Explorer

YouTube Content Creators Beware! Malware Named YTStealer Is Targeting YouTube Channels, Stealing Credentials

A new malware named YTStealer has been on the prowl and it is targeting YouTube content creators.

A new malware named YTStealer has been on the prowl and it is targeting YouTube content creators. The YTStealer malware attacks YouTube content creators by stealing authentication cookies and hijacking their channels. The malware has been identified by a researcher named Joakim Kennedy of security research firm Intezer.

"In this blog post, we are describing a new malware that we have concluded is highly likely sold as a service on the Dark Web. We have named the malware YTStealer because its sole objective is to steal authentication cookies from YouTube content creators. In June 2020, IntSights released a report on a new trend that they observed. In this trend, threat actors were selling access to YouTube accounts," Kennedy wrote in the blog post.

The researcher has shared one of the many methods threat actors are using to obtain these YouTube accounts.

YTStealer is essentially a malware whose objective is to steal YouTube authentication cookies. As a stealer, it operates like many other stealers. The first thing it does when it’s executed is to perform some environment checks. This is to detect if the malware is being analysed in a sandbox. The code that performs the checks comes from an open-source project hosted on GitHub called Chacal.

What sets YTStealer aside from other stealers sold on the Dark Web market is that it is solely focused on harvesting credentials for one single service instead of grabbing everything it can get hold of.

"When it comes to the actual process, it is very similar to that seen in other stealers. The cookies are extracted from the browser’s database files in the user’s profile folder," Kennedy added.

Top Headlines

Apple Rolls Out Second iOS 26.4 Beta 3: How To Install Update, Which iPhones Support It
Apple Rolls Out Second iOS 26.4 Beta 3: How To Install Update, Which iPhones Support It
Nothing Phone 4a & 4a Pro Launched With Snapdragon Chips: Check Price In India, & Specs
Nothing Phone 4a & 4a Pro Launched With Snapdragon Chips: Check Price In India, & Specs
WhatsApp Could Soon Charge For Extra Features: Here’s What ‘WhatsApp Plus’ Might Offer
WhatsApp Could Soon Charge For Extra Features: Here’s What ‘WhatsApp Plus’ Might Offer
Old Phone Battery Explodes In Hand, Student Loses Thumb Just Before Exam
Old Phone Battery Explodes In Hand, Student Loses Thumb Just Before Exam

Videos

Strategic Conflict Update: Israel’s 100-Hour Strike Devastates Iran; USS Abraham Lincoln Targeted
GeoConflict Alert: Iran Strikes US Airbase in Kuwait, Israel Intensifies Lebanon Offensive
War Alert: Iran Launches Khaibar Shikan Missiles on Israel Amid Escalating Middle East War
War Update: Iran Targets USS Abraham Lincoln, US Navy Scrambles Amid Escalating Middle East War
Global War Update: US Allows India to Buy Russian Oil as Iran Strikes Israel and Kuwait Base

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget