HomeSecurityTubrosa malware sends users to YouTube

Tubrosa malware sends users to YouTube

tuberose

Known scammers profit from advertising revenue by using and spreading the Tubrosa, which redirects users to videos on their YouTubeafter it has been installed on computers.

The new malware campaign aims to make money by using the victim's computer to watch videos on YouTube and benefit from the ads displayed through them.

This malicious campaign, discovered by Symantec experts, has been running for several months, targeting users around the world through malware called Tubrosa. Tubrosa consists of two parts, the first which is delivered to the system via phishing email and the second which is the download and installation – execution of the first component.

The Tubrosa malware receives a list of YouTube links, about a thousand in number, from the C&C server and opens them in the background of the infected system. The malicious code uses some scripts to avoid arousing suspicion, but in reality, it mutes the computer speakers and opens the video in the background. Even if the computer does not have Adobe Flash player installed, the malware downloads and installs it to allow viewing of the videos.

Symantec experts estimate that the scammers have so far earned several thousand dollars through this campaign. It is impossible, they say, to know if there are other similar campaigns running at the moment. They also advise users that a sign of system infection is a drop in their computer's performance.

So far, the only information we know is that this campaign started in August 2014 and is still running. Most of the systems it has infected are in countries such as South Korea, India, Mexico, and the US.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS