Cyber Criminals has started targeting Youtubers in promoting the trojan malware links.

Cyber Criminals has started targeting Youtubers in promoting the trojan malware links.

Cybercriminals are sending bogus copyright claims to YouTubers to coerce them into promoting malware and cryptocurrency miners on their videos. The threat actors take advantage of the popularity of Windows Packet Divert (WPD) tools that are increasingly used in Russia as they help users bypass internet censorship and government-imposed restrictions on websites and online services. YouTube creators catering to this audience publish tutorials on how to use various WPD-based tools to bypass censorship and are being targeted by threat actors posing as the copyright holders of these tools. In most cases seen by Kaspersky, the threat actors claim to be the original developers of the presented restriction bypass tool, filing a copyright claim with YouTube and then contacting the creator to offer a resolution in the form of including a download link they provide. At the same time, they threaten that non-compliance will result in two more "strikes" on YouTube, which could lead to a channel ban based on the platform's "three strikes" policy. In other cases, the attackers contact the creator directly, impersonating the tool's developers and claiming that the original tool has a new version or new download link, asking the creator to change it on their video. The creators, fearing they will lose their channels, give in to the threat actors' demands, and agree to add links in their videos to GitHub repositories that host the said Windows Packet Divert (WPD) tools. However, these are trojanized versions that include a cryptominer downloader instead. Kaspersky has seen this promotion of laced WPD tools take place on a YouTube video that generated over 400,000 views, with the malicious link reaching 40,000 downloads before it got removed. A Telegram channel with 340,000 subscribers has also promoted the malware under the same disguise."According to our telemetry, the malware campaign has affected more than 2,000 victims in Russia, but the overall figure could be much higher," warns Kaspersky.
in Russia, but the overall figure could be much higher," warns Kaspersky. SilentCryptoMiner deploymentThe malicious archive downloaded from the GitHub repositories contains a Python-based malware loader that is launched using PowerShell via a modified start script ('general. bat'). If the victim's antivirus disrupts this process, the start script delivers a 'file not found' error message suggesting that the user disables their antivirus and re-download the file. The executable fetches the second-stage loader only for Russian IP addresses and executes it on the device. The second stage payload is another executable whose size was bloated to 690 MB to evade antivirus analysis, while it also features anti-sandbox and virtual machine checks. The malware loader turns off Microsoft Defender protections by adding an exclusion and creates a Windows service named 'DrvSvc' for persistence between reboots. Eventually, it downloads the final payload, SilentCryptoMiner, a modified version of XMRig capable of mining multiple cryptocurrencies, including ETH, ETC, XMR, and RTM. The coin miner fetches remote configurations from Pastebin every 100 minutes so it can be updated dynamically. For evasion, it is loaded into a system process like 'dwm. exe' using process hollowing and pauses mining activity when the user launches monitoring tools like Process Explorer and the Task Manager. Although the campaign discovered by Kaspersky primarily targets Russian users, the same tactics may be adopted for broader-scoped operations that also deliver higher-risk malware like info-stealers or ransomware. Users should avoid downloading software from URLs in YouTube videos or descriptions, especially from smaller to medium-sized channels that are more susceptible to scams and blackmail.

Go Back to All Posts

RECENT CONTENTS

Jeff Bezos Reclaims No. 3 Richest Title From Sergey Brin After Amazon Store Closures - Runfarbiz Network
Jeff Bezos Reclaims No. 3 Richest Title From Sergey Brin After Amazon Store Closures
Jeff Bezos became the world’s third-richest person again on Tuesday while reclaiming the spot from Google cofounder Sergey Brin, who surpassed Bezos earlier this month, as Amazon shares rose after announcing it would shutter dozens of retail stores to expand its Whole Foods Market business. Shares of Amazon rose 2.4% to above $244 as of 3:15 p.m. EST, while Alphabet shares increased slightly (0.6%). An uptick for Amazon’s stock followed...
Read More
Saudi Giant Acquires 123-Year-Old South African Firm Barloworld in $1.3 Billion Deal - Runfarbiz Network
Saudi Giant Acquires 123-Year-Old South African Firm Barloworld in $1.3 Billion Deal
Saudi Arabia’s Zahid Group has completed its acquisition of South African industrial company Barloworld in a landmark deal valued at R23 billion (about $1.3 billion). The transaction, finalized in January 2026, takes the 123-year-old firm private after more than a century on public markets and stands out as one of the most significant corporate cross-border deals between the Middle East and Africa in recent years.Barloworld’s shares will be delisted from...
Read More
Deputy CDF Okiding hails parade discipline ahead of Liberation Day. - Runfarbiz Network
Deputy CDF Okiding hails parade discipline ahead of Liberation Day.
Lt. Gen. Sam Okiding, the Deputy Chief of Defence Forces, has commended security forces for improving discipline and coordination as Uganda prepares to mark Liberation Day on Monday. Speaking at Kololo Ceremonial Grounds after inspecting parade rehearsals, Lt. Gen. Okiding said earlier shortcomings in the drills had been addressed and expressed confidence that the country would stage a flawless national celebration. He said some simple mistakes had been corrected and that...
Read More
UNEB SPEAKS ON PLE 2026 RELEASE. - Runfarbiz Network
UNEB SPEAKS ON PLE 2026 RELEASE.
KAMPALA, Uganda — The Uganda National Examinations Board dismissed reports Wednesday that the release of the 2025 Primary Leaving Examinations results has been delayed by a recent internet shutdown.Jennifer Kalule-Musamba, the board’s principal public relations officer, said claims linking the results timeline to the Jan. 14 internet interruption are false. She noted the reports were intended to cause panic among candidates and parents.The marking, verification and quality assurance processes for...
Read More
Ghana Government Security Official Has Arrested 9 Nigerians Involved In Scamming 400000$ from 200 Cyber Crime Victims - Runfarbiz Network
Ghana Government Security Official Has Arrested 9 Nigerians Involved In Scamming 400000$ from 200 Cyber Crime Victims
Ghana's security forces have arrested nine Nigerians suspected of co-ordinating a host of cyber-crime activities from makeshift offices in and around the capital, Accra. Forty-four others, believed to be victims brought to Ghana from Nigeria under false pretences, have also been detained and handed over to the immigration authority. During the two-day intelligence-led operation, raids uncovered 62 laptops, 52 mobile phones and two pump-action guns, the authorities have said. There is a growing...
Read More
Why Burkina Faso, Mali, and Niger Are Launching a Shared Telecom Satellite with Russia. - Runfarbiz Network
Why Burkina Faso, Mali, and Niger Are Launching a Shared Telecom Satellite with Russia.
Burkina Faso, Mali, and Niger have taken a decisive step toward reshaping the Sahel’s digital and economic future, turning to Russia to build the region’s first shared telecommunications satellite. The project, discussed under the framework of the Alliance of Sahel States (AES), underscores the three countries’ growing emphasis on technological sovereignty, regional integration, and economic self-reliance amid shifting geopolitical alliances. According to officials cited by Business Insider Africa, the satellite...
Read More

WEBSITE PAGE LISTS

HomepageAbout UsPrivacy PolicyTerms of ServiceLogin| RegisterDisclaimerContact Us
Initializing...