• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Malicious Tor Browser Installers Spread Via Darknet Video on YouTube

You are here: Home / General Cyber Security News / Malicious Tor Browser Installers Spread Via Darknet Video on YouTube
October 4, 2022

Cybersecurity researchers have recognized several bacterial infections through malicious Tor Browser installers distribute through an explanatory video clip about the Darknet on YouTube.

The discovery comes from Kaspersky, which said in an advisory printed earlier right now that the channel in dilemma has far more than 180,000 subscribers, even though the look at depend on the movie with the malicious url exceeds 64,000.

By adding a connection to an infected model of Tor Browser in the description bar of the video clip, cyber–criminals, dubbed ‘OnionPoison’ by the security firm, spread malware that could accumulate victims’ details and attain total command around their personal computers by using shell commands.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“Most of the affected people had been from China,” Kaspersky wrote. “As the Tor Browser web page is blocked in China, individuals from this country usually resort to downloading Tor from third–party sites. And cyber–criminals are keen on spreading their destructive exercise through this sort of sources.”

From a technological standpoint, Kaspersky stated the analyzed variation of Tor Browser is configured to be less private than the original software package device.

In fact, the malicious variant not only stored searching record and all the information the person entered into site varieties but also distributed spy ware to obtain particular info and send it to the hackers’ server.  

“Curiously, as opposed to quite a few other stealers, OnionPoison does not seem to be to demonstrate a distinct interest in collecting users’ passwords or wallets,” Kaspersky stated.

“Instead, they are likely to be more interested in gathering victims’ determining information and facts which can be used to observe down the victims’ identities, these types of as searching histories, social network account IDs and WiFi networks.”

According to Kaspersky, the tactic is relating to as it hints at curiosity by the attacker to transfer from electronic to serious life.

“The attackers can collect facts on the victim’s own existence, his household or household tackle. Moreover, there are circumstances when the attacker employed the acquired data to blackmail the sufferer.”

Kaspersky warned providers and persons versus downloading computer software from suspicious third–party internet websites to lessen the risks of turning into victims of these malicious campaigns.

“If employing formal sites is not an alternative for you, it is achievable to confirm the authenticity of installers downloaded from third–party resources by inspecting their digital signatures.”

The advisory comes months immediately after Tor Job up-to-date its flagship anonymizing browser to make it less difficult for buyers to evade federal government attempts to block its use in numerous areas.

More a short while ago, hacker teams reportedly made use of the resource to aid protestors in Iran.


Some areas of this article are sourced from:
www.infosecurity-magazine.com

Previous Post: «best security systems for business Best security systems for business
Next Post: Researchers Report Supply Chain Vulnerability in Packagist PHP Repository researchers report supply chain vulnerability in packagist php repository»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.