Malware campaigns create videos to distribute trojans that steal passwords from unsuspecting viewers.

See also: Google: Hackers target YouTubers with cookie theft malware
Password-stealing trojans are malicious software that runs silently on a computer and steals passwords, screenshots, cookies, credit cards stored in browsers, FTP credentials, and various other files.
Once installed, the malware communicates with a Command & Control server and waits for commands from the attacker, which could result in the execution of additional malware.
Malicious actors have long used YouTube videos as a way to distribute malware, via embedded links in the video descriptions.
However, this week, Cluster25 security researcher Frostsaid there has been a significant increase in malware campaigns on YouTube, pushing various password-stealing Trojans.
Frost said it's possible that two groups of malicious activity are taking place simultaneously. One is promoting the RedLine malware and the other is promoting Racoon Stealer.
The researcher said that thousands of videos and channels had been created as part of this massive malware campaign, with 100 new videos and 81 channels being created in just twenty minutes.
Frost explained that threat actors use the stolen Google accounts to start new YouTube channels and spread malware, creating an endless and ever-expanding cycle.
See also: Android security update may be malware

The attacks begin with criminals creating numerous YouTube channels, filled with videos about hardware cracks, licenses, user guides, cryptocurrencies, mining, VPN software, and almost any other popular category.
These videos contain content that explains how to perform a task using a specific program or utility. Additionally, the YouTube video description includes a supposed link to the relevant tool used to distribute the malware.
If a video contains a bit.ly link, it leads to another file-sharing website that hosts the password-stealing RedLine malware.
Once a user is infected, the malware will proceed to scan all installed browsers and the computer for cryptocurrency wallets, credit cards, passwords, and other data and send them to the attacker.
These campaigns show how important it is not to randomly download programs from the Internet, as sites like YouTube cannot check every link added by video publishers.
Therefore, a user should research a website before downloading and installing any program from it to see if it has a good reputation and is trustworthy. Even then, it is always recommended to first upload the program to a website like VirusTotal to confirm if it is safe to run.
See also: YouTube permanently cancels Rewind after years
If you have accidentally fallen victim to this attack and installed a program from a similar link, it is recommended that you scan your computer with an antivirus program. After removing any malware detected in a virus scan, you should immediately change any passwords stored in your browsers.
