Mollywood: Subtitles as an attack vector
Elham Arshad, Giuliano Turri, Bruno Crispo · 2022 IEEE Symposium on Computers and Communications (ISCC) · 2022
Online subtitle repositories manage a huge amount of subtitle files for a variety of movies/TV-shows in 88 different languages and are available to the public to download and upload. Given the popularity of these repositories, we study the subtitle providers (STP) ecosystem by identifying and analyzing the involved parties. Our observations reveal that these STPs seem to be one of the most widespread and easily accessed resources to be potentially abused by attackers. Therefore, due to the features of STP ecosystem, they could be considered as a new attack vector through the subtitle files. However, all potentials of this new attack vector have not been yet exploited. Due to the rise of cryptojacking attacks substantially, this paper shows how a vulnerability present in a popular streaming platform can be exploited to perform a cryptojacking attack using the malicious subtitles delivered by STPs.