December 14, 2021 By David Bisson 2 min read

Digital attackers are using Netflix’s popular series “Squid Game” as a lure for their malware campaigns and phishing operations.

Two Trojan Downloaders Targeting Fans

Kaspersky uncovered dozens of different malicious files related to Squid Game between September and October 2021, reported PC Mag.

In one of those attack instances, a user came across an animated version of the first game depicted in Netflix’s series. What the user didn’t know is that the campaign downloaded a trojan in the background. Once launched, that threat stole the user’s data from their web browser and exfiltrated it to a server under the attackers’ control.

The attack operation also created a shortcut in one of the victim’s folders. This ensured that the trojan would launch every time the victim’s system started up.

Another attack discovered by the security firm arrived in the form of a mobile malware threat relying on unofficial app stores and other portals for distribution. It tantalized a user with the prospect of downloading an episode from Squid Game. In reality, the user downloaded a trojan onto their device.

Other Squid Game Malware Findings from the Community

Kaspersky isn’t the only security firm that’s observed malicious actors using Squid Game as a lure for their attack campaigns.

In mid-October, for instance, Forbes reported on the discovery of a malicious Squid Game-themed wallpaper app that infiltrated Google’s Play Store.

With 5,000 downloads at the time of its discovery and removal by Google, the malware turned out to be a sample of the Joker Android malware family. This threat targeted victims with ad fraud and/or signed them up for premium SMS-based text message services.

It was just a few weeks later when Proofpoint flagged a campaign targeting all industries in the United States. The attack emails arrived with a Squid Game-themed subject line like “Squid game new season commercials casting preview” and “Squid game scheduled season commercials talent cast schedule”.

All the emails instructed the victim to download an attached document for the purpose of either obtaining early access to the new season of the show or for auditioning to become part of the background cast.

Those attachments consisted of macro-laden Excel documents. If enabled, those spreadsheets downloaded samples of the Dridex banking trojan.

How to Defend Against Squid Game-Themed Malware

Organizations can protect themselves against Squid Game-themed digital threats by cultivating their employees’ security awareness.

Businesses can remind their employees of general best practices, including checking the authenticity of a website before submitting any personal information or downloading anything by double-checking URL formats and the spellings of company names.

They can also instruct employees to avoid downloading suspicious files and to avoid interacting with links that promise early access to web content.

More from News

Insights from CISA’s red team findings and the evolution of EDR

3 min read - A recent CISA red team assessment of a United States critical infrastructure organization revealed systemic vulnerabilities in modern cybersecurity. Among the most pressing issues was a heavy reliance on endpoint detection and response (EDR) solutions, paired with a lack of network-level protections. These findings underscore a familiar challenge: Why do organizations place so much trust in EDR alone, and what must change to address its shortcomings? EDR’s double-edged sword A cornerstone of cyber resilience strategy, EDR solutions are prized for…

DHS: Guidance for AI in critical infrastructure

4 min read - At the end of 2024, we've reached a moment in artificial intelligence (AI) development where government involvement can help shape the trajectory of this extremely pervasive technology. In the most recent example, the Department of Homeland Security (DHS) has released what it calls a "first-of-its-kind" framework designed to ensure the safe and secure deployment of AI across critical infrastructure sectors. The framework could be the catalyst for what could become a comprehensive set of regulatory measures, as it brings into…

Apple Intelligence raises stakes in privacy and security

3 min read - Apple’s latest innovation, Apple Intelligence, is redefining what’s possible in consumer technology. Integrated into iOS 18.1, iPadOS 18.1 and macOS Sequoia 15.1, this milestone puts advanced artificial intelligence (AI) tools directly in the hands of millions. Beyond being a breakthrough for personal convenience, it represents an enormous economic opportunity. But the bold step into accessible AI comes with critical questions about security, privacy and the risks of real-time decision-making in users’ most private digital spaces. AI in every pocket Having…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today