News

Pirated Windows 10 ISOs Include Hidden Malware

In a classic case of ‘play stupid games win stupid prizes’, it has been found that pirated copies of Windows 10 have been distributed containing malware hidden within the EFI partition.

Pirated Windows Copies Containing Malware

As reported by Bleepingcomputer.com, hackers have distributed Windows 10 using torrents which have hidden cryptocurrency hijackers within them. The malware was hidden within the Extensible Firmware Interface partition (EFI) which is a partition that contains the bootloader and related files before the OS starts and in turn is hidden from most anti-virus programs. The malware was discovered and explained by researchers at drweb.com who found that it does not execute from the EFI but instead uses the partition as a hidden place to store the infected files.

How Does it Work?

The malware consists of three stages starting with Trojan.MulDrop22.7578 which launches via the system Task Scheduler and has the goal of mounting an EFI system partition to the M:\ drive and copy two other malicious components onto it. After it does this it deletes the original trojan from the C:\ drive launches the next stage under trojan.inject4.57873 and unmounts the EFI partition. TrojanInject4.57873 then uses the Process Hollowing technique to inject Trojan.Clipper.231 into the Lsaiso.exe system process taking control. The malware then monitors the clipboard and substitutes crypto wallet addresses copied into it with attacker-provided addresses.

The researchers say that using the EFI partition as a method of malware infiltration is a very rare attack vector and is of great interest to security professionals. The researchers have also estimated that Trojan.Clipper.231 has so far managed to steal 0.73406362 BTC and 0.07964773 ETH which is around $18,976.29 a fairly hefty sum of cash.

I know Windows is expensive but at least with a reliable source, you don’t get hit with one of these.

Jakob Aylesbury

Disqus Comments Loading...

Recent Posts

S.T.A.L.K.E.R. 2: Heart of Chornobyl Gets A New Trailer

While I'm not familiar with the Bilibili streaming platform, it was the source of a…

8 hours ago

Jensen Huang to Kick Off Computex 2024 With NVIDIA Keynote

As Computex 2024 approaches, the tech industry buzzes with anticipation for a series of high-profile…

1 day ago

MSI Prioritizes NVIDIA Over AMD as RX 7000 GPU Supplies Vanish

MSI, a key player in the graphics card market, appears to be shifting its focus…

1 day ago

TeamGroup Clinches Four Red Dot Awards for Innovative Design

TeamGroup has once again proven its prowess in the field of memory product innovation by…

1 day ago

eFootball Hits Major Milestone with 750 Million Downloads

Konami's eFootball has reached a staggering 750 million downloads worldwide. This milestone comes as the…

1 day ago

Manor Lords Is Out Now On Steam, Epic and Gamespass!

Just a few hours after its release on Steam alone Manor Lords has already managed…

2 days ago