December 14, 2021 By David Bisson 2 min read

Digital attackers are using Netflix’s popular series “Squid Game” as a lure for their malware campaigns and phishing operations.

Two Trojan Downloaders Targeting Fans

Kaspersky uncovered dozens of different malicious files related to Squid Game between September and October 2021, reported PC Mag.

In one of those attack instances, a user came across an animated version of the first game depicted in Netflix’s series. What the user didn’t know is that the campaign downloaded a trojan in the background. Once launched, that threat stole the user’s data from their web browser and exfiltrated it to a server under the attackers’ control.

The attack operation also created a shortcut in one of the victim’s folders. This ensured that the trojan would launch every time the victim’s system started up.

Another attack discovered by the security firm arrived in the form of a mobile malware threat relying on unofficial app stores and other portals for distribution. It tantalized a user with the prospect of downloading an episode from Squid Game. In reality, the user downloaded a trojan onto their device.

Other Squid Game Malware Findings from the Community

Kaspersky isn’t the only security firm that’s observed malicious actors using Squid Game as a lure for their attack campaigns.

In mid-October, for instance, Forbes reported on the discovery of a malicious Squid Game-themed wallpaper app that infiltrated Google’s Play Store.

With 5,000 downloads at the time of its discovery and removal by Google, the malware turned out to be a sample of the Joker Android malware family. This threat targeted victims with ad fraud and/or signed them up for premium SMS-based text message services.

It was just a few weeks later when Proofpoint flagged a campaign targeting all industries in the United States. The attack emails arrived with a Squid Game-themed subject line like “Squid game new season commercials casting preview” and “Squid game scheduled season commercials talent cast schedule”.

All the emails instructed the victim to download an attached document for the purpose of either obtaining early access to the new season of the show or for auditioning to become part of the background cast.

Those attachments consisted of macro-laden Excel documents. If enabled, those spreadsheets downloaded samples of the Dridex banking trojan.

How to Defend Against Squid Game-Themed Malware

Organizations can protect themselves against Squid Game-themed digital threats by cultivating their employees’ security awareness.

Businesses can remind their employees of general best practices, including checking the authenticity of a website before submitting any personal information or downloading anything by double-checking URL formats and the spellings of company names.

They can also instruct employees to avoid downloading suspicious files and to avoid interacting with links that promise early access to web content.

More from News

Research finds 56% increase in active ransomware groups

4 min read - Any good news is welcomed when evaluating cyber crime trends year-over-year. Over the last two years, IBM’s Threat Index Reports have provided some minor reprieve in this area by showing a gradual decline in the prevalence of ransomware attacks — now accounting for only 17% of all cybersecurity incidents compared to 21% in 2021. Unfortunately, it’s too early to know if this trendline will continue. A recent report released by Searchlight Cyber shows that there has been a 56% increase in…

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

CISA and FBI release secure by design alert on cross-site scripting 

3 min read - CISA and the FBI are increasingly focusing on proactive cybersecurity and cyber resilience measures. Conjointly, the agencies recently released a new Secure by Design alert aimed at eliminating cross-site Scripting (XSS) vulnerabilities, which have long been exploited to compromise both data and user trust. Cross-site scripting vulnerabilities occur when a web application improperly handles user input, allowing attackers to inject malicious scripts into web pages that are then executed by unsuspecting users. These vulnerabilities are dangerous because they don't attack…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today