{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,5]],"date-time":"2026-04-05T09:45:31Z","timestamp":1775382331716,"version":"3.50.1"},"reference-count":33,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2023,9,28]],"date-time":"2023-09-28T00:00:00Z","timestamp":1695859200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Technologies providing copyright-infringing IPTV content are commonly used as an illegal alternative to legal IPTV subscriptions and services, as they usually have lower monetary costs and can be more convenient for users who follow content from different sources. These infringing IPTV technologies may include websites, software, software add-ons, and physical set-top boxes. Due to the free or low cost of illegal IPTV technologies, illicit IPTV content providers will often resort to intrusive advertising, scams, and the distribution of malware to increase their revenue. We developed an automated solution for collecting and analysing malware from illegal IPTV technologies and used it to analyse a sample of illicit IPTV websites, application (app) stores, and software. Our results show that our IPTV Technologies Malware Analysis Framework (IITMAF) classified 32 of the 60 sample URLs tested as malicious compared to running the same test using publicly available online antivirus solutions, which only detected 23 of the 60 sample URLs as malicious. Moreover, the IITMAF also detected malicious URLs and files from 31 of the sample\u2019s websites, one of which had reported ransomware behaviour.<\/jats:p>","DOI":"10.3390\/fi15100325","type":"journal-article","created":{"date-parts":[[2023,9,29]],"date-time":"2023-09-29T02:47:30Z","timestamp":1695955650000},"page":"325","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Investigating IPTV Malware in the Wild"],"prefix":"10.3390","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1318-9036","authenticated-orcid":false,"given":"Adam","family":"Lockett","sequence":"first","affiliation":[{"name":"Department of Computing & Informatics, Faculty of Science & Technology, Bournemouth University, Fern Barrow, Wallisdown, Dorset BH12 5BB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8063-0827","authenticated-orcid":false,"given":"Ioannis","family":"Chalkias","sequence":"additional","affiliation":[{"name":"Centre for Research and Technology Hellas, Information Technologies Institute, 570 01 Thessaloniki, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4901-5954","authenticated-orcid":false,"given":"Cagatay","family":"Yucel","sequence":"additional","affiliation":[{"name":"Department of Computing & Informatics, Faculty of Science & Technology, Bournemouth University, Fern Barrow, Wallisdown, Dorset BH12 5BB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0807-2661","authenticated-orcid":false,"given":"Jane","family":"Henriksen-Bulmer","sequence":"additional","affiliation":[{"name":"Department of Computing & Informatics, Faculty of Science & Technology, Bournemouth University, Fern Barrow, Wallisdown, Dorset BH12 5BB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vasilis","family":"Katos","sequence":"additional","affiliation":[{"name":"Department of Computing & Informatics, Faculty of Science & Technology, Bournemouth University, Fern Barrow, Wallisdown, Dorset BH12 5BB, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,9,28]]},"reference":[{"key":"ref_1","unstructured":"Digital Citizens Allience (2023, August 25). How Digital Platforms Are Being Overrun by Bad Actors and How the Internet Community Can Beat Them at Their Own Game. Available online: https:\/\/www.digitalcitizensalliance.org\/clientuploads\/directory\/Reports\/Trouble-in-Our%20Digital-Midst%20Report-June-2017.pdf."},{"key":"ref_2","unstructured":"Digital Citizens Allience (2023, August 25). Fishing in the Piracy Stream: How Dark Web of Entertainment Is Consumers to Harm. Available online: https:\/\/www.digitalcitizensalliance.org\/clientuploads\/directory\/Reports\/DCA_Fishing_in_the_Piracy_Stream_v6.pdf."},{"key":"ref_3","unstructured":"Hsiao, L., and Ayers, H. (2019). The Price of Free Illegal Live Streaming Services. arXiv."