Cyber Criminals has started targeting Youtubers in promoting the trojan malware links.

Post Image
Cybercriminals are sending bogus copyright claims to YouTubers to coerce them into promoting malware and cryptocurrency miners on their videos.

The threat actors take advantage of the popularity of Windows Packet Divert (WPD) tools that are increasingly used in Russia as they help users bypass internet censorship and government-imposed restrictions on websites and online services.

YouTube creators catering to this audience publish tutorials on how to use various WPD-based tools to bypass censorship and are being targeted by threat actors posing as the copyright holders of these tools.

In most cases seen by Kaspersky, the threat actors claim to be the original developers of the presented restriction bypass tool, filing a copyright claim with YouTube and then contacting the creator to offer a resolution in the form of including a download link they provide.

At the same time, they threaten that non-compliance will result in two more "strikes" on YouTube, which could lead to a channel ban based on the platform's "three strikes" policy.

In other cases, the attackers contact the creator directly, impersonating the tool's developers and claiming that the original tool has a new version or new download link, asking the creator to change it on their video.

The creators, fearing they will lose their channels, give in to the threat actors' demands, and agree to add links in their videos to GitHub repositories that host the said Windows Packet Divert (WPD) tools. However, these are trojanized versions that include a cryptominer downloader instead.


Kaspersky has seen this promotion of laced WPD tools take place on a YouTube video that generated over 400,000 views, with the malicious link reaching 40,000 downloads before it got removed.

A Telegram channel with 340,000 subscribers has also promoted the malware under the same disguise.

"According to our telemetry, the malware campaign has affected more than 2,000 victims in Russia, but the overall figure could be much higher," warns Kaspersky.


SilentCryptoMiner deployment
The malicious archive downloaded from the GitHub repositories contains a Python-based malware loader that is launched using PowerShell via a modified start script ('general.bat').

If the victim's antivirus disrupts this process, the start script delivers a 'file not found' error message suggesting that the user disables their antivirus and re-download the file.

The executable fetches the second-stage loader only for Russian IP addresses and executes it on the device.


The second stage payload is another executable whose size was bloated to 690 MB to evade antivirus analysis, while it also features anti-sandbox and virtual machine checks.

The malware loader turns off Microsoft Defender protections by adding an exclusion and creates a Windows service named 'DrvSvc' for persistence between reboots.


Eventually, it downloads the final payload, SilentCryptoMiner, a modified version of XMRig capable of mining multiple cryptocurrencies, including ETH, ETC, XMR, and RTM.

The coin miner fetches remote configurations from Pastebin every 100 minutes so it can be updated dynamically.

For evasion, it is loaded into a system process like 'dwm.exe' using process hollowing and pauses mining activity when the user launches monitoring tools like Process Explorer and the Task Manager.


Although the campaign discovered by Kaspersky primarily targets Russian users, the same tactics may be adopted for broader-scoped operations that also deliver higher-risk malware like info-stealers or ransomware.

Users should avoid downloading software from URLs in YouTube videos or descriptions, especially from smaller to medium-sized channels that are more susceptible to scams and blackmail.






Go Back

RECENTLY PUBLISHED CONTENTS

Solomon Kampala, Son of Bobi Wine, Engages Mexican Partner Helen Jaquez in Stunning Lakeside Proposal
Solomon Kampala, Son of Bobi Wine, Engages Mexican Partner Helen Jaquez in Stunning Lakeside Proposal
Solomon Kampala, the eldest son of Ugandan opposition leader and musician Bobi Wine, has officially announced his engagement to his Mexican partner, Helen Jaquez. The romantic lakeside proposal took place on Lake Travis in Texas, and the news quickly spread across social media, capturing the hearts of many.  At just 19 years old, Solomon shared the happy news through a series of stunning photos and videos on Instagram. The couple was...
Read More
The tech world was left stunned when Perplexity, the $18 billion AI startup led by Indian-origin CEO Aravind Srinivas, made an audacious $34.5 billion cash offer to acquire Google Chrome.
The tech world was left stunned when Perplexity, the $18 billion AI startup led by Indian-origin CEO Aravind Srinivas, made an audacious $34.5 billion cash offer to acquire Google Chrome.
The tech world was left stunned when Perplexity, the $18 billion AI startup led by Indian-origin CEO Aravind Srinivas, made an audacious $34.5 billion cash offer to acquire Google Chrome. Yes, the same Chrome that dominates the global browser market with over 60% share, owned by Alphabet, one of the most valuable companies in the world. The move has raised eyebrows, not just because of the sheer audacity but because...
Read More
Crystal Palace stunned Liverpool to win the Community Shield
Crystal Palace stunned Liverpool to win the Community Shield
Crystal Palace stunned Liverpool by winning the Community Shield 3-2 in a penalty shootout after the match ended 2-2 in regular time. The game saw new Liverpool signings Hugo Ekitike and Jeremie Frimpong score for the Reds, while Jean-Philippe Mateta and Ismaila Sarr netted for Palace.Match Highlights:Early Goal: Liverpool took the lead within four minutes, courtesy of Hugo Ekitike's precise finish assisted by Florian Wirtz.Palace Equalizer: Crystal Palace leveled the...
Read More
UPDF has disqualified More than 60000 Applicants In Intitail Phase Screening.
UPDF has disqualified More than 60000 Applicants In Intitail Phase Screening.
The Uganda People’s Defence Forces (UPDF) recruitment drive for 2025 has become one of the most talked-about topics in the country this week, and for good reason. Over 60,000 applicants—65,000 to be exact—were disqualified in the initial phase, leaving only 13,000 candidates to proceed to the next stage. The army aims to enlist 11,500 new soldiers, meaning even among the shortlisted, another 1,500 will face elimination after physical screenings in...
Read More
UPDF Bids Farewell to Over 600 Retirees in Nationwide Ceremonies.
UPDF Bids Farewell to Over 600 Retirees in Nationwide Ceremonies.
The Uganda Peoples’ Defence Forces (UPDF) has officially retired more than 600 junior officers and Non-Commissioned Officers (NCOs) in a series of vibrant ceremonies held across its various divisions and services.At the central ceremony in Bombo, Maj Gen Francis Takirwa, Deputy Commander Land Force, paid tribute to the retirees for their unwavering dedication to Uganda’s security and their contributions to peacekeeping operations abroad. “It is now with great honour that...
Read More
EAST AFRICA MUSIC STAR IODINE KENYA
EAST AFRICA MUSIC STAR IODINE KENYA
Iodine Kenya, whose real name is Martin Nkonge, is a prominent Kenyan independent artist...
Read More


MOST POPULAR CREATORS

WEBSITE PAGE LISTS

HomepageAbout UsPrivacy PolicyTerms of ServiceLogin| RegisterDisclaimerContact Us