• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
beware! youtube videos promoting cracked software distribute lumma stealer

Beware! YouTube Videos Promoting Cracked Software Distribute Lumma Stealer

You are here: Home / General Cyber Security News / Beware! YouTube Videos Promoting Cracked Software Distribute Lumma Stealer
January 9, 2024

Risk actors are resorting to YouTube films that includes written content related to cracked software program in order to entice users into downloading an information stealer malware identified as Lumma.

“These YouTube video clips normally feature material similar to cracked applications, presenting consumers with related set up guides and incorporating malicious URLs frequently shortened making use of services like TinyURL and Cuttly,” Fortinet FortiGuard Labs researcher Cara Lin stated in a Monday investigation.

This is not the first time pirated software program movies on YouTube have emerged as an helpful bait for stealer malware. Formerly comparable attack chains were noticed delivering stealers, clippers, and crypto miner malware.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

In accomplishing so, menace actors can leverage the compromised devices for not only data and cryptocurrency theft, but also abuse the resources for illicit mining.

In the most current attack sequence documented by Fortinet, users browsing for cracked variations of respectable online video editing equipment like Vegas Pro on YouTube are prompted to click on a url located in the video’s description, major to the obtain of a bogus installer hosted on MediaFire.

Lumma Stealer

The ZIP installer, the moment unpacked, options a Windows shortcut (LNK) masquerading as a set up file that downloads a .NET loader from a GitHub repository, which, in transform, loads the stealer payload, but not in advance of performing a sequence of anti-digital equipment and anti-debugging checks.

Lumma Stealer, penned in C and provided for sale on underground forums since late 2022, is able of harvesting and exfiltrating sensitive info to an actor-managed server.

The advancement arrives as Bitdefender warned of stream-jacking attacks on YouTube in which cybercriminals consider about high-profile accounts via phishing attacks that deploy the RedLine Stealer malware to siphon their credentials and session cookies, and ultimately endorse a variety of crypto frauds.

Cybersecurity

It also follows the discovery of an 11-month-outdated AsyncRAT marketing campaign that employs phishing lures to download an obfuscated JavaScript file which is then utilized to fall the remote accessibility trojan.

“The victims and their firms are meticulously chosen to broaden the impact of the marketing campaign,” AT&T Alien Labs researcher Fernando Martinez stated. “Some of the identified targets manage crucial infrastructure in the U.S.”

Identified this article fascinating? Stick to us on Twitter  and LinkedIn to read through more exceptional written content we publish.


Some sections of this write-up are sourced from:
thehackernews.com

Previous Post: «syrian hackers distributing stealthy c# based silver rat to cybercriminals Syrian Hackers Distributing Stealthy C#-Based Silver RAT to Cybercriminals
Next Post: Alert: New Vulnerabilities Discovered in QNAP and Kyocera Device Manager alert: new vulnerabilities discovered in qnap and kyocera device manager»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms
  • Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist
  • 6 Steps to 24/7 In-House SOC Success
  • Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
  • 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers
  • New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theft
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session
  • Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Copyright © TheCyberSecurity.News, All Rights Reserved.