Cyber Security News

Hackers Hijacking Popular YouTube Channels To Deliver Infostealer Malware

Hackers always end up targeting famous YouTube channels because of their large audience base, and their aim is to exploit the same for different reasons. 

Hacking such a platform becomes one of the most lucrative activities in terms of money that one can engage in through demanding ransom or getting those illegal revenues earned from adverts. 

Furthermore, leading channels are appropriate tools that enable hackers to distribute malware and propaganda.

Cybersecurity researchers at ASEC recently discovered that hackers have been actively targeting and hijacking popular YouTube channels to deliver infostelaer malware.

Malware uploaded by a YouTube account with more than 800,000 subscribers (Source – ASEC)

Malware distribution arises mainly from the misuse of web services, like tricky websites with legitimate applications, such as game cheats, cracks, and keygens, which are malware.

Document
Stop Advanced Phishing Attack With AI

AI-Powered Protection for Business Email Security

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Stopping 99% of phishing attacks missed by other email security solutions. .

These sites betray users’ trust, making them unsuspectingly download and execute malicious software.

YouTube is also a target where threat actors include links for downloading malware in videos, descriptions, and comments.

Since 2020, this has been the distribution channel for infostealers like RedLine, BlackGuard and RecordBreaker.

In the latest occurrence, hackers chose channels with large numbers of subscribers ranging from entertainment to niche interests that escalated the scale of their attacks.

Targeted YouTube channels (Source – ASEC)

The attackers usually upload videos on cracked versions of genuine programs like Adobe, and the video descriptions or comments carry download links.

The password-protected malware payloads are hosted on MediaFire to outsmart detection.

Under decompression, infections like Vidar come into view in their hidden forms.

These installers that seem normal, as in “Set-up.exe,” effectively load modified malware parts, including “msedge_elf.dll,” upon initiation.

It makes encrypted files such as “berley.asp” and “complot.ppt” serve as its payloads. Essentially, this kind of decrypted malware often remains hidden within fake files with a size of up to 800 MB, which results in increased security measures being implemented.

Additionally, C&C server addresses plus sharing of platforms like Telegram and Steam Community show that the activities are organized by one actor.

Vidar Abusing Telegram and Steam (Source – ASEC)

The installers contain the LummaC2 malware and have no notable characteristics compared to Vidar malware cases.

LummaC2, an infostealer like Vidar, Azorult, RedLine, and AgentTesla, steals credentials, cryptocurrency wallets, and screenshots. 

Installers containing LummaC2 malware (Source – ASEC)

It’s actively distributed as cracked software. Recently, threat actors hacked popular YouTube channels to distribute Vidar and LummaC2 malware disguised as pirated apps, targeting over 800,000 subscribers. 

These infostealers collect user data and can install additional malware. Users should avoid illegal programs and suspicious sites/P2P and use genuine software.

Besides this, it’s also recommended that the V3 be updated to prevent malware infections.

IoCs

MD5s

  • af273f24b4417dce302cf1923fb56c71: Vidar Loader (msedge_elf.dll)
  • 0c9c366aa9938df153c406db65debe82: Encoded Data (berley.asp)
  • dae50482d640385a5665272cd1f716df: Encoded Data (complot.ppt)
  • e8201c07fcb62107a91411c55c261fab: Vidar (Setup.exex)
  • 2414085b0a5bf49d9658f893c74cf15e: LummaC2 (Adobe_Activator.exe)
  • cd0338fffaebc9cbc50a435868397e96: LummaC2 (Update-setup.exe)

C&C Servers

  • hxxps://steamcommunity[.]com/profiles/76561199658817715: Vidar
  • hxxps://t[.]me/sa9ok: Vidar
  • hxxps://78.47.221[.]177: Vidar
  • hxxps://95.216.176[.]246:5432: Vidar
  • hxxps://interferencesandyshiw[.]shop/api: LummaC2
  • hxxps://chokepopilarvirusew[.]shop/api: LummaC2
  • hxxps://pillowbrocccolipe[.]shop/api: LummaC2
  • hxxps://communicationgenerwo[.]shop/api: LummaC2
  • hxxps://diskretainvigorousiw[.]shop/api: LummaC2
  • hxxps://affordcharmcropwo[.]shop/api: LummaC2
  • hxxps://dismissalcylinderhostw[.]shop/api: LummaC2
  • hxxps://enthusiasimtitleow[.]shop/api: LummaC2
  • hxxps://worryfillvolcawoi[.]shop/api: LummaC2
  • hxxps://cleartotalfisherwo[.]shop/api: LummaC2

Secure your emails in a heartbeat! To find your ideal email security vendor, Take a Free 30-Second Assessment.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago