Proprietary 2018-06-18 · 18 days ·Credential Theft, Keylogging, Remote Access, Malware Delivery

VSDC links served stealer chain

VSDC's official website replaced download links with attacker URLs on three days in 2018. Victims received JavaScript that staged a stealer, keylogger, and DarkVNC.

Story

The first documented VSDC compromise was a direct attack on the vendor website. Qihoo 360 reported that the official videosoftdev.com download links were changed on 2018-06-18, 2018-07-02, and 2018-07-06.

The substituted links did not serve the normal installer. They redirected users to 5.79.100.218/_files/file.php or drbillbailey.us/tw/file.php, where a JavaScript file posed as VSDC software. That script launched PowerShell and pulled additional payloads from attacker infrastructure.

The payload chain included AZORult Stealer, X-Key Keylogger, and DarkVNC. 360 described stolen data going to system-check.xyz; BleepingComputer also reported Telegram, Steam, Skype, Electrum, screenshots, keystrokes, and remote-control capability.

VSDC confirmed that attackers reached the administrative side of the website and tried to replace distribution-file links, while the distributives themselves were not damaged. The company said it restored site files, removed fake files, changed passwords, added two-factor access controls, and installed server-side file validation.

Affected Artifacts

VSDC Free Video Editor

windows installer · videosoftdev.com · Binary Archive
Observed
2018-06-18 to 2018-07-06
Compromised Versions
Unknown
Fixed
Not listed
Evidence
distribution: videosoftdev.com/free-video-editor/download, mirror: videosoftdev.com/news/attacks-successfully-stopped, url: hxxp://5.79.100.218/_files/file.php, url: hxxp://drbillbailey.us/tw/file.php , +8 more
  • VSDC said the attackers replaced links to the distribution file, but the original distributives themselves were not damaged.

Incident Context

Motive
Financial Gain
Attribution
Group
Cause
Website Compromise
Transitive
No
Actor
Cybercriminal

External References

Source record: proprietary/vdsc/meta.yaml