{"id":419898,"date":"2021-10-25T22:52:20","date_gmt":"2021-10-25T20:52:20","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=419898"},"modified":"2021-10-25T22:58:13","modified_gmt":"2021-10-25T20:58:13","slug":"russian-crypto-scammers-target-youtube-channels","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/419898-russian-crypto-scammers-target-youtube-channels.html","title":{"rendered":"Russian crypto scammers target YouTube channels"},"content":{"rendered":"<p>Russian cryptocurrency scammers are targeting YouTube, according to a <strong><a href=\"https:\/\/blog.google\/threat-analysis-group\/phishing-campaign-targets-youtube-creators-cookie-theft-malware\/\" target=\"_blank\" rel=\"noopener\">report<\/a><\/strong> from Google&#8217;s Threat Analysis Group (TAG).<\/p>\n<p>These cybercriminals use cookie theft malware, also known as a &#8220;pass-the-cookie-attack&#8221;, to take over YouTube channels and post cryptocurrency scams.<\/p>\n<p>&#8220;Pass-the-cookie-attacks&#8221; enable hackers to access user accounts via session cookies that are stored in the browser.<\/p>\n<p>As a result, this allows attackers to access the passwords and YouTube account information of their victims.<\/p>\n<p>Google has attributed the phishing cookie-theft attacks and phishing campaigns to a group of hackers recruited via a Russian speaking forum.<\/p>\n<p>The attacks have been ongoing since late 2019, TAG stated.<\/p>\n<p>According to TAG, the hackers &#8220;lure their target with fake collaboration opportunities (typically a demo for anti-virus software, VPN, music players, photo editing or online games)&#8221;.<\/p>\n<div id=\"attachment_419902\" style=\"width: 810px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-419902\" class=\"wp-image-419902 size-full\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/10\/Example-of-Crypto-email-\u2014-800-x-533.png\" alt=\"\" width=\"800\" height=\"533\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/10\/Example-of-Crypto-email-\u2014-800-x-533.png 800w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/10\/Example-of-Crypto-email-\u2014-800-x-533-600x400.png 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/10\/Example-of-Crypto-email-\u2014-800-x-533-640x426.png 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/10\/Example-of-Crypto-email-\u2014-800-x-533-768x512.png 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><p id=\"caption-attachment-419902\" class=\"wp-caption-text\">Example of a phishing email sent to channel owners.<\/p><\/div>\n<p>They then &#8220;hijack their channel, then either sell it to the highest bidder or use it to broadcast cryptocurrency scams&#8221;.<\/p>\n<p>These phishing attempts are commonly initiated with emails sent to YouTube channel owners.<\/p>\n<p>Once the channel owner agrees to the collab, the malware\u2014made to look like a software download URL\u2014is sent via email or a PDF on Google Drive.<\/p>\n<p>In collaboration with YouTube, Gmail, Trust &amp; Safety, CyberCrime Investigation Group and Safe Browsing teams, TAG said it had lowered the volume of phishing emails by 99.6% since May 2021.<\/p>\n<p>&#8220;We blocked 1.6M messages to targets, displayed ~62K Safe Browsing phishing page warnings, blocked 2.4K files, and successfully restored ~4K accounts,&#8221; they said.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/419876-russian-hacking-group-assaulting-global-tech-supply-chain.html\" target=\"_blank\" rel=\"noopener\">Russian hacking group assaulting global tech supply chain<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Google&#8217;s Threat Analysis Group has attributed phishing attempts targeted at YouTube channel owners to hackers recruited via a Russian forum.<\/p>\n","protected":false},"author":341076,"featured_media":419904,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[44696,27],"tags":[51093,167,30188,73190,2150],"class_list":["post-419898","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency","category-security","tag-cryptocurrency-scam","tag-google","tag-phishing-attack","tag-threat-analysis-group-tag","tag-youtube"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/419898"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=419898"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/419898\/revisions"}],"predecessor-version":[{"id":419914,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/419898\/revisions\/419914"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/419904"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=419898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=419898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=419898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}