AI-generated YouTube videos spreading info-stealing malware, Here’s how

by 24britishtvMarch 14, 2023, 7 p.m. 17
-


• Who are the founders of YouTube?

Jawed Karim, Steve Chen, Chad Hurley

According to a report by cyber intelligence firm CloudSEK , YouTube has recently experienced a surge in videos that include harmful links to infostealers in their descriptions. Many of these videos utilize AI-generated personas to deceive viewers into trusting them.Since November 2022, there has been a significant increase of 200-300% in content uploaded to the video hosting website that tricks viewers into installing well-known malware like Vidar, RedLine, and Raccoon . The videos claim to be tutorials on how to download illicit copies of popular paid-for design software such as Adobe Photoshop Autodesk 3ds Max, and AutoCAD.The tutorial videos have become increasingly sophisticated, evolving from simple screen recordings and audio walkthroughs to now utilizing AI to create a realistic portrayal of a person guiding the viewer through the process. The goal is to create a more trustworthy appearance and deceive viewers into downloading malware.According to CloudSEK, the use of AI-generated videos is growing for legitimate purposes like education, recruitment, and promotion, but unfortunately, cybercriminals are also taking advantage of this technology for their malicious purposes.Infostealers are a type of malware that infiltrate a user's system and steal personal and valuable information, including passwords and payment details. They are often spread through malicious downloads and links, such as those found in video descriptions in this case. The stolen data is then uploaded to the attacker's server.CloudSEK has highlighted that YouTube, with its 2.5 billion monthly users, is a prime target for threat actors. To avoid detection by the platform's automated content review process, attackers employ various tactics to deceive the algorithm. These tactics include using region-specific tags, adding fake comments to make videos appear legitimate, and flooding the platform with multiple videos to compensate for any removed or banned content. CloudSEK discovered that as many as 5-10 of these malicious videos are uploaded every hour.For SEO optimization, attackers also use hidden links and random keywords in different languages to manipulate YouTube's recommendation algorithm. To conceal the malicious nature of the links, link-shortening services like bit.ly and file hosting services such as MediaFire are frequently utilized.According to CloudSEK, relying solely on traditional string-based rules will not be enough to detect malware that uses dynamically generated or encrypted strings. Instead, they recommend that organizations adopt a more manual approach to threat detection, where tactics and techniques of threat actors are closely monitored to correctly identify potential threats.Moreover, CloudSEK suggests conducting awareness campaigns that share simple advice such as avoiding clicking on unknown links and using multi-factor authentication to secure accounts, preferably with an authenticator app.

-

Related Articles

HOT TRENDS

Could office blocks be the next big casualty of the banking crisis?

by 24britishtvMarch 28, 2023, 7:20 a.m.2
HOT TRENDS

David Jason ‘delighted’ to discover 52-year-old daughter he never knew

by 24britishtvMarch 28, 2023, 7:20 a.m.2
HOT TRENDS

Deal Or No Deal set to return to screens with Stephen Mulhern to host series

by 24britishtvMarch 28, 2023, 2:20 a.m.2
HOT TRENDS

Man Utd 'banished' Greenwood from first team training but Sanchez saved him

by 24britishtvMarch 28, 2023, 1:20 a.m.2
HOT TRENDS

Everything we know about Mason Greenwood - next move and Man Utd stance

by 24britishtvMarch 28, 2023, midnight2
HOT TRENDS

Saudi Arabia in the orbit of China and Russia: towards a new strategic alliance?

by 24britishtvMarch 27, 2023, 11:20 p.m.2
HOT TRENDS

Can Humza Yousaf unite the SNP?

by 24britishtvMarch 27, 2023, 11:20 p.m.2
HOT TRENDS

Republic of Ireland vs. France - Football Match Report - March 27, 2023 - ESPN

by 24britishtvMarch 27, 2023, 11:20 p.m.2
HOT TRENDS

Coronation Street confirms Justin's fate after acid attack

by 24britishtvMarch 27, 2023, 10:20 p.m.2
HOT TRENDS

Republic of Ireland 0-1 France commentary

by 24britishtvMarch 27, 2023, 9:20 p.m.2
HOT TRENDS

Phillip Schofield's brother 'sexually abused teenage boy over three years'

by 24britishtvMarch 27, 2023, 9:20 p.m.2
HOT TRENDS

Prince Harry shows he is not bluffing in vendetta against Daily Mail owner

by 24britishtvMarch 27, 2023, 9:20 p.m.2
HOT TRENDS

Ireland vs France: live score and latest updates from the Euro 2024 qualifiers

by 24britishtvMarch 27, 2023, 8:20 p.m.2
HOT TRENDS

Calls for answers over Poole harbour oil spill as cleanup continues

by 24britishtvMarch 27, 2023, 7:21 p.m.2
HOT TRENDS

England MU18s 3-1 Switzerland

by 24britishtvMarch 27, 2023, 6:20 p.m.2
HOT TRENDS

Rolex announces a hefty lineup of new watches for 2023

by 24britishtvMarch 27, 2023, 6:20 p.m.2
HOT TRENDS

Stuart Hogg announces retirement post Rugby World Cup 2023

by 24britishtvMarch 27, 2023, 5:20 p.m.2
HOT TRENDS

Stuart Hogg: Scotland full-back to retire after 2023 Rugby World Cup

by 24britishtvMarch 27, 2023, 4:20 p.m.2
HOT TRENDS

Linda Nolan reveals heart-breaking health update on Good Morning Britain

by 24britishtvMarch 27, 2023, 4:20 p.m.2
HOT TRENDS

When is the first DWP cost of living payment date in 2023?

by 24britishtvMarch 27, 2023, 4:20 p.m.2