December 14, 2021 By David Bisson 2 min read

Digital attackers are using Netflix’s popular series “Squid Game” as a lure for their malware campaigns and phishing operations.

Two Trojan Downloaders Targeting Fans

Kaspersky uncovered dozens of different malicious files related to Squid Game between September and October 2021, reported PC Mag.

In one of those attack instances, a user came across an animated version of the first game depicted in Netflix’s series. What the user didn’t know is that the campaign downloaded a trojan in the background. Once launched, that threat stole the user’s data from their web browser and exfiltrated it to a server under the attackers’ control.

The attack operation also created a shortcut in one of the victim’s folders. This ensured that the trojan would launch every time the victim’s system started up.

Another attack discovered by the security firm arrived in the form of a mobile malware threat relying on unofficial app stores and other portals for distribution. It tantalized a user with the prospect of downloading an episode from Squid Game. In reality, the user downloaded a trojan onto their device.

Other Squid Game Malware Findings from the Community

Kaspersky isn’t the only security firm that’s observed malicious actors using Squid Game as a lure for their attack campaigns.

In mid-October, for instance, Forbes reported on the discovery of a malicious Squid Game-themed wallpaper app that infiltrated Google’s Play Store.

With 5,000 downloads at the time of its discovery and removal by Google, the malware turned out to be a sample of the Joker Android malware family. This threat targeted victims with ad fraud and/or signed them up for premium SMS-based text message services.

It was just a few weeks later when Proofpoint flagged a campaign targeting all industries in the United States. The attack emails arrived with a Squid Game-themed subject line like “Squid game new season commercials casting preview” and “Squid game scheduled season commercials talent cast schedule”.

All the emails instructed the victim to download an attached document for the purpose of either obtaining early access to the new season of the show or for auditioning to become part of the background cast.

Those attachments consisted of macro-laden Excel documents. If enabled, those spreadsheets downloaded samples of the Dridex banking trojan.

How to Defend Against Squid Game-Themed Malware

Organizations can protect themselves against Squid Game-themed digital threats by cultivating their employees’ security awareness.

Businesses can remind their employees of general best practices, including checking the authenticity of a website before submitting any personal information or downloading anything by double-checking URL formats and the spellings of company names.

They can also instruct employees to avoid downloading suspicious files and to avoid interacting with links that promise early access to web content.

More from News

3,000 “ghost accounts” on GitHub spreading malware

3 min read - In the past, cyber criminals directly distributed malware on GitHub using encrypted scripting code or malicious executables. But now threat actors are turning to a new tactic to spread malware: creating ghost accounts. A highly effective malware campaign Check Point Research recently exposed a new distribution-as-a-service (DaaS) network, referred to as the Stargazers Ghost Network, that has been spreading malware on GitHub for at least a year. Because the accounts perform typical activities as well, users did not realize that…

Warren Buffett’s warning highlights growing risk of cyber insurance losses

3 min read - The United States cyber insurance industry continues to see strong profits, according to Fitch Ratings. Average premium increases, meanwhile, have moderated over the last three years: While 2021 saw a 34% jump in premium pricing and costs rose 15% in 2022, increases were under 1% in 2023.As noted by the Fitch Ratings report, "segment underwriting profitability at current levels is unsustainable as cyber insurance pricing is likely to remain flat or down going forward." While this is good news for…

New CISA guidance for organizations adopting Single Sign-On

4 min read - The Cybersecurity and Infrastructure Security Agency (CISA) recently conducted a comprehensive study of various small and medium-sized businesses to help identify common challenges and opportunities associated with Single Sign-On (SSO) adoption. SSO has garnered considerable chatter across several industries, especially regarding its ability to improve security while extending a certain level of convenience to employees using this protocol. However, it hasn’t yet been widely adopted as a best practice standard. Some businesses rave about SSO's security benefits, while others are…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today