Rampant Kodi Malware? Itâs Time to Either Put Up or Shut Up
Faced with a tsunami of pirated movies and TV shows being accessed at will through millions of piracy-enabled set-top boxes, entertainment industry groups have had to come up with a new anti-piracy strategy.
The main goal seems to demonize these devices in the press, creating the impression that anyone using them puts themselves in danger, either due to fire risk or exposure to the perils of viruses and malware.
These claims are perfect tabloid material. Newspapers, particularly in the UK, gobble up press releases and quickly spin them out, whether they have any substance to them or not. While thereâs little evidence that the scare stories are working as a deterrent among the pirating masses, they are a continuous source of irritation for those who know better.
This week a new Kodi-related video appeared on YouTube. Filmed at the RSA conference and presented by CyberScoop editor Greg Otto, it consists of a short interview with Kurtis Minder, CEO of security company GroupSense. âHow malware is growing on the Kodi/XMBC platformâ was the topic.
After a brief introduction on so-called âKodi boxesâ, Otto put it to Minder that his company had been looking into the âmalware that has been floating through these boxesâ and asked him to elaborate.
Minder said his company started its research around two months ago, working with the Digital Citizens Alliance (DCA). Of course, DCA has been one of the main sources of Kodi-related malware stories, ostensibly for the protection of consumers.
However, DCA is affiliated with the entertainment industries and there is little doubt theyâre being used to promote an anti-piracy agenda. There is nothing inherently wrong with companies trying to protect their content, of course, but doing so in a way that has the potential to mislead the public is bound to raise questions.
Back to the video, Minder told interviewer Otto that his company had been looking at âwhat the attack footprint would be for malware on the media that would show up on any given Kodi box that would be in someoneâs home.â
Itâs a curious statement to talk about the streaming media itself providing an attack vector but Minder doubled down, stating that theyâd discovered several places on the dark web âwhere people are selling malware-enabled media.â
Otto didnât ask Minder to elaborate on these claims and Minder didnât respond to TFâs request for comment, so we still have no idea what heâs referring to. However, Otto did pour fuel on the confusion by asking Minder about malware which requires capabilities that no âKodi boxâ has.
âWhat happens with [that malware]? Is it a RAT [Remote Access Trojan] that takes over a TV that hooks up to a camera and is almost like spyware? Is it ransomware? What are we seeing?â he asked the security expert.
âSome of that is [to be determined], we donât know exactly what all of it does,â Minder responded. âBut we do know there is a fair amount that enable DDoS capability from the boxes.â
We have no idea what constitutes a âfair amountâ of malware but it sounds like multiple instances. Here on TF back in 2017, we broke the news that a single Kodi addon was programmed to repeatedly visit the websites of rivals.
In that single case, the architect of that addon quickly apologized for his actions, the whole thing was concluded inside a week, and we havenât heard of any similar incident since. But Minder said there are additional risks too.
âThere is malware that will actually take over some of the components. We donât know to what extent, if itâs actually listening to the people in the room or not, that stuff hasnât really been netted out,â he told Otto.
Indeed, such a thing has never been reported anywhere, not least since âKodi boxesâ donât have microphones. But after more prompting from Otto, Minder then went on to talk about Kodi installed on platforms other than Android devices. His revelations about supposed âKodi malwareâ in this respect are also controversial.
âThe delivery mechanism [for the malware] appears to be two primary ways. Itâs the Kodi platform itself, which means whatever you load that on. For instance, if you did load that on an [Amazon] Firestick it could still be effective as an attack vector. The other one is the streaming media itself. Embedded in the media itself there are some malware variants,â he said.
As far as we know, malware embedded in streaming media that can be consumed via Kodi or indeed any regular media player is unheard of these days. Nathan Betzen, President of the XBMC Foundation, the group behind Kodi, told TorrentFreak that at least as far as he is aware, such a thing doesnât exist.
âIâve never heard of malware in a video stream. I guess anything is possible, but to my knowledge, there have been no reports to that effect,â Betzen said.
Bogdan Botezatu, Senior E-threat Analyst at BitDefender, also told TorrentFreak that heâd seen nothing like that in the wild.
âMalformed video could leverage vulnerabilities in the player itself, but Iâm not aware of such attacks happening in the wild,â Botezatu told us.
âActually, the last time I saw malicious videos distributed via torrent websites was years ago, back in the days when Trojan.Wimad was making the headlines.â
Trojan.Wimad was a trojan discovered in 2005 that was able to download remote files from websites by exploiting the Digital Rights Management (DRM) technology available in Windows. The trojan got onto usersâ computers as a licensed-protected video file. Kodi users are certainly not interested in those and in any case, Android-based Kodi boxes are unaffected.
So, apart from the addon incident that lasted for a week in 2017, weâve never heard of a live Kodi-related malware attack anywhere in the wild. Betzen told us that heâd heard of an instance where a coin miner had spread via third-party code but thatâs an issue for thousands of mainstream websites too.
All that being said, we arenât known as security experts, so we asked security firm AVAST if they could provide information on all Kodi-related malware incidents they have on record.
âUnfortunately, we have not observed any Kodi-related malware risks in the wild,â AVAST Communications Manager Stefanie Smith told TorrentFreak.
Bogdan Botezatu at BitDefender also had no specific instances to report.
âThere has been a lot of attention towards Kodi in the past year and most of the âsecurity risksâ go around the fact that some addons allow users to stream media directly from websites, so this is mostly a legal issue rather than a cyber-security one,â Botezatu said.
