'Free' downloads of Oscar-nominated movies are actually nasty bundles of malware

Joker
(Image credit: Warner Bros.)

Security researchers at Kaspersky have found hundreds of sites hosting bundles of malicious software, presented as free downloads of this year's Oscar-nominated movies. They also discovered a slew of phishing sites that tricked users into entering confidential information and even credit card details, using films including 1917 and Jojo Rabbit as bait.

With the Oscars awards ceremony due to take place on February 9, criminals are exploiting people's increased interest in the nominees for Best Picture. According to Kaspersky's report, Joker was the movie most commonly used to lure victims into downloading malware and handing over their bank details.

Malicious downloads typically start to appear around the time movies arrive on real streaming sites, as people start searching for other ways to watch them online. 

"Cybercriminals aren’t exactly tied to the dates of film premieres, as they are not really distributing any content except for malicious data,” said Kaspersky malware analyst Anton Ivanov.

"However, as they always prey on something when it becomes a hot trend, they depend on users’ demand and actual file availability. To avoid being tricked by criminals, stick to legal streaming platforms and subscriptions to ensure you can enjoy a nice evening in front of the TV without having to worry about any threats."

Oscar bait

The best way to protect yourself from such malware attacks is to play by the rules, and only stream movies from legitimate sites and services such as Netflix, Amazon Prime Video, Hulu or Disney+ (we've assembled a guide to all the best streaming services to help you choose).

Before trying a new site or service, do some research to check that it's legitimate, and remember that if it seems too good to be true, it almost certainly is.

Phishing websites can be hard to spot, and are sometimes nearly identical to the sites they're impersonating. Always take a good look at the address bar to see which domain you're actually on, and don't click links from unknown sources in emails (instead, visit the site directly by typing its URL).

TOPICS
Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years and is an SCA-certified barista, so whether you want to invest in some smart lights or pick up a new espresso machine, she's the right person to help.

Latest in Antivirus
Kaspersky Antivirus is banned in the US – here are 3 superb alternatives
A person holding an iPhone close to the camera with the Google search homepage displayed onscreen
That Google Ad you click could be dangerous—here’s why
A stressed out hacker looking at a laptop screen
Your antivirus software will get a major boost from this new hacking competition
Promotional material for McAfee online protection.
Protect your online life with the power of McAfee
"Best Free Antivirus Software" next to a laptop being opened
Best free antivirus in 2025
Antivirus
Which antivirus software works with Malwarebytes?
Latest in News
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years
The Nanoleaf PC Screen Mirror Lightstrip being used on a desktop computer.
Mac gaming could get an intriguing boost – but not in the way you'd expect
Snapdragon G Series
Qualcomm poised to muscle in on AMD's territory with powerful gaming handheld processors