Censys Reports Malicious Payload Delivered via Fake MP4 Files
Censys has identified a new cyberattack method where malicious payloads are delivered through seemingly legitimate MP4 video files. These fake MP4s, while structurally valid enough to pass basic file-type checks, are unplayable and contain encrypted NetSupport client data. The attack chain begins with a PowerShell loader served as raw text/html, which then retrieves the fake MP4 from the same host. This MP4 file, typically 6.5 MB, embeds a 16.8 MB compressed PowerShell script within a 'uuid' box, which constitutes 99.95% of the file. The script then deploys the NetSupport client, a legitimate remote administration tool often abused by threat actors, and establishes persistence on the victim's system. The delivery infrastructure involves Cloudflare-fronted hosts and command-and-control (C2) domains registered in close succession, often using Russian-language business sites as decoys.