AI-generated YouTube videos spreading info-stealing malware, Here’s how

CloudSEK report claims that there has been a recent upsurge in videos on YouTube that contain harmful links to infostealers in their descriptions. These videos often use AI-generated personas to trick viewers into trusting them.

Reuters
According to a report by cyber intelligence firm CloudSEK, YouTube has recently experienced a surge in videos that include harmful links to infostealers in their descriptions. Many of these videos make use of AI-generated personas to deceive viewers into trusting them.

Since November 2022, there has been a significant increase of 200-300% in content uploaded to the video hosting website that tricks viewers into installing well-known malware like Vidar, RedLine, and Raccoon. The videos claim to be tutorials on how to download illicit copies of popular paid-for design software such as Adobe Photoshop, Premiere Pro, Autodesk 3ds Max, and AutoCAD.

The tutorial videos have become increasingly sophisticated, evolving from simple screen recordings and audio walkthroughs to now utilizing AI to create a realistic portrayal of a person guiding the viewer through the process. The goal is to create a more trustworthy appearance and deceive viewers into downloading malware.


According to CloudSEK, the use of AI-generated videos is growing for legitimate purposes like education, recruitment, and promotion, but unfortunately, cybercriminals are also taking advantage of this technology for their malicious purposes.

Infostealers are a type of malware that infiltrate a user's system and steal personal and valuable information, including passwords and payment details. They are often spread through malicious downloads and links, such as those found in video descriptions in this case. The stolen data is then uploaded to the attacker's server.

YouTube new CEO Neal Mohan: 8 things you did not know about him
1/10

Indian-American Neal Mohan will be the new CEO of YouTube, replacing Susan Wojcicki who has announced to step down after 25 years at the company.

Indian-American Neal Mohan will be the new CEO of YouTube, replacing Susan Wojcicki who has announced to step down after 25 years at the company.

At the Stanford School of Business, Mohan was an Arjay Miller scholar, awarded to the top 10% of the class who have the highest GPA.

At the Stanford School of Business, Mohan was an Arjay Miller scholar, awarded to the top 10% of the class who have the highest GPA.

Neal Mohan started his career in 1996 at Accenture. From there he joined NetGravity, later acquired by internet advertising firm DoubleClick.

Neal Mohan started his career in 1996 at Accenture. From there he joined NetGravity, later acquired by internet advertising firm DoubleClick.

The 49-year-old left DoubleClick to pursue his career in MBA, after which he did a brief stink in Microsoft before rejoining DoubleClick.

The 49-year-old left DoubleClick to pursue his career in MBA, after which he did a brief stink in Microsoft before rejoining DoubleClick.

Neal Mohan played an important role in DoubleClick's $3.1 billion merger with Google, through which he joined the company.

Neal Mohan played an important role in DoubleClick's $3.1 billion merger with Google, through which he joined the company.

Mohan joined YouTube when Susan Wojcicki, a key architect of Google's online ad wing took over the video platform and recruited him as the Chief Product Officer.

Mohan joined YouTube when Susan Wojcicki, a key architect of Google's online ad wing took over the video platform and recruited him as the Chief Product Officer.

Mohan played an important role in launching key YouTube products like YouTube Premium, YouTube Music, YouTube Shorts and YouTube Kids.

Mohan played an important role in launching key YouTube products like YouTube Premium, YouTube Music, YouTube Shorts and YouTube Kids.

When Twitter was struggling to make it to prominence, Mohan was a top choice of the company. To retain him, Google offered him a $100 million stock bonus.

When Twitter was struggling to make it to prominence, Mohan was a top choice of the company. To retain him, Google offered him a $100 million stock bonus.

The new YouTube CEO has a bachelors degree in electrical engineering from Stanford University and an MBA from the Stanford Graduate School of Business.

The new YouTube CEO has a bachelors degree in electrical engineering from Stanford University and an MBA from the Stanford Graduate School of Business.

ADVERTISEMENT

CloudSEK has highlighted that YouTube, with its 2.5 billion monthly users, is a prime target for threat actors. To avoid detection by the platform's automated content review process, attackers employ various tactics to deceive the algorithm. These tactics include using region-specific tags, adding fake comments to make videos appear legitimate, and flooding the platform with multiple videos to compensate for any removed or banned content. CloudSEK discovered that as many as 5-10 of these malicious videos are uploaded every hour.

For SEO optimization, attackers also use hidden links and random keywords in different languages to manipulate YouTube's recommendation algorithm. To conceal the malicious nature of the links, link-shortening services like bit.ly and file hosting services such as MediaFire are frequently utilized.

According to CloudSEK, relying solely on traditional string-based rules will not be enough to detect malware that uses dynamically generated or encrypted strings. Instead, they recommend that organizations adopt a more manual approach to threat detection, where tactics and techniques of threat actors are closely monitored to correctly identify potential threats.

Moreover, CloudSEK suggests conducting awareness campaigns that share simple advice such as avoiding clicking on unknown links and using multi-factor authentication to secure accounts, preferably with an authenticator app.
ADVERTISEMENT

FAQs
  1. Who are the founders of YouTube?
    Jawed Karim, Steve Chen, Chad Hurley
  2. When was YouTube founded?
    February 14, 2005
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
Download
The Economic Times News App
for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › News › International › US News › AI-generated YouTube videos spreading info-stealing malware, Here’s how
Text Size:AAA
Success
This article has been saved

*

+