Cybercriminals are increasingly leveraging YouTube's massive platform to distribute malware, bypassing traditional antivirus detections and exploiting users' trust in the popular video-sharing site.
See also: YouTube is testing a new horizontal layout on Android

Security researchers have uncovered a sophisticated campaign where hackers are hijacking YouTube channels and using them to spread information-stealing malware disguised as cracked software and game cheats.
Attackers target official YouTube channels, some with hundreds of thousands of subscribers, to lend credibility to their malware content. These compromised channels are then used to upload videos purporting to offer free versions of premium software or game hacks, with download links in the video descriptions or comments.
What makes this campaign stand out is the attackers’ use of legitimate file hosting services, such as Mediafire and Mega.nz, to host their malicious payloads. By leveraging these platforms, cybercriminals make it much harder for security software to detect and block threats.
See also: YouTube expands access to custom playback speeds
Additionally, many of the malicious downloads are password-protected and encrypted, further complicating analysis in security sandboxes and allowing the malware to evade early detection. The primary malware distributed via YouTube is a variant of Lumma Stealer, a sophisticated information-stealing trojan. Once installed on a victim's system, Lumma Stealer can collect a wide range of sensitive data, including:

- Stored passwords and autofill data from web browsers
- Cryptocurrency wallet information
- Steam and Discord tokens
- Credit card details
- Screenshots of the victim's desktop
This attack is particularly insidious because it exploits users' desire for free or cracked software. Threat actors create convincing installation guides and embed malicious URLs, often shortened using services like TinyURL and Cuttly to further obfuscate their true nature.
Security experts warn that this malware campaign is part of a broader trend of increasing theft attacks via YouTube.
See also: YouTube's AI dubbing available to more creators
Bypassing antivirus detections is a technique often used to evade security software’s protective measures. This involves understanding how antivirus programs detect malicious files and developing strategies to undermine their methods. Common approaches include using obfuscation to hide malicious code, encrypting payloads to make them appear benign, or using code injection to interfere with legitimate processes. Understanding the methodologies used by antivirus solutions is crucial to creating malware that can effectively bypass them. However, it is important to emphasize that this knowledge should only be applied ethically and within legal boundaries, such as to strengthen defenses and conduct authorized penetration testing.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