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Watters, P. (2013). A Systematic Approach to Measuring Advertising Transparency Online: An Australian Case Study. SSRN Electron. J.","DOI":"10.2139\/ssrn.2362621"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Simpson, W., and Greenfield, H. (2009). IPTV and Internet Video, Elsevier.","DOI":"10.1016\/B978-0-240-81245-8.00011-6"},{"key":"ref_6","unstructured":"(2023, August 25). Sandvine Subscription Television Piracy Sandvine Global Internet Phenomena Spotlight. Case Study 2 Global Internet Phenomena Spotlight. Available online: https:\/\/www.sandvine.com\/hubfs\/downloads\/reports\/internet-phenomena\/sandvine-spotlight-subscription-television-piracy.pdf."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Pandey, P., Aliapoulios, M., and McCoy, D. (2019, January 17\u201319). Iniquitous Cord-Cutting: An Analysis of Infringing IPTV Services. Proceedings of the 2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Stockholm, Sweden.","DOI":"10.1109\/EuroSPW.2019.00054"},{"key":"ref_8","unstructured":"Intellectual Property Office (2023, August 25). UK Government Response to the Call for Views Regarding Illicit IPTV Streaming Devices, Available online: https:\/\/assets.publishing.service.gov.uk\/government\/uploads\/system\/uploads\/attachment_data\/file\/750177\/Gov-Response-call-for-views-Illicit-IPTV.pdf."},{"key":"ref_9","unstructured":"EUIPO (2023, August 25). Illegal Iptv in the European Union. Available online: https:\/\/euipo.europa.eu\/tunnel-web\/secure\/webdav\/guest\/document_library\/observatory\/documents\/reports\/2019_Illegal_IPTV_in_the_European_Union\/2019_Illegal_IPTV_Ex_Summ_en.pdf."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Warrior, M.A., Xiao, Y., Varvello, M., and Kuzmanovic, A. (2020, January 20\u201324). De-Kodi: Understanding the Kodi Ecosystem. Proceedings of the Web Conference 2020, Taipei, Taiwan.","DOI":"10.1145\/3366423.3380194"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"137","DOI":"10.1007\/978-981-10-6544-6_14","article-title":"Malicious PDF Files Detection Using Structural and Javascript Based Features","volume":"Volume 750","author":"Dabral","year":"2017","journal-title":"Proceedings of the Communications in Computer and Information Science"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"121395","DOI":"10.1109\/ACCESS.2022.3222307","article-title":"Detecting Malicious URLs Using Machine Learning Techniques: Review and Research Directions","volume":"10","author":"Aljabri","year":"2022","journal-title":"IEEE Access"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Samtani, S., Chinn, K., Larson, C., and Chen, H. (2016, January 28\u201330). AZSecure Hacker Assets Portal: Cyber Threat Intelligence and Malware Analysis. Proceedings of the IEEE International Conference on Intelligence and Security Informatics: Cybersecurity and Big Data, ISI 2016, Tucson, AZ, USA.","DOI":"10.1109\/ISI.2016.7745437"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Piplai, A., Mittal, S., Abdelsalam, M., Gupta, M., Joshi, A., and Finin, T. (2020, January 9\u201310). Knowledge Enrichment by Fusing Representations for Malware Threat Intelligence and Behavior. Proceedings of the 2020 IEEE International Conference on Intelligence and Security Informatics, ISI 2020, Arlington, VA, USA.","DOI":"10.1109\/ISI49825.2020.9280512"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Miles, C., Lakhotia, A., Ledoux, C., Newsom, A., and Notani, V. (2014, January 19\u201321). VirusBattle: State-of-the-Art Malware Analysis for Better Cyber Threat Intelligence. Proceedings of the 7th International Symposium on Resilient Control Systems, ISRCS 2014, Denver, CO, USA.","DOI":"10.1109\/ISRCS.2014.6900103"},{"key":"ref_16","unstructured":"Tan, H., Chandramohan, M., Cifuentes, C., Bai, G., and Ko, R.K.L. (2021). ColdPress: An Extensible Malware Analysis Platform for Threat Intelligence. arXiv."},{"key":"ref_17","unstructured":"EUIPO (2023, August 25). Identification and Analysis of Malware on Selected Suspected Copyright-Infringing Websites. Available online: https:\/\/euipo.europa.eu\/knowledge\/course\/view.php?id=3395."},{"key":"ref_18","unstructured":"Theocharidou, M., Malatras, A., Lella, I., and Tsekmezoglou, E. (2021). ENISA Threat Landscape 2021, European Union Agency for Cybersecurity."},{"key":"ref_19","first-page":"46","article-title":"A Review on Fileless Malware Analysis Techniques","volume":"9","author":"Khushali","year":"2020","journal-title":"Int. J. Eng. Res."