logo

The Video That Plays You: Fake MP4 File Carries Malicious Payload

ID: 958e9527-b108-5795-8a1d-7dba07b9fcbd

STIX ID: report--958e9527-b108-5795-8a1d-7dba07b9fcbd

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2026-08-28

Date Updated: 2026-08-29

...
...

Censys ARC observed an active multi-stage delivery chain that serves raw PowerShell droppers and a fake MP4 carrier (containing an XOR key and compressed PowerShell in an ISO-BMFF uuid box) from Cloudflare-fronted and direct hosts; the chain decrypts and executes a NetSupport Manager client configured for silent operation and connects to WebSocket-based C2 gateways. The report documents 18 distinct builds across ~40 live stage-1 endpoints, lists carrier URLs, payload and dropped-file hashes, persistence markers (SecurityHealth Run key, ProgramData run-once marker), and detection/mitigation insights for identifying anomalous MP4 carriers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.