The BitDefender expert did, however, point us to a security advisory from CheckPoint which detailed a software vulnerability affecting Kodi, VLC, and other players using subtitles, which TF reported last year.
âKodi 17.1 was known to have been vulnerable to a subtitle parsing bug that allowed an attacker to remotely control the Kodi box. This is one of the most serious threats I know of because third parties could rig subtitles uploaded to various repositories and this would go unnoticed for a while,â he said.
While this vulnerability could have been used for nefarious purposes, there is no evidence of it ever being exploited in the wild. And, in common with all responsible platforms, Kodi and all others involved fixed the issue before any damage could be done.
Moving through our list of vendors, TorrentFreak also asked Symantec if they had ever encountered any actual Kodi-related malware. The company told us they had nothing to report at this time but did highlight the same subtitle vulnerability pointed out by BitDefender.
To be clear, vulnerabilities can affect any software, including Windows, but that doesnât make them inherently dangerous to the consumer as long as theyâre disclosed and then fixed in a responsible and timely manner.
However, listening to the entertainment industries and those aligned with them, Kodi use presents an active and serious malware danger to the public, but one with almost zero evidence to support it.
Minder himself didnât respond to our request for elaboration but we did manage to obtain a copy of a presentation his company prepared for the Conference of Western Attorneys General detailing supposed Kodi threats. The document, dated May 2018, makes for interesting reading.
Perhaps referencing the claims that Kodi malware is available on the dark web, the presentation slides show an advert discovered on the hidden âDream Marketâ marketplace. The advert offers subscriptions to an illicit IPTV service but itâs actually one thatâs easily accessible on the regular open web. Perhaps most importantly, there is no mention of malware anywhere on the slide.

The next slide proved interesting since it covers a topic first published here on TorrentFreak at the start of 2018. We revealed how some Kodi setups can be accessed by outside parties if users arenât careful about the settings for Kodiâs web interface. While this is a known issue, this has nothing to do with malware.
Finally, the last slide had this to say about Kodi and third-party Kodi addons.
âUnbeknownst to the consumer these thirdâparty addâons further introduces [users] to risks such as copyright violations, malware infection, disclosure of IP address and Internet behavior, and the loss of the confidentiality of their communications,â the slide reads (PDF).
While it canât be argued that copyright violations can take place, the ever-present malware claim isnât backed up by any publicly-available information indicating that such an event has happened more than once or twice. To put that into perspective, the AV-TEST Institute says it registers over 250,000 new malicious programs every day.
Furthermore, IP addresses are always disclosed no matter what content users access online, so that point is moot too, along with the supposed issues with confidentiality of communications. However, GroupSense has more to add.
âAdditionally, the communication between their Kodi application and the thirdâparty addâons are unencrypted and unauthenticated meaning that an attacker can introduce malicious code into the communication stream or compromise the thirdâparty addâon before the recipient (consumer) receives the data; thereby, infecting their device to incorporate into a botnet or steal privileged information such as user credentials,â the slide reads.
We presented these claims to TVAddons, the worldâs largest repository of third-party addons and the developer of many, past and present. They werenât impressed with the claims.
âThat argument is quite the stretch. Technically the same would apply to any website you visit that doesnât use forced-HTTPS. Almost every unofficial add-on repository is hosted through GitHub, which forces encryption,â the site said.
âKodi âboxesâ are used on home networks, not public Wi-Fi. By the time someone could perform a [Man-in-the-Middle] attack on your Kodi box, it would mean that they would have already had to compromise your router. If someone were to go through all that, they could likely do a lot more damage without even considering exploiting Kodi.
âFurthermore, most users use Kodi on their media boxes, where little to no privileged information would be present,â the site added.
Letâs be clear, every single piece of hardware and software, whether on or offline, can be exploited in some way by nefarious players or simply the curious. However, the persistent claim that Kodi users are somehow under constant malware attack isnât borne out by any publicly available information.
Indeed, one of the worldâs most popular anti-piracy vendors in AVAST says they have no record of ANY Kodi-related malware. And Marius Buterchi, PR Manager at the highly-respected BitDefender, couldnât point us to any specific instances either.
âI just talked with the Lab guys and they told me that they actually havenât seen any Kodi-related malware in the wild,â he told us Friday.
With that, it now seems the perfect time to either put up or shut up in respect of âKodi malware.â
If there is malware out there affecting users of Kodi, security and entertainment industry companies making these claims should back them up with solid evidence because, as it stands, the horror stories seem designed to frighten the masses, rather than protect them.
The benefits of full disclosure, detailing the EXACT NAMES of the malware, WHEN they were discovered and by WHO, and what EXACTLY THEY DO, would be two-fold.
Firstly, the aim of scaring people away from Kodi would have more impact, since the evidence of malware would be hard to ignore. That would be a big plus for the movie and TV industries who are quite rightly concerned about protecting their business.
Secondly, and just as importantly, Kodi users could take steps to protect themselves, which should be the number one priority of any group, organization, or company that claims to be acting in the best interests of consumers and the public in general.
With that in mind, we understand that the Digital Citizens Alliance will publish a new Kodi malware report in the coming weeks. Perhaps it will contain actual evidence of the malware being spoken of continuously in the media.
We would certainly welcome the publication of a specific and detailed list of all malware variants in the wild which specifically target Kodi users. At that point, we can alert the major anti-virus and malware vendors who currently appear to be strangely in the dark.
Buy a VPN stay safe online
IPV-ISP Tracking-728×90
Thank you to the original source https://torrentfreak.com/rampant-kodi-malware-its-time-to-either-put-up-or-shut-up-190610/




