Authored by a Symantec employee

 

Attackers are setting their sights on stealing users’ Netflix credentials in order to sell them on the black market, providing access to the streaming service for less expensive prices.

Netflix’s popularity has grown a great deal since its launch in 1997. The company recently launched its streaming service globally, and it is now available in more than 190 regions around the world. As a result, this has attracted the attention of cybercriminals.

Attackers are using two methods to try to gain user credentials:

Malware disguised as Netflix

This malware campaign involves attackers using malicious apps posing as Netflix on compromised computers’ desktops. These files are most likely downloaded by users who may have been tricked by fake advertisements or offers of free or cheaper access to Netflix.

Phishing for Netflix credentials

In addition to attempting to obtain the login credentials through malware, attackers may target Netflix users via phishing campaigns. Phishing is essentially a con game and phishers are nothing more than tech-savvy con artists. In this particular case, they use spam emails to try to trick people into divulging Netflix account credentials. Since Netflix subscriptions allow between one and four users on the same account, an attacker could piggyback on a user’s subscription without their knowledge.

In these phishing campaigns, attackers redirect users to a fake Netflix website in order to trick users into providing their login credentials, personal information, and payment cards details. Luckily, fake websites are easy to spot, as the creators don’t spend a lot of time building them. These sites contain easy to spot errors, such as grammatical and spelling mistakes.

Graphics are missing, unprofessional, or just look bad. When in doubt, look for the padlock in the URL.

How to stay protected:

  • Only download the Netflix application from official sources such as the Google Play Store or Windows Store. There is currently no app available for Apple computers.
  • Steer clear of services that appear to offer Netflix for free or a reduced price, as they may contain malicious files or steal data.
  • Additionally, Norton Security protects users against the malware seen in this campaign.
  • You can also check if someone has access to your account by going into your user profile and clicking on “Viewing Activity.” If something looks awry, you can choose to sign out of all devices. Once you have done that, change your password to your account, thereby locking would-be thieves out of your account.


Symantec Corporation, the world’s leading cyber security company, allows organizations, governments, and people to secure their most important data wherever it lives. More than 50 million people and families rely on Symantec’s Norton and LifeLock comprehensive digital safety platform to help protect their personal information, devices, home networks, and identities.

© 2017 Symantec Corporation. All rights reserved. Symantec, the Symantec Logo, the Checkmark Logo, Norton, Norton by Symantec, LifeLock, and the Lockman Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the United States and other countries. Firefox is a trademark of Mozilla Foundation. Google Chrome is a trademark of Google, Inc. Mac, iPhone and iPad are trademarks of Apple Inc. Microsoft and the Windows logo are trademarks of Microsoft Corporation in the United States and/or other countries. The Android robot is reproduced or modified from work created and shared by Google and used according to terms described in the Creative Commons 3.0 Attribution License. Other names may be trademarks of their respective owners.