Romance Scam Delivers Malware Hidden In ‘Lovely Photos’ File

Image by Joshua Reddekopp, from Unsplash

Romance Scam Delivers Malware Hidden In ‘Lovely Photos’ File

Reading time: 2 min

A new cyberattack is targeting German speakers with adult-themed romance scams, secretly delivering malware.

In a rush? Here are the quick facts:

  • The attack targets German speakers using adult-themed romance scam emails.
  • Emails contain links to ISO malware hosted on Russian servers.
  • Keitaro TDS filters victims by location and time.

According to Sublime Security, the attackers use two deceptive links to entice victims by luring them via a romantic email.

The first link looks like a video preview image, yet the second link leads to a disguised archive file. If clicked, the system checks if the user is in Germany. If so, it downloads a 300MB ISO file from a Russian server.

The researchers explain that the attackers use Keitaro TDS, a commercial traffic distribution system, to target users during their working hours through this malicious campaign.

“Keitaro is able to view many characteristics of the computer, making the request and providing connection paths,” Sublime explained. This targeted precision increases the chances of success.

Once downloaded, the ISO file evades detection by inflating its size. When mounted, it reveals a file called ‘lovely_photos.exe’ and a text file with a password. Running the file prompts the user for that password, which triggers the extraction of explicit images and multiple malicious files.

The malware builds an AutoIt interpreter to run a heavily disguised script, designed to bypass antivirus software. “The final AutoIt script is extensively obfuscated […] over 11,500 lines of code,” Sublime noted. The script installs itself as a scheduled Windows task called DragonMapper, ensuring the malware runs every time the user logs in.

This campaign highlights the increasing sophistication of social engineering attacks and how threat actors are now combining adult scams with anti-analysis techniques and legitimate tools like AutoIt and Keitaro TDS to remain undetected.

Did you like this article? Rate it!
I hated it I don't really like it It was ok Pretty good! Loved it!

We're thrilled you enjoyed our work!

As a valued reader, would you mind giving us a shoutout on Trustpilot? It's quick and means the world to us. Thank you for being amazing!

Rate us on Trustpilot
0 Voted by 0 users
Title
Comment
Thanks for your feedback