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"113","DOI":"10.1007\/978-3-030-34339-2_7","article-title":"JSLess: A Tale of a Fileless Javascript Memory-Resident Malware","volume":"Volume 11879","author":"Saad","year":"2019","journal-title":"Information Security Practice and Experience\u2014ISPEC 2019"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"119133","DOI":"10.1016\/j.eswa.2022.119133","article-title":"Fileless Malware Threats: Recent Advances, Analysis Approach through Memory Forensics and Research Challenges","volume":"214","author":"Kara","year":"2023","journal-title":"Expert Syst. Appl."},{"key":"ref_22","unstructured":"Ponemon Institute (2023, August 25). The Third Annual Study on the State of Endpoint Security Risk. Available online: https:\/\/www.morphisec.com\/hubfs\/2020%20State%20of%20Endpoint%20Security%20Final.pdf."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Yucel, C., Chalkias, I., Mallis, D., Karagiannis, E., Cetinkaya, D., and Katos, V. (2020, January 8\u20139). On the Assessment of Completeness and Timeliness of Actionable Cyber Threat Intelligence Artefacts. Proceedings of the Multimedia Communications, Services and Security: 10th International Conference, MCSS 2020, Krak\u00f3w, Poland.","DOI":"10.1007\/978-3-030-59000-0_5"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Xing, X., Meng, W., Lee, B., Weinsberg, U., Sheth, A., Perdisci, R., and Lee, W. (2015, January 18). Understanding Malvertising Through Ad-Injecting Browser Extensions. Proceedings of the 24th International Conference on World Wide Web, International World Wide Web Conferences Steering Committee, Geneva, Switzerland.","DOI":"10.1145\/2736277.2741630"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s42400-019-0043-x","article-title":"An Emerging Threat Fileless Malware: A Survey and Research Challenges","volume":"3","author":"Sudhakar","year":"2020","journal-title":"Cybersecurity"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Sanjay, B.N., Rakshith, D.C., Akash, R.B., and Hegde, V.V. (2018, January 20\u201322). An Approach to Detect Fileless Malware and Defend Its Evasive Mechanisms. Proceedings of the 2018 3rd International Conference on Computational Systems and Information Technology for Sustainable Solutions (CSITSS), Bengaluru, India.","DOI":"10.1109\/CSITSS.2018.8768769"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Abad, S., Gholamy, H., and Aslani, M. (2023). Classification of Malicious URLs Using Machine Learning. Sensors, 23.","DOI":"10.3390\/s23187760"},{"key":"ref_28","unstructured":"(2023, January 6\u20138). Using Machine Learning to Detect and Classify URLs: A Phishing Detection Approach. Proceedings of the 2023 4th International Conference on Electronics and Sustainable Communication Systems, ICESC 2023\u2014Proceedings, Coimbatore, India."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Difaizi, T.Z., Camille, O.P.-W.L., Benhura, T.C., and Gupta, G. (, January 11\u201312). URL Based Malicious Activity Detection Using Machine Learning. Proceedings of the 2023 International Conference on Disruptive Technologies (ICDT), Greater Noida, India.","DOI":"10.1109\/ICDT57929.2023.10150899"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Ghaleb, F.A., Alsaedi, M., Saeed, F., Ahmad, J., and Alasli, M. (2022). Cyber Threat Intelligence-Based Malicious URL Detection Model Using Ensemble Learning. Sensors, 22.","DOI":"10.3390\/s22093373"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"92523","DOI":"10.1109\/ACCESS.2023.3291811","article-title":"QsecR: Secure QR Code Scanner According to a Novel Malicious URL Detection Framework","volume":"11","author":"Rafsanjani","year":"2023","journal-title":"IEEE Access"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Sheppard, J. (2018, January 1\u20133). Cloud Investigations of Illegal IPTV Networks. Proceedings of the 2018 17th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/12th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE), New York, NY, USA.","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00295"},{"key":"ref_33","first-page":"1","article-title":"Cyber Threat Intelligence: Challenges and Opportunities","volume":"Volume 70","author":"Conti","year":"2018","journal-title":"Advances in Information Security"}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/15\/10\/325\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T21:01:10Z","timestamp":1760130070000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/15\/10\/325"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,28]]},"references-count":33,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2023,10]]}},"alternative-id":["fi15100325"],"URL":"https:\/\/doi.org\/10.3390\/fi15100325","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,9,28]]}}}