Spotify: cómo los cibercriminales la utilizan para distribuir malware

ESET, compañía líder en detección proactiva de amenazas, advierte que ciberdelincuentes están usando Spotify para camuflar links maliciosos en descripciones de podcasts y listas, aprovechando su reputación y nivel de indexación en resultados de búsquedas. Estos links llevan a sitios fraudulentos con la promesa de descarga de software crackeado, e-books o monedas virtuales de juegos online como Fortnite. Uno de los atractivos de la plataforma para los atacantes es que cuenta con más de 600 millones de usuarios mundiales, entre los que Latinoamérica representa el 22 por ciento.

Desde ESET ya hemos advertido en otras oportunidades sobre cómo este tipo de amenazas se esconden en cuentas de YouTube robadas, en cracks y cheats de video juegos, o que se diseminaban en descripciones de videos en YouTube. Se trata de una práctica que siempre está vigente ya que se aprovecha del interés general por los contenidos y software gratuitos, beneficiándose del mejor posicionamiento en los resultados de búsqueda que le dan estas páginas conocidas.”, explica Camilo Gutiérrez Amaya, Jefe del Laboratorio de Investigación de ESET Latinoamérica.

Como se puede observar en la siguiente imagen, al realizar una búsqueda en Google sobre un crack específico, aparecen resultados que llevan directamente a Spotify, e incluso a un link para descargar una versión pirata de esta app:

Imagen 1: Resultados de búsquedas de Google.

Al ingresar al link de la supuesta descarga del crack para iTopVPN, este lleva a un podcast que tendrá en su descripción varios links que conducen a la descarga del supuesto crack del software prometido alojado en un popular servicio de almacenamiento en la nube.

El equipo de ESET analizó los archivos que se descargan mediante esta ruta y, revisando los resultados de Virustotal, se puede observar que se trata de un instalador (archivo MSI) que es detectado como contenido malicioso por soluciones de seguridad como las de ESET. Este tipo de detección está relacionada con códigos maliciosos que derivan en la instalación de adware, que llenarán el dispositivo de publicidad en popups y redirigen a sitios maliciosos, incluso llevando a la descarga de malware más peligroso.

Imagen 3: Resultado de análisis en virustotal.

Hace unas semanas, distintos usuarios de la red social X reportaron otros ejemplos de este tipo de distribución, donde detectaron enlaces maliciosos en la descripción de varios podcasts en Spotify. Los enlaces simulan ser links para descargar audiolibros o material pirata similar.

Si un usuario se encuentra ante una descripción en la plataforma que lleva a un link falso, e incluso que promociona contenido ilegal o pirata, una opción para denunciarlo es en el apartado de soporte al usuario de la misma aplicación.

ESET recomienda seguir una serie de buenas prácticas para reducir el riesgo de caer en este tipo de engaños:

  • Evitar interactuar con enlaces sospechosos. Si algo parece demasiado bueno para ser verdad, lo más probable es que sea un engaño.
  • Denunciar contenido malicioso.
  • Usar soluciones de seguridad confiables. Mantener actualizado el sistema y la solución antimalware y escanear los archivos descargados antes de abrirlos.
  • Ser crítico al buscar contenido gratuito. Enlaces a software pirateado, e-books o audiolibros gratuitos suelen ser un señuelo común.

Los ciberdelincuentes adaptan sus estrategias para llegar a los usuarios e intentar engañarlos. Utilizar plataformas legítimas como Spotify, que indexan mejor en buscadores web, es una de sus estrategias para distribuir malware. Es importante mantener el estado de alerta y evitar descargar software de fuentes no oficiales, y nunca hacer clic en enlaces dudosos.”, señala el investigador de ESET.

Para conocer más sobre seguridad informática visite el portal de noticias de ESET: https://www.welivesecurity.com/es/cibercrimen/como-utilizan-spotify-distribuir-malware-podcasts-listas/

53 Replies to “Spotify: cómo los cibercriminales la utilizan para distribuir malware”

  1. If you are actually a driver in Chicago, securing the appropriate auto insurance coverage is
    actually important for your tranquility of thoughts. Auto
    insurance coverage in Chicago may aid protect you in case of a crash, fraud,
    or even weather-related problems. Constantly be sure your plan satisfies both
    your requirements and spending plan when considering auto insurance in Chicago.

    A detailed customer review of your choices is actually essential to discovering the very best auto insurance policy in Chicago.

  2. If you are actually a chauffeur in Las Vegas, possessing Car Insurance in Las Vegas Nevada is actually crucial for your protection. The price of Car Insurance in Las Vegas Nevada could be lowered through deciding on a greater insurance deductible.
    Some insurer give unique fees for brand new consumers of Car
    Insurance in Las Vegas Nevada. Always go through the particulars before
    purchasing Car Insurance in Las Vegas Nevada to ensure it
    fulfills your demands.

  3. Heey there! I know this iis kiinda offf topoic buut I was wondering which bblog ppatform are you using for this site?
    I’m getting fed uup off Wordpess because I’ve had issuees with hckers
    and I’m lookiung att alternatives forr nother platform.
    I woulpd bee great iif yoou coujld point mme in the direction of a gold platform.

  4. Hi, I do thiink thiis is aan excelleent blog. I stumbledupon itt 😉 I may comee back yet again snce I book marked it.
    Mney annd freedomm iss the bdst waay tto change, mayy you bbe ridh annd continue too
    help others.

  5. Hi there, I discovered your site by way of Google while looking for a similar matter, your web
    site came up, it seems good. I have bookmarked it in my google bookmarks.

