Cyber Criminals has started targeting Youtubers in promoting the trojan malware links.

Cyber Criminals has started targeting Youtubers in promoting the trojan malware links.
Cybercriminals are sending bogus copyright claims to YouTubers to coerce them into promoting malware and cryptocurrency miners on their videos.

The threat actors take advantage of the popularity of Windows Packet Divert (WPD) tools that are increasingly used in Russia as they help users bypass internet censorship and government-imposed restrictions on websites and online services.

YouTube creators catering to this audience publish tutorials on how to use various WPD-based tools to bypass censorship and are being targeted by threat actors posing as the copyright holders of these tools.

In most cases seen by Kaspersky, the threat actors claim to be the original developers of the presented restriction bypass tool, filing a copyright claim with YouTube and then contacting the creator to offer a resolution in the form of including a download link they provide.

At the same time, they threaten that non-compliance will result in two more "strikes" on YouTube, which could lead to a channel ban based on the platform's "three strikes" policy.

In other cases, the attackers contact the creator directly, impersonating the tool's developers and claiming that the original tool has a new version or new download link, asking the creator to change it on their video.

The creators, fearing they will lose their channels, give in to the threat actors' demands, and agree to add links in their videos to GitHub repositories that host the said Windows Packet Divert (WPD) tools. However, these are trojanized versions that include a cryptominer downloader instead.


Kaspersky has seen this promotion of laced WPD tools take place on a YouTube video that generated over 400,000 views, with the malicious link reaching 40,000 downloads before it got removed.

A Telegram channel with 340,000 subscribers has also promoted the malware under the same disguise.

"According to our telemetry, the malware campaign has affected more than 2,000 victims in Russia, but the overall figure could be much higher," warns Kaspersky.


SilentCryptoMiner deployment
The malicious archive downloaded from the GitHub repositories contains a Python-based malware loader that is launched using PowerShell via a modified start script ('general.bat').

If the victim's antivirus disrupts this process, the start script delivers a 'file not found' error message suggesting that the user disables their antivirus and re-download the file.

The executable fetches the second-stage loader only for Russian IP addresses and executes it on the device.


The second stage payload is another executable whose size was bloated to 690 MB to evade antivirus analysis, while it also features anti-sandbox and virtual machine checks.

The malware loader turns off Microsoft Defender protections by adding an exclusion and creates a Windows service named 'DrvSvc' for persistence between reboots.


Eventually, it downloads the final payload, SilentCryptoMiner, a modified version of XMRig capable of mining multiple cryptocurrencies, including ETH, ETC, XMR, and RTM.

The coin miner fetches remote configurations from Pastebin every 100 minutes so it can be updated dynamically.

For evasion, it is loaded into a system process like 'dwm.exe' using process hollowing and pauses mining activity when the user launches monitoring tools like Process Explorer and the Task Manager.


Although the campaign discovered by Kaspersky primarily targets Russian users, the same tactics may be adopted for broader-scoped operations that also deliver higher-risk malware like info-stealers or ransomware.

Users should avoid downloading software from URLs in YouTube videos or descriptions, especially from smaller to medium-sized channels that are more susceptible to scams and blackmail.






Go Back

RECENTLY PUBLISHED CONTENTS

Trump Health 2025 Perfect MRI No Idea What Body Part Was Scanned, Full Story. - Runfarbiz Network
Trump Health 2025 Perfect MRI No Idea What Body Part Was Scanned, Full Story.
Good evening, America. This is a special update on a story that has brought smiles to millions across the country tonight.On Sunday, November 30, 2025, as Air Force One carried President Donald Trump back to Washington from a beautiful weekend in Florida, he stepped into the press cabin with that familiar energy and confidence we’ve all come to know so well. Reporters asked about the MRI he had during his...
Read More
Uganda Police Ban Campaign Processions and Ambulance Misuse as Bobi Wine Launches Kampala Campaigns in Kawempe | 2026 Elections. - Runfarbiz Network
Uganda Police Ban Campaign Processions and Ambulance Misuse as Bobi Wine Launches Kampala Campaigns in Kawempe | 2026 Elections.
The Uganda Police Force has taken decisive steps to ensure that the ongoing election campaigns across the country remain peaceful, orderly, and in strict compliance with both the law and public health regulations. In a detailed statement released ahead of intensified campaign activities in the capital and other urban centers, the police leadership outlined a comprehensive framework of security and conduct guidelines that every candidate, campaign team, political party, and...
Read More
Auditor-General Demands Shs2 Trillion Forensic Tax Audit on Uganda Telecom Companies Over Revenue Discrepancies. - Runfarbiz Network
Auditor-General Demands Shs2 Trillion Forensic Tax Audit on Uganda Telecom Companies Over Revenue Discrepancies.
The Auditor-General, Mr John Muwanga, has asked the Uganda Revenue Authority (URA) to conduct a forensic audit into the affairs of telecommunications companies, citing a potential revenue loss of nearly Shs2 trillion.In his report for the financial year ended December 31, 2023, which was submitted to Parliament last week, Mr Muwanga indicated that the audit should cover the period between 2018 and 2023.The recommendation stems from a review of the...
Read More
DR GODFREY EGWAU DIES AT MULAGO - Runfarbiz Network
DR GODFREY EGWAU DIES AT MULAGO
Teso's long-serving gynaecologist, Dr. Godfrey Egwau, has passed away at Mulago National Referral Hospital in Kampala. He was a renowned medical practitioner who dedicated decades to improving women's healthcare in Soroti and surrounding districts.Dr. Egwau was known for his exceptional skill and compassionate approach to maternal health, earning him respect from patients and colleagues alike. He was also a dedicated mentor, guiding young medical officers with patience and professionalism.The news...
Read More
Antoine Semenyo £65m Release Clause Active in January: Man City, Liverpool & Spurs Monitoring Bournemouth Star. - Runfarbiz Network
Antoine Semenyo £65m Release Clause Active in January: Man City, Liverpool & Spurs Monitoring Bournemouth Star.
Bournemouth forward Antoine Semenyo has a £65m release clause that becomes active in January, Sky Sports News understands.The clause is structured as £60m plus £5m in add-ons, but it is only active for a limited period during the January transfer window. The release clause price is set to drop in the summer of 2026.Bristol City, who sold Semenyo to Bournemouth for around £10m in January 2023, would be due 20...
Read More
Uganda and Kenya Assure No War Over Indian Ocean Oil Dispute , Museveni Remarks, Mudavadi Response & EAC Diplomacy 2025. - Runfarbiz Network
Uganda and Kenya Assure No War Over Indian Ocean Oil Dispute , Museveni Remarks, Mudavadi Response & EAC Diplomacy 2025.
In the vast expanse of East Africa's geopolitical landscape, where landlocked nations like Uganda grapple with the eternal challenge of accessing the sea, a recent flare-up in diplomatic tensions has once again thrust the relationship between Uganda and Kenya into the global spotlight. It all began with a seemingly innocuous yet provocative statement from Ugandan President Yoweri Museveni, delivered during a radio appearance in Mbale City on November 8, 2025....
Read More

WEBSITE PAGE LISTS

HomepageAbout UsPrivacy PolicyTerms of ServiceLogin| RegisterDisclaimerContact Us