Android updates

YouTube virus: watch out for this malware in video descriptions!

Her nickname is Aurora Stealer. This is a piece of malware that – as the name suggests – will steal just about anything stealable from a computer. We are talking here about money via more than 40 types of crypto wallets, but also passwords to access the victim’s accounts or steal their identity. Aurora Stealer is part of a new wave of viruses: “Malware-as-a-Service”. Just pay $250/month to access the various features. Each budding little crook must therefore make his investment profitable by placing contaminated links to trap his unfortunate victims.

Watch out for links in YouTube descriptions!

The easiest way is to pollute YouTube videos using two techniques. The first is to hack more or less known channels, create a video using AI to promote software and place broken link in description. It is also possible to cheat gullible YouTubers. All the pirate has to do is pretend to be a salesman who wants to sell software. The YouTuber is paid for a certain amount or is paid a percentage (which he will never see the color) to place the link. After clicking on the latter, the victim does not suspect anything, because the page is strictly identical to that of the editor.

Antiviruses pass through…

This is where it becomes interesting, because the download link does not lead directly to malware, but to a “loader” which will generate “à la carte” malware for its victim. By using a “process hollowing” technique – which will modify part of a “safe” program with a contaminated part – the victim’s antivirus will see nothing but fire. Here, the loader will use the legitimate sihost.exe process to deliver the malware payload to the computer.

The guys from Tipiak are getting stronger and stronger.

youtube virus
On the VirusTotal malware detection site, the various components of Aurora are not detected as viruses…

Leave a Reply

Your email address will not be published. Required fields are marked *