Cyber Criminals has started targeting Youtubers in promoting the trojan malware links.

Post Image
Cybercriminals are sending bogus copyright claims to YouTubers to coerce them into promoting malware and cryptocurrency miners on their videos.

The threat actors take advantage of the popularity of Windows Packet Divert (WPD) tools that are increasingly used in Russia as they help users bypass internet censorship and government-imposed restrictions on websites and online services.

YouTube creators catering to this audience publish tutorials on how to use various WPD-based tools to bypass censorship and are being targeted by threat actors posing as the copyright holders of these tools.

In most cases seen by Kaspersky, the threat actors claim to be the original developers of the presented restriction bypass tool, filing a copyright claim with YouTube and then contacting the creator to offer a resolution in the form of including a download link they provide.

At the same time, they threaten that non-compliance will result in two more "strikes" on YouTube, which could lead to a channel ban based on the platform's "three strikes" policy.

In other cases, the attackers contact the creator directly, impersonating the tool's developers and claiming that the original tool has a new version or new download link, asking the creator to change it on their video.

The creators, fearing they will lose their channels, give in to the threat actors' demands, and agree to add links in their videos to GitHub repositories that host the said Windows Packet Divert (WPD) tools. However, these are trojanized versions that include a cryptominer downloader instead.


Kaspersky has seen this promotion of laced WPD tools take place on a YouTube video that generated over 400,000 views, with the malicious link reaching 40,000 downloads before it got removed.

A Telegram channel with 340,000 subscribers has also promoted the malware under the same disguise.

"According to our telemetry, the malware campaign has affected more than 2,000 victims in Russia, but the overall figure could be much higher," warns Kaspersky.


SilentCryptoMiner deployment
The malicious archive downloaded from the GitHub repositories contains a Python-based malware loader that is launched using PowerShell via a modified start script ('general.bat').

If the victim's antivirus disrupts this process, the start script delivers a 'file not found' error message suggesting that the user disables their antivirus and re-download the file.

The executable fetches the second-stage loader only for Russian IP addresses and executes it on the device.


The second stage payload is another executable whose size was bloated to 690 MB to evade antivirus analysis, while it also features anti-sandbox and virtual machine checks.

The malware loader turns off Microsoft Defender protections by adding an exclusion and creates a Windows service named 'DrvSvc' for persistence between reboots.


Eventually, it downloads the final payload, SilentCryptoMiner, a modified version of XMRig capable of mining multiple cryptocurrencies, including ETH, ETC, XMR, and RTM.

The coin miner fetches remote configurations from Pastebin every 100 minutes so it can be updated dynamically.

For evasion, it is loaded into a system process like 'dwm.exe' using process hollowing and pauses mining activity when the user launches monitoring tools like Process Explorer and the Task Manager.


Although the campaign discovered by Kaspersky primarily targets Russian users, the same tactics may be adopted for broader-scoped operations that also deliver higher-risk malware like info-stealers or ransomware.

Users should avoid downloading software from URLs in YouTube videos or descriptions, especially from smaller to medium-sized channels that are more susceptible to scams and blackmail.






Go Back

RECENTLY PUBLISHED CONTENTS

The Gaza Ceasefire and Netanyahu’s Precarious Future: A Deep Dive into Israel’s Political Landscape.
The Gaza Ceasefire and Netanyahu’s Precarious Future: A Deep Dive into Israel’s Political Landscape.
The article incorporates trending news themes, draws on recent analyses, and maintains a balanced perspective while exploring the political, diplomatic, and social challenges Netanyahu faces in the wake of the ceasefire. The structure remains coherent, with clear sections addressing the ceasefire’s implications, Israel’s international isolation, domestic political dynamics, and Netanyahu’s personal and legal challenges.Israeli Prime Minister Benjamin Netanyahu has long been a polarizing figure, both at home and abroad. His...
Read More
President Yoweri Museveni has promised to address two critical needs in Obongi District—electricity and better roads
President Yoweri Museveni has promised to address two critical needs in Obongi District—electricity and better roads
President Yoweri Museveni has promised to address two critical needs in Obongi District—electricity and better roads—assuring residents that the days of isolation and underdevelopment are numbered. Speaking to thousands of National Resistance Movement (NRM) supporters at Lionga Grounds in Obongi on Friday, October 17, 2025, the President and NRM presidential candidate announced that funding is secured to connect the district to electricity and start paving its major roads within the...
Read More
Germany's Air Power Pivot: Inside the 20 New Eurofighter Typhoon Order
Germany's Air Power Pivot: Inside the 20 New Eurofighter Typhoon Order
It’s a strange thing, reading a piece of news like this. On the surface, it’s just a headline, a transaction. A country orders some new hardware. Germany Orders 20 New Most Advanced Swing-Role Combat Aircraft in the World. You see it, you process the words, and your mind might flicker to images of sleek grey jets against a blue sky, the roar of an engine at an airshow, maybe a...
Read More
A comprehensive biography of Raila Odinga, exploring his journey from political detainee to Prime Minister, his five presidential bids, and his complex legacy in shaping modern Kenya.
A comprehensive biography of Raila Odinga, exploring his journey from political detainee to Prime Minister, his five presidential bids, and his complex legacy in shaping modern Kenya.
The world received the news on October 15, 2025, with profound shock: Raila Amolo Odinga, Kenya's perennial opposition leader and former prime minister, had passed away at age 80 after suffering a cardiac arrest while in Koothattukulam, Kerala, India. For decades, Odinga had been more than just a politician in Kenya; he was a living symbol of the nation's struggle for democracy, a figure who embodied both its promise and its...
Read More
Africa aviation industry, Isaac Balami University of Aeronautics and Management, IBUAM, first aeronautics university Africa.
Africa aviation industry, Isaac Balami University of Aeronautics and Management, IBUAM, first aeronautics university Africa.
Africa’s aviation industry is charting a new course as Nigeria launches the Isaac Balami University of Aeronautics and Management (IBUAM), the continent’s first specialised aeronautics and management institution. This groundbreaking development arrives at a pivotal moment for African aviation, a sector long defined by its challenges but now increasingly celebrated for its immense potential. The continent’s aviation market is projected to grow at 4.1% annually over the next 20 years,...
Read More
KENYAN VETERAN OPPOSITION LEADER RAILA ODINGA DIES AT 80
KENYAN VETERAN OPPOSITION LEADER RAILA ODINGA DIES AT 80
Raila Odinga, a veteran Kenyan opposition leader who served as prime minister and made five unsuccessful bids for the presidency, has died, according to multiple Kenyan media reports. He was 80.The Nairobi-based Star newspaper and other outlets reported that Odinga died Wednesday morning in India after suffering a heart attack. The reports cited sources within his family.Odinga was a dominant figure in Kenyan politics for more than three decades. His...
Read More


MOST POPULAR CREATORS

WEBSITE PAGE LISTS

HomepageAbout UsPrivacy PolicyTerms of ServiceLogin| RegisterDisclaimerContact Us