Spotify Has A Pirated Software Problem (404media.co) 22
An anonymous reader shares a report: People are using Spotify playlist and podcast descriptions to distribute spam, malware, pirated software and cheat codes for video games. Cybersecurity researcher Karol Paciorek posted an example of this: A Spotify playlist titled "*Sony Vegas Pro*13 C-r-a-c-k Free Download 2024 m-y-s-o-f-t-w-a-r-e-f-r-e-e.com" acts as a free advertisement for piracy website m-y-s-o-f-t-w-a-r-e-f-r-e-e[dot]com, which hosts malicious software.
"Cybercriminals exploit Spotify for #malware distribution," Paciorek posted on X. "Why? Spotify has a strong reputation and its pages are easily indexed by search engines, making it an effective platform to promote malicious links."
"The playlist title in question has been removed," a spokesperson for Spotify told 404 Media in a statement. "Spotify's Platform Rules prohibit posting, sharing, or providing instructions on implementing malware or related malicious practices that seek to harm or gain unauthorized access to computers, networks, systems, or other technologies."
"Cybercriminals exploit Spotify for #malware distribution," Paciorek posted on X. "Why? Spotify has a strong reputation and its pages are easily indexed by search engines, making it an effective platform to promote malicious links."
"The playlist title in question has been removed," a spokesperson for Spotify told 404 Media in a statement. "Spotify's Platform Rules prohibit posting, sharing, or providing instructions on implementing malware or related malicious practices that seek to harm or gain unauthorized access to computers, networks, systems, or other technologies."
Except... (Score:1)
Except a link to a license key doesn't do any o that.
Re:Except... (Score:5, Informative)
Most of these sites contain malware in everything from ad banners to download link to the said key.
Re: (Score:3)
Except a link to a license key doesn't do any o that.
Literally none of what is posted on there is just a link to a license key. The content posted in this way is universally riddled with malware.
Wow (Score:3)
I've seen some stupid ways to promote malicious websites, but this may be the stupidest one yet. Anyone who would see something like that and then go to that website deserves whatever happens to them. Those people shouldn't be allowed to have technology in the first place.
Re: (Score:2)
I'm kind of surprised nobody has come up with a malformed mp3 that does something like encode pirated software or other messages directly into the music; then get patriotic singers from whatever country to participate in spreading information by selling tracks on spotify.
Streaming vs steganography (Score:2)
malformed mp3 that does something like encode pirated software or other messages directly into the music;
The problem is that steganography requires, obviously, access to the music data (e.g. an MP3 file) so you can open it with the tool and decode/extract the hidden data.
And modern streaming platform try to hide the data as much as possible from the end user (as in you get an nice "play" button in the app, AAC encoded audio is directly stream to your wireless earbuds but there's no way so save the file and open it in another app - short of having a rooted phone and using special tools to intercept that data an
Re: (Score:2)
Any stream you can receive, you can save. It's pretty easy to watch the network traffic coming in to your own computer.
Spreading (Score:2)
Any stream you can receive, you can save. It's pretty easy to watch the network traffic coming in to your own computer.
Apple, Google and several other strongly disagree on the subject whether your smartphone qualifies as your own computer.
Yes, there are ways with which you, I, and most of the people here on /. could capture data which is streamed (ignoring for now the problems around encryption and DRM).
But Random Joe 6-Pack only know to tap the button on the smartphone app to listen to music. Do not count on them to be able to do all the tricks to get steganography working.
And that will severely limit how wide said patriot
Re: (Score:2)
Yeah, but Random Joe 6-Pack (or for that matter Guido the Enforcer) doesn't need to know how the magic works to get the message. He just needs a side-loaded app that allows him to tune in to the message.
Re: (Score:2)
To be fair, it works even better if people writes articles detailing the links that these exploits point to. the next article will be "people use 404media articles to amplify the distribution of pirated software, malware cracks etc" followed by "people use slashdot articles ..."
Re: (Score:3)
Eh, for all the problems it poses, I'd hesitate to say that "it's stupid" is one of them. Spotify ranks rather well on Google, so it's a great (but evil) way to ride Spotify's tailcoat and get your malware links seen.
Re: (Score:2)
It's still stupid, because literally only the stupidest of the stupid people (or weird malware researchers, but they don't count) would ever visit any of those malware links. It pains me that there are people that it does work on and that those people are allowed continued access to technology they don't understand or even appreciate.
Stop citing 404media (Score:1)
Stop citing IT-Clickbait.
Promoting Malware? (Score:2)
Malware promoting malware, checks out!
Spotify has a content upload problem (Score:2, Troll)
Seriously they need to start introducing some level of filtering into what people upload. This link spam is just the latest problem. They also suffer with actually pirated music being uploaded, AI trash being uploaded, fake band names attempting to generate plays by imitating real bands, it's becoming a cesspool.
Re: (Score:2)
cesspool
what % of the platform is the content you mention? I use Spotify the majority of my conscious hours and encounter nothing but smooth sailing.
AI trash
Related, this is the AI garbage for sale [temu.com] being show in ads on /. So far, slashdot is looking more like the cesspool than Spotify. Not saying the things you mentioned don't exist on Spotify - it's not news to me at all. Just wondering what % of the time it is in front of you.
Re: (Score:2)
The percentage is small, but then everything is small when you have a catalogue of 100million songs. I've come across a completely fake album before. Had to do a double take when I realised the band sounded completely different.
We even covered this here https://entertainment.slashdot... [slashdot.org]
But there's been plenty of other stories with various publishing dates over the past few years https://www.theverge.com/2024/... [theverge.com] https://blog.negativewhite.com... [negativewhite.com]
Re: (Score:3)
Spotify is a cesspool even for artists, who get pennies on the millionth view or whatever. It shouldn't have existed, but it does because it does a better job of separating artists from the cash generated by the art. It's built on the premise of throwing more to the industry than to the creators. It's just grabbing at every possible way to do that now, with as little human interaction as possible. It's custom made for digital fraud, and now it's starting to pay off in this type of bullshit.
advertise != distribute (Score:5, Insightful)
Spotify is not distributing anything. People are using plain-text playlist titles to advertise their shitty websites, just like they can do with ANY website that allows users to enter plain-text that others can read, including this one. By the way, the REAL site for *Sony Vegas Pro*13 C-r-a-c-k Free Download is goatse[dot]cx
Comment Subject: (Score:1)
*every editable text field on the internet has a pirated software problem
Is this 1999? We're headlining that spambots dump crude links? Even /. has them
Hell, here, have a goat[dot]cx on the house.
Meanwhile... (Score:3)
"The playlist title in question has been removed," a spokesperson for Spotify told 404 Media in a statement.
Meanwhile the other 2,646,318 'titles' are still there.
Good job, Spotify, that's so inspiring, keep up the good work...
Spotify hosts ... (Score:3)
Of course, podcasts could bypass this by streaming spoken word instructions as to where to download the illicit stuff. But recognizing music should be relatively simple*, as BMI and ASCAP already have clients piggy-backed on phone apps that can recognize their content, capture the location and send a bill to a bar or dance club that isn't paying their fees.
*Sorry. The "not music, deleted" rule will knock rap recordings off the 'Net. But that's a small price to pay in the grand scheme of tings.