What happened?
Crunchyroll's website was hijacked, displaying a page with the following fake announcement:
A New Beginning, A New Media Player…
Crunchyroll Viewer
Stream your favorites animes in full 4k HD from anywhere! Support lasts crunchyroll features, inbuilt microtransactions management. Get your FREE trial now !
Unsuspecting users downloaded and executed a file named CrunchyViewer.exe, which was a malicious program.
Crunchyroll restored their website to normal, and published a blog post regarding the details of the attack.
What is the connection with Taiga?
Simply put, CrunchyViewer.exe is a modified version of Taiga, bundled with a virus. The people behind this incident took the source code of Taiga and renamed some instances of "Taiga" to "Crunchyroll" or "crunchyroll viewers". They didn't bother with changing them all, or distributing the application along with its data files. I imagine that they wanted to make it look like a legitimate application, with minimal effort.
Am I infected?
If you downloaded CrunchyViewer.exe and ran it on your Windows machine, then your system is likely infected. Otherwise, you should be safe.
How can I clean my system?
- Run
regedit, go to HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete the registry value named Java.
- Open
%AppData% directory (e.g. C:\Users\YOUR_USERNAME\AppData\Roaming\) and delete the file named svchost.exe.
If you don't know how, Bleeping Computer has a guide with pictures, describing these steps.
You may also want to block 145.239.41.131:6969.
Note that following these instructions may not suffice, so you should take other precautions such as scanning your computer with Malwarebytes.
See Hybrid Analysis and Blaze's Security Blog for technical details.
What happened?
Crunchyroll's website was hijacked, displaying a page with the following fake announcement:
Unsuspecting users downloaded and executed a file named
CrunchyViewer.exe, which was a malicious program.Crunchyroll restored their website to normal, and published a blog post regarding the details of the attack.
What is the connection with Taiga?
Simply put,
CrunchyViewer.exeis a modified version of Taiga, bundled with a virus. The people behind this incident took the source code of Taiga and renamed some instances of "Taiga" to "Crunchyroll" or "crunchyroll viewers". They didn't bother with changing them all, or distributing the application along with its data files. I imagine that they wanted to make it look like a legitimate application, with minimal effort.Am I infected?
If you downloaded
CrunchyViewer.exeand ran it on your Windows machine, then your system is likely infected. Otherwise, you should be safe.How can I clean my system?
regedit, go toHKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Runand delete the registry value namedJava.%AppData%directory (e.g.C:\Users\YOUR_USERNAME\AppData\Roaming\) and delete the file namedsvchost.exe.If you don't know how, Bleeping Computer has a guide with pictures, describing these steps.
You may also want to block
145.239.41.131:6969.Note that following these instructions may not suffice, so you should take other precautions such as scanning your computer with Malwarebytes.
See Hybrid Analysis and Blaze's Security Blog for technical details.