meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Malware in pirated Windows installation files. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

News, Tech News, Daily News, Technology

4.81.1K Ratings

🗓️ 3 July 2021

⏱️ 14 minutes

🧾️ Download transcript

Summary

Guest Tom Roter from Minera Labs joins Dave to discuss his team research: "Rigging a Windows Installation." It is common knowledge that pirated software might contain malware, yet millions still put themselves and their devices at risk and download from dubious sources. It is even more surprising to see the popularity of torrented operating system installations, which are ranked at the top of most torrent tracker ranking lists. Today we will prove conventional wisdom right and show off a devious, yet clever attack chain employed by an infected Windows 10 image, frequently shared and downloaded by tens of thousands of users. Over the last year, numerous malicious PowerShell events popped up in our telemetry. The events caught our attention because a payload was being downloaded into the “C:\Windows” directory, which is usually well guarded under NTFS permissions, this implies that the attacker had very high privilege on the compromised system.  The research can be found here: Rigging a Windows installation Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire Network, powered by N2K.

0:07.0

Today's episode is sponsored by SRM, your first call for cybersecurity and

0:18.1

investigations. Threats today are evolving faster than ever before and since 2005 SRM has pioneered

0:25.3

tailored security solutions for global corporations and their executives.

0:29.5

Whether it's defending against cyber attacks with their award-winning team of ethical hackers and incident response specialists,

0:36.4

or navigating the murky waters of compliance and ESG challenges,

0:40.9

SRMs, Insight and Straight straightforward advice will help you navigate complex risks

0:46.4

and emerge more resilient.

0:48.4

Their secret, a culture that nurtures the sharpest minds, giving them access to the newest technologies and the freedom

0:55.3

to solve problems in new ways, enabling them to craft simple effective solutions for your

1:01.4

unique cyber challenges.

1:03.7

Search your first call to discover how SRM can help your business. Hello everyone and welcome to the CyberWire's Research Saturday.

1:27.0

I'm Dave Bitner and this is our weekly conversation with researchers and analysts tracking

1:31.7

down threats and vulnerabilities, solving some of the hard problems of protecting

1:36.1

ourselves in a rapidly evolving cyberspace.

1:39.4

Thanks for joining us. As part of our regular threat hunting, we saw some weird events, power shell events.

1:54.0

We saw them regularly for over a year.

1:58.0

Only when a user contacted us,

2:02.0

we figured out that the events are coming from a pirated windows installation.

2:07.0

That's Tom Roter. He's a security researcher at Minerva Labs. The research we're discussing today is titled

2:14.1

Rigging a Windows installation.

2:25.0

You can sense to glory. If this is started something.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.