhance their detection mechanisms to identify these sophisticated threats. This includes implementing deeper file analysis that goes beyond basic file-type checks to validate the actual playability or functionality of media files. Security solutions should focus on detecting anomalous file structures, such as MP4s with disproportionately large 'uuid' boxes or those that fail to decode properly. Furthermore, monitoring network traffic for unusual C2 communications, even from seemingly legitimate domains, will be crucial. Users should be educated about the risks of opening unexpected media files and the importance of robust endpoint security. The continuous rotation of carrier files by the attackers suggests an ongoing and adaptive threat that requires constant vigilance and updates to security protocols.
Beyond the Headlines
The use of fake MP4 files for malware delivery highlights a broader trend in cyber warfare: the increasing sophistication of social engineering and technical evasion techniques. This method exploits the trust users place in common file formats and the limitations of current security tools in performing deep content inspection. It also underscores the challenge of distinguishing legitimate software from malicious use, as NetSupport Manager is a valid tool. This could lead to a re-evaluation of how security software categorizes and flags applications, potentially impacting the usability of legitimate remote administration tools. The reliance on Cloudflare and decoy websites also points to the complex infrastructure threat actors build to obscure their origins, raising questions about the responsibility of service providers in mitigating such abuses and the need for international cooperation in tracking down these sophisticated operations.











