bavinfosec
4 min readApr 28, 2020

Be A Cautious: Fraudsters misuse COVID-19 Lockdown with fake NETFLIX links went to be a Malware

Due to the COVID-19 pandemic, users are all over online sites and web-based life gave the scammers to exploit cyber attacks. Digital lawbreakers are finding new methods to target users staying indoors following the Covid-19 lockdown.

The most recent evident scam doing the rounds in different countries is the ‘NETFLIX subscription’ message with a link to click.

Netflix is offering its premium account for no cost has turned into a web sensation. The message is as follows.

“2 Months of Netflix Premium Free at no cost For REASON OF QUARANTINE (CORONA VIRUS) Get 2 Months of Netflix Premium Free anywhere in the world for 60 days. Get it now HERE https://itsmyflix.com/?m”

This message got viral in the USA and AUSTRALIA, wherein INDIA users started receiving phishing messages forwarded through WhatsApp and Facebook media.

This is the URL used in India https://itsmyflix.com/?m, for other countries the URL is as shown below:

NETFLIX link shared in other countries landed upon a phishing site where they indicated the number of free accounts available.

Users are asked to join a survey to avail of the free pass. When a user finishes the survey, they were requested to share the message to 10 contacts on WhatsApp to “activate”.

The malicious site additionally has a Facebook-clone comment area, highlighting tributes to vindicate the claim. Anyhow those are fake.

Netflix affirmed to an American financial news website (Business Insider) that it is not offering any free subscription or passes amid the corona-virus pandemic.

Also, the Australian government body Scamwatch had warned everyone against clicking on the link and asked them to delete the message immediately.

Original Tweet:

“Don’t fall for this #COVID -19 Netflix phishing scam! Netflix is not offering free streaming for 3 months. Don’t click on the link — just delete the message,” it tweeted.

Don’t fall for this #COVID-19 Netflix phishing scam! Netflix is not offering free streaming for 3 months. Don’t click on the link — just delete the message. pic.twitter.com/G9Ym8WWOXa

— Scamwatch_gov_au (@Scamwatch_gov) April 2, 2020

In INDIA, https://itsmyflix.com link that is circulating in social media lands users on a warning page which leads nowhere and only puts your device’s security at risk.

Once the user taps the link, the Flix.apk file gets downloaded to your device. This .apk gets installed in the back-end and runs the service, which automatically forwards the pishing message to other users.

Scammers are taking advantage of this for stealing individual’s private data like bank account details, credit/debit card details, email-id, and passwords

If you are already affected by this, follow the instructions mentioned below:

1. Go to Settings in your android mobile, select Apps, now search for an application Flix.apk

Now uninstall the application (Flix.apk) and restart your device.

Note: For better result, it is strongly recommended you to Factory Reset your device without a backup of your data.

Recommendations:

1. Do not click on any links in emails or messages or open attachments from people or organizations you don’t recognize. Just delete the messages immediately.

2. It is recommended to change your credentials periodically, as the scammers are reusing the credentials stolen previously.

3. Not to use the same passwords for different accounts.

4. Do not share your personal information unnecessarily.

Do not fall for the scammer’s tactics which incorporates malicious code sent via e-mail which aims of taking control of devices and phishing emails claiming there is an issue with the user’s account and asking for login details to address the problem.

Be Alert, Be A Vigilant !!!