viralamo

Menu
  • Technology
  • Science
  • Money
  • Culturs
  • Trending
  • Video

Subscribe To Our Website To Receive The Last Stories

Join Us Now For Free
Home
Technology
YouTube content creator credentials are under siege by YTStealer malware
Technology

YouTube content creator credentials are under siege by YTStealer malware

29/06/2022

YouTube content creator credentials are under siege by YTStealer malware

Getty Images

In online crime forums, specialization is everything. Enter YTStealer, a new piece of malware that steals authentication credentials belonging to YouTube content creators.

“What sets YTStealer aside from other stealers sold on the Dark Web market is that it is solely focused on harvesting credentials for one single service instead of grabbing everything it can get ahold of,” Joakim Kennedy, a researcher at security firm Intezer wrote in a blog post on Wednesday. “When it comes to the actual process, it is very similar to that seen in other stealers. The cookies are extracted from the browser’s database files in the user’s profile folder.”

As soon as the malware obtains a YouTube authentication cookie it opens a headless browser and connects to YouTube’s Studio page, which content creators use to manage the videos they produce. YTStealer then extracts all available information about the user account, including the account name, number of subscribers, age, and whether channels are monetized.

Advertisement

The malware then encrypts each data sample with a unique key and sends both to a command and control server.

The structure of the YTStealer code and the unique identifier used for each sample leads Intezer to suspect that YTStealer is being sold as a service to other threat actors. Company researchers further noticed that files used to install the malware on victim computers loaded other credential stealers, including ones called RedLine and Vidar.

Many of the files are disguised as installers for legitimate tools or software. They included fake installers for:

  • OBS Studio, a piece of an open source streaming software
  • Video editing software, including Adobe Premiere Pro, Filmora, and HitFilm Express
  • Audio applications and plugins such as Antares Auto-Tune Pro, Valhalla DSP, FabFilter Total, and Xfer Serum
  • Game modes and cheats for games such as Grand Theft Auto V, Roblox, Counter-Strike, and Call of Duty
  • Driver tools such as “Driver Booster” and “Driver Easy,” which bill themselves as a means for improving gaming computer performance
  • “Cracks” for legitimate software or services including Norton Security, Malwarebytes, Discord Nitro, Stepn, and Spotify Premium

Hardcoded into the YTStealer is the domain youbot[.]solutions. It’s not immediately clear if the domain is connected to Youbot Solutions LLC, which is registered in the New Mexico registry of corporations. Attempts to reach the company for comment weren’t successful.

Source link

Share
Tweet
Pinterest
Linkedin
Stumble
Google+
Email
Prev Article
Next Article

Related Articles

Strivr raises $30 million to bring VR training to the enterprise
Strivr, the company behind a virtual reality (VR) platform that …

Strivr raises $30 million to bring VR training to the enterprise

Facebook lets users transfer images directly to Google Photos as part of data portability program
As the Wuhan coronavirus death toll rises to more than …

Facebook fights spread of coronavirus misinformation

Leave a Reply Cancel reply

Find us on Facebook

Related Posts

  • Fast & Furious: Crossroads lives video games a quarter-mile at a time
    Geneva Motor Show canceled over coronavirus fears
    28/02/2020
  • Information security gets personal: How to protect yourself and your stuff
    Information security gets personal: How to protect …
    27/05/2022
  • Fast & Furious: Crossroads lives video games a quarter-mile at a time
    How to make sense of the coronavirus …
    20/04/2020
  • Netflix IT exec forced employees to use products from vendors that bribed him
    Netflix IT exec forced employees to use …
    04/05/2021
  • Verizon partners with Deloitte to create enterprise 5G, edge solutions
    Verizon partners with Deloitte to create enterprise …
    21/12/2020

Popular Posts

  • Samsung heir pardoned due to South Korean economic needs
    Samsung heir pardoned due to South Korean …
    12/08/2022 0
  • 10 Shortest Marriages in History – Listverse
    15/07/2022 0
  • 10 Urban Legends with Origins in True …
    15/07/2022 0
  • Hackers are targeting industrial systems with malware
    Hackers are targeting industrial systems with malware
    16/07/2022 0
  • 10 Most Unsettling PSAs Ever Made – …
    16/07/2022 0

viralamo

Pages

  • Contact Us
  • Privacy Policy
Copyright © 2022 viralamo
Theme by MyThemeShop.com

Ad Blocker Detected

Our website is made possible by displaying online advertisements to our visitors. Please consider supporting us by disabling your ad blocker.

Refresh