![]() Google has since terminated the hacked channels. The development echoes another campaign in which gamers looking for cheats and cracks on YouTube are being directed to videos containing links to a malicious archive file distributing information stealers and cryptocurrency miners. Rather, the idea appears to be to identify the victims through their browsing histories, social networking account IDs, and Wi-Fi network SSIDs. What's notable about the command-and-control server (torbrowserio) is that it's a visual replica of the original Tor Browser website and its download links lead to the legitimate Tor Browser portal.įurthermore, unlike other information stealers, OnionPoison is not designed to gather user passwords, session cookies, or wallet data. The spyware module further provides the functionality to exfiltrate a list of installed software and running processes, browser histories, victims' WeChat and QQ account IDs, in addition to executing arbitrary shell commands on the victim machine. The weaponized freebl3.dll library achieves this by establishing contact with a remote server that responds back with a second-stage payload containing the spyware, but only when the IP address of the victim originates from China. ![]() ![]() "More importantly, one of the libraries bundled with the malicious Tor Browser is infected with spyware that collects various personal data and sends it to a command-and-control server," Kaspersky researchers Leonid Bezvershenko and Georgy Kucherin said. ![]() ![]() The attack banks on the fact that the actual Tor Browser website is blocked in China, thus tricking unsuspecting users searching for "Tor浏览器" (i.e., Tor Browser in Chinese) on YouTube into potentially downloading the rogue variant.Ĭlicking on the link redirects the user to a 74MB executable that, once installed, is designed to store users' browsing history and data entered into website forms. The channel that hosted the video has 181,000 subscribers and claims to be based in Hong Kong. Google has moved to pull the video from the social media platform for violating YouTube's Harmful and Dangerous policies. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |