- YouTube -Crossers are threatened with Copyright requirements
- The way to solve the problem is to share a download link
- Link distributes Trojanized programs that install a cryptomins
Cyber criminals have been targeted at YouTubers with false copyright claims and threatened them to distribute malware through their videos and channels. T.
Cybersecurity scientists in Kaspersky recently discovered the campaign in nature and claimed that most of the victims are Russian.
Kaspersky said it discovered a video with more than 400,000 views that shared the malicious link and that the campaign resulted in more than 40,000 downloads (before being pulled down).
Tens of thousands of downloads
Kaspersky said the Windows Packet Decert (WPD), a user mode network package recording and Windows injection tool is growing increasingly popular in Russia. It allows applications to intercept and change network packages at different stages of the Windows Network stack and are used as part of a tech stack that allows users to bypass government censorship.
There are many YouTube Videotutorials on how to use WPD tools to do just that and their creators are targeted. Apparently, threat players would file a copyright requirement for YouTube and then reach out to the creators and claim they were the tools of the tool. They will then require the creators to add the tool’s github -download -link in the video’s description.
Alternatively, they would just reach out to the creators who claimed to be the developers and offer an “updated” download link.
However, the GitHub storage, which is shared in this way, is Trojanized and includes a version of the tool that carries a cryptocurrency called silentcryptomins. This is a change of the notorious XMRig and is able to mining ETH, etc., XMR and RTM.
“According to our telemetry, the Malware campaign has affected more than 2,000 victims in Russia, but the total number could be much higher,” Kaspersky said in his analysis.
Cryptojackers are a popular type of malware that can be easily detected as the device that runs can do nothing else as its calculation effect is fully used in mining.
Via Bleeping computer