    Hi there, just turned into alert to your weblog through Google, and located
    that it is really informative. I’m going to watch out for brussels.
    I’ll appreciate should you continue this in future. Lots
    of folks will probably be benefited out of your
    writing. Cheers!

  6. When picking Auto Insurance in Las Vegas Nevada, look at the credibility of
    the service provider. It is very important to opt for a provider with a tough
    monitor report for customer support as well as professes taking care of when purchasing Auto Insurance
    in Las Vegas Nevada. Reading assessments as
    well as obtaining recommendations may aid you find the
    very best carrier for Auto Insurance in Las Vegas Nevada.
    A reliable carrier guarantees you’ll possess support when you require it very most under
    your Auto Insurance in Las Vegas Nevada plan.

  7. Thanks for your personal marvelous posting! I certainly enjoyed reading it, you can be a great author.
    I will be sure to bookmark your blog and may come back sometime soon. I want to encourage continue your great writing, have a nice evening!

  8. Sweet blog! I found it while browsing on Yahoo News. Do you have
    any tips on how to get listed in Yahoo News? I’ve been trying for a while
    but I never seem to get there! Thanks

  9. Oh my goodness! Impressive article dude!

    Thanks, However I am experiencing difficulties with your RSS.
    I don’t know why I am unable to subscribe to it. Is there anybody else getting the same
    RSS problems? Anybody who knows the answer can you kindly respond?
    Thanks!!

  10. Simply want to say your article is as astounding.

    The clarity in your post is just spectacular and i could assume you’re an expert on this
    subject. Fine with your permission let me to grab your feed to keep up to date with forthcoming post.
    Thanks a million and please keep up the rewarding work.

  11. Good post. I learn something new and challenging on sites I
    stumbleupon everyday. It will always be helpful to read through articles from other writers and use a
    little something from other web sites.

  12. I don’t know whether it’s just me or if everyone else encountering issues with your site.

    It looks like some of the written text on your content are running off
    the screen. Can somebody else please comment and let me know if this is happening to them too?
    This may be a problem with my web browser because
    I’ve had this happen previously. Many thanks

  13. Hmm is anyone else having problems with the images on this blog loading?
    I’m trying to determine if its a problem on my end or if it’s the blog.

    Any feed-back would be greatly appreciated.

  14. Nice weblog here! Also your website quite a bit up very fast!
    What host are you using? Can I get your affiliate hyperlink to your
    host? I desire my web site loaded up as quickly as yours lol

  15. I think what you composed was very logical. But, what
    about this? what if you wrote a catchier title? I am not suggesting your information is not solid., but what if you added something that makes people want more?

    I mean Spotify: cómo los cibercriminales la utilizan para distribuir malware – Carlos Meneses
    is a little vanilla. You might look at Yahoo’s front page and note how
    they create news titles to get viewers interested. You might add a video
    or a related picture or two to grab people excited about everything’ve written.
    Just my opinion, it would make your website a little bit
    more interesting.

  16. Yesterday, while I was at work, my cousin stole my apple ipad and tested to see if it can survive a thirty foot drop, just so she can be a youtube sensation. My apple ipad is now
    destroyed and she has 83 views. I know this is entirely off topic but I had to share it with someone!

  17. Heey there, I think youjr website might bee
    hhaving browzer compatibility issues. When I loook at youur bkog site iin Opera, it looks fin bbut wen opening in Internet Explorer, it hass some overlapping.

    I just wantted to giv yoou a quick heads up! Otjer thwn that, wonderful blog!

  18. Admiring the hard work you put into your site and in depth
    information you present. It’s good to come across a blog every once in a while that isn’t the same old rehashed
    information. Great read! I’ve saved your site and I’m including
    your RSS feeds to my Google account.

  19. Fantastic beat ! I wish to apprentice while you amend your
    web site, how can i subscribe for a blog website? The account helped me
    a acceptable deal. I had been tiny bit acquainted of this your broadcast provided
    bright clear concept

  20. Hello my loved one! I want to say that this article is amazing, great written and come with almost all significant
    infos. I’d like to look more posts like this .

  21. After going over a number of the blog posts on your website, I seriously like your way
    of writing a blog. I book marked it to my bookmark site list and will be checking back in the
    near future. Take a look at my website too and tell
    me how you feel.

  22. whoah this blog is excellent i really like studying your posts.
    Stay up the great work! You realize, lots of persons
    are searching round for this information, you could aid them greatly.

  23. Hey there would you mind stating which blog platform you’re using?
    I’m looking to start my own blog soon but I’m having a hard time
    choosing between BlogEngine/Wordpress/B2evolution and Drupal.
    The reason I ask is because your design and style
    seems different then most blogs and I’m looking for something completely unique.
    P.S Sorry for being off-topic but I had to ask!

  24. Hmm is anyone else having problems with the images on this blog loading?
    I’m trying to determine if its a problem on my end or
    if it’s the blog. Any feed-back would be greatly appreciated.

  25. I was curious if you ever thought of changing the page layout of your blog?
    Its very well written; I love what youve got to say. But maybe you could a little more in the way of content so people could connect with it
    better. Youve got an awful lot of text for only having 1 or
    two images. Maybe you could space it out better?

  26. Hello, Neat post. There’s a problem along with your web site in web explorer, may check this?
    IE nonetheless is the marketplace leader and a big component to other people will
    miss your magnificent writing due to this problem.

  27. Thanks for another great article. Where else may just anybody get that kind of info in such a perfect means of writing?

    I’ve a presentation next week, and I’m at the look
    for such information.

  28. hello!,I like your writing very a lot! share we keep in touch more about your article on AOL?
    I need an expert in this space to unravel my problem.
    May be that is you! Having a look forward to look you.

Agregue un comentario

Su dirección de correo no se hará público.