YouTube Bitcoin Scams Pushing the njRAT Backdoor InfoStealer

- Advertisement -

YouTube scams are promoting software that pretends to allow users to get free Bitcoins, but instead installs the njRAT remote access trojan and password stealer.

These YouTube videos pretend to be hack scripts, giveaways, or games that allow you to win free cryptocurrency such as bitcoins. These videos tend to have the “FREEBITCO IN” string in the title or description, which makes it easy to find the videos that are part of this campaign.

YouTube Bitcoin Scam

YouTube Bitcoin Scam

According to security researcher Frost who discovered this campaign, we should expect to see more of these scam videos as the prices of Bitcoin continue to rise above $10,000.

Included in the description for these videos is a http://bit.ly link that leads to a landing page that offers a “Freebitcoins 2019 Update Script” that you need to download and run in order to generate your free Bitcoin.

Scam Landing Page

Clicking on the download button brings you to a free file sharing service, such as SecuFiles below, where you can download the script.  In this particular example the script is named “SCRIPT UPDATE WIN BTC.VBS”.

Downloading Script

As a general word of warning, never download files that end with VBS, JS, or BAT from any file sharing site. There is very high chance that these will be used to install an infection on to your computer.

Infecting users with njRAT

This “SCRIPT UPDATE WIN BTC.VBS” is obfuscated to make it a bit harder to analyze it and determine what it is doing as shown below.

Obfuscated Script

Once deobfuscated,  we can see that it will save an embedded base64 encoded strings as the file Windows.exe and then execute it. This executable is detected as Bladabindi or njRAT.

Deobfuscated Script

When launched, the Windows.exe will connect to a command and control server and send a variety of information such as the PC name, user name, and more. It will then wait for commands given by the attacker that the program will execute.

njRAT Executable

As this infection has the ability to steal browser passwords and log keystrokes, if you are infected by this scam, it should be assumed that your login names and passwords have been compromised. Once the computer is cleaned, you should change your login credentials at any sites you regularly use, especially financial institutions.

Source

Previous Articles:

- Advertisement -
- Advertisement -
- Advertisement -

Latest

Warren Slams Trump Stablecoin Bill: “Grift to Enrich Himself”

Senator Elizabeth Warren criticizes stablecoin legislation, claiming it enables President Trump to leverage his crypto project for personal enrichment.Warren specifically targets the Financial Innovation...

Trump Threatens “Larger Scale Tariffs” on EU, Canada Amid Trade Tensions

Former President Trump threatens larger import tariffs against EU and Canada if they collaborate to harm U.S. economic interests.Financial markets remain stable despite Trump's...

OpenAI’s revenue to surge to $12.7B amid rising Chinese AI challengers

OpenAI projects revenue growth from $12.7 billion in 2024 to $29.4 billion in 2025, despite not expecting positive cash flow until 2029.The company is...

Synthetix Founder Exposes Predatory Crypto Market Maker Tactics

Synthetix founder Kain Warwick revealed how crypto market makers have evolved from legitimate operations to manipulative entities charging projects up to $300,000 monthly during...

Court Dismisses Dfinity Lawsuit: ICP Investors’ Claims Expired

U.S. District Judge James Donato dismissed a class action lawsuit against Dfinity related to Internet Computer (ICP) tokens, citing time limitation issues.The lawsuit, filed...

US Senate Votes to Kill Biden-Era DeFi Tax Reporting Rule

US Senate passed a resolution with a 70-28 vote to repeal the IRS DeFi broker rule targeting crypto reporting.The resolution will next head to...

Russia Faces Energy Crisis, May Import Electricity from China

Russia faces severe energy shortages caused by the Ukraine war, Western sanctions, and cryptocurrency mining demand, transforming it from an energy exporter to a...

US Lawmakers Push Stablecoin Bill Forward in Trump’s Crypto Agenda

Republican lawmakers plan to advance stablecoin legislation and update the FIT 21 crypto framework within days.House Financial Services Crypto Subcommittee published a draft stablecoin...
- Advertisement -

Must Read

17 Best Audiobooks On Blockchain Technology For Beginners

If you're looking to dive into the world of blockchain technology, you're in for a treat. The field is rapidly evolving and the potential...

Read Next
Recommended to you