BitTorrent serves malware directly from website - no need for P2P!

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Sophos said:
According to a really-ought-to-be-more-visible warning on the download pages of bittorrent.com and utorrent.com, a breach of the two servers resulted in a two-hour window in which downloading BitTorrent's software would have given you a fake anti-virus program instead.

bt-breach-500.png


BitTorrent, Inc. identifies the malware as belonging to the Security Shield scareware family.

Confusingly, the BitTorrent blog has recently been updated to claim that the software available from the bittorrent.com URI was not affected, implying that only those who downloaded utorrent during the infection window would be at risk.

Since the two sites share the same network infrastructure - both resolve to the same IP number in Limelight Networks' cloud - you might want to ignore that blog update and assume that any recent downloads from Bittorrent, Inc. were dodgy and give yourself a thorough anti-malware checkover.

Read more
 
D

Deleted member 178

used utorrent since long time ago so im not one of the victim :D
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
On my parents laptop has utorrent but an old version so good to see the laptop isn't infected.
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
There's nothing wrong with uTorrent client software.

Would this have only affected direct downloads from their website and not from the built-in updater?

Thanks :D
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top