Explorer

YouTube Content Creators Beware! Malware Named YTStealer Is Targeting YouTube Channels, Stealing Credentials

A new malware named YTStealer has been on the prowl and it is targeting YouTube content creators.

A new malware named YTStealer has been on the prowl and it is targeting YouTube content creators. The YTStealer malware attacks YouTube content creators by stealing authentication cookies and hijacking their channels. The malware has been identified by a researcher named Joakim Kennedy of security research firm Intezer.

"In this blog post, we are describing a new malware that we have concluded is highly likely sold as a service on the Dark Web. We have named the malware YTStealer because its sole objective is to steal authentication cookies from YouTube content creators. In June 2020, IntSights released a report on a new trend that they observed. In this trend, threat actors were selling access to YouTube accounts," Kennedy wrote in the blog post.

The researcher has shared one of the many methods threat actors are using to obtain these YouTube accounts.

YTStealer is essentially a malware whose objective is to steal YouTube authentication cookies. As a stealer, it operates like many other stealers. The first thing it does when it’s executed is to perform some environment checks. This is to detect if the malware is being analysed in a sandbox. The code that performs the checks comes from an open-source project hosted on GitHub called Chacal.

What sets YTStealer aside from other stealers sold on the Dark Web market is that it is solely focused on harvesting credentials for one single service instead of grabbing everything it can get hold of.

"When it comes to the actual process, it is very similar to that seen in other stealers. The cookies are extracted from the browser’s database files in the user’s profile folder," Kennedy added.

Read more
Sponsored Links by Taboola

Top Headlines

‘It Is Out Of The Question’: Prithviraj Chavan Says He Won’t Apologise For Operation Sindoor Comment
‘It Is Out Of The Question’: Prithviraj Chavan Says He Won’t Apologise For Operation Sindoor Comment
Heavy Police Escort, Faces Covered: Luthra Brothers Taken To Goa — Video
Heavy Police Escort, Faces Covered: Luthra Brothers Taken To Goa — Video
PM Modi Becomes First Global Leader To Receive Ethiopia’s Top Honour, Dedicates It To 'People Of India'
PM Modi Becomes First Global Leader To Receive Ethiopia’s Top Honour, Dedicates It To 'People Of India'
‘Evil Forces of Radical Islamic Terrorism’: Trump on Sydney Shooting, Urges Unity At Hanukkah Reception
‘Evil Forces of Radical Islamic Terrorism’: Trump on Sydney Shooting, Urges Unity At Hanukkah Reception

Videos

National Herald Case: Congress Leaders Protest, Allege ED Targeting Gandhi Family
National Herald Case: Mallikarjun Kharge Calls National Herald Case Politically Motivated, Targets BJP and Central Agencies
BMC Election: Thackeray Brothers to Announce BMC Election Alliance Before Nominations on Dec 22-23
Breaking: Delhi Air Pollution Crisis Deepens as AQI Crosses 300, Supreme Court to Hear Matter Today
Parliament Session: Opposition Gears Up for Aggressive Protest as Government Pushes to Pass ‘Viksit Bharat Ji Ram Ji’ Bill in Lok Sabha

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget