VSDC links served stealer chain
VSDC's official website replaced download links with attacker URLs on three days in 2018. Victims received JavaScript that staged a stealer, keylogger, and DarkVNC.
Story
The first documented VSDC compromise was a direct attack on the vendor website. Qihoo 360 reported that the official videosoftdev.com download links were changed on 2018-06-18, 2018-07-02, and 2018-07-06.
The substituted links did not serve the normal installer. They redirected users to 5.79.100.218/_files/file.php or drbillbailey.us/tw/file.php, where a JavaScript file posed as VSDC software. That script launched PowerShell and pulled additional payloads from attacker infrastructure.
The payload chain included AZORult Stealer, X-Key Keylogger, and DarkVNC. 360 described stolen data going to system-check.xyz; BleepingComputer also reported Telegram, Steam, Skype, Electrum, screenshots, keystrokes, and remote-control capability.
VSDC confirmed that attackers reached the administrative side of the website and tried to replace distribution-file links, while the distributives themselves were not damaged. The company said it restored site files, removed fake files, changed passwords, added two-factor access controls, and installed server-side file validation.
Affected Artifacts
- Observed
- 2018-06-18 to 2018-07-06
- Compromised Versions
- Unknown
- Fixed
- Not listed
- Evidence
- distribution: videosoftdev.com/free-video-editor/download, mirror: videosoftdev.com/news/attacks-successfully-stopped, url: hxxp://5.79.100.218/_files/file.php, url: hxxp://drbillbailey.us/tw/file.php , +8 more
- VSDC said the attackers replaced links to the distribution file, but the original distributives themselves were not damaged.
Incident Context
- Motive
- Financial Gain
- Attribution
- Group
- Cause
- Website Compromise
- Transitive
- No
- Actor
- Cybercriminal
External References
- Popular Software Site Hacked to Redirect Users to Keylogger, Infostealer, Morebleepingcomputer.com
- Famous software VSDC official website was hacked and affected more than 30 countriesblog.360totalsecurity.com
- VSDC Video Editor team has detected and stopped hacker attacks on the websitevideosoftdev.com
Source record: proprietary/vdsc/meta.yaml