YouTube BitCoin Videos Pushing Predator Info-Stealing Trojan

- Advertisement -

A new scam is underway on YouTube that uses videos to promote a tool that can allegedly generate the private key for a bitcoin address. The attackers then claim this key would then allow you to gain access to the bitcoins stored in the bitcoin address, when in reality the victims will be infected with a password and data stealing Trojan.

This campaign was discovered by security researcher Frost who routinely monitors YouTube videos for cryptocurrency scams that lead to malware, which in this particular case is the Predator the Thief information-stealing Trojan

In this scam, the attacker is uploading videos that promotes a fake bitcoin address private key generator that can be used to steal other people’s bitcoins.

Uploaded Videos

In the video’s description will also be links to download the trojanized program from Yandex, Google Drive, and Mega.

Video Promoting Trojan

The file being offered is called Crypto World.zip and when extracted contains a setup.exe file, which includes a password-protected ZIP file containing the Predator the Thief executable.  This setup.exe file currently has 1/71 detections on VirusTotal.

CryptoWorld.zip files

This setup.exe program is a Trojan that will unzip a file to the .languagetemplatestemp folder as license.exe.

Extracting Predator the Thief installer

The license.exe file will then be executed and the Predator the Thief information stealing Trojan will be installed and executed on the computer.

Once running, Predator the Thief will communicate with the malware’s command and control server to download further components, other malware, and to send information back to the attackers.

Predator Network Traffic

This Trojan can steal a variety of information and passwords from a computer, including copying the victim’s clipboard, recording over the webcam, and stealing files from the victim.

According to Kaspersky, Predator the Thief v3 has the following features and this version may be newer.

LocationData stolen
GamesOsu
Battle.net
FTPWinSCP
VPNNordVPN
2FAAuthy
MessengersPidgin
Skype
Operating SystemWebcam
HWID
Clipboard
Specific document files (Grabber)
Project filenames*
BrowsersIE/Edge

If you have been infected with this Trojan, you should immediately change all passwords for your financial accounts, web sites, chat services such as Discord, and gaming services such as Steam and Battle.net. 

As always, you should use a password manager in order to create unique and strong passwords for every account you visit and never download programs off of YouTube, especially ones that claim to generate free money or cryptocurrency.



Source

Previous Articles:

- Advertisement -
- Advertisement -
- Advertisement -

Latest

Bitcoin Holds Above $87K as Traders Eye US Tariffs and Economic Data

Bitcoin holds steady above $87,000 as traders await U.S. economic data and April 2nd tariff developments.Memecoins outperform major cryptocurrencies, with DOGE rising 5.5% and...

SEC Closes Immutable Investigation as IMX Token Surges 15%

Immutable's token (IMX) surged 15% after the SEC closed its investigation without taking further action.IMX reached its highest price since March 3 before retracing...

Dogecoin Surges 10% as Analysts Project $3 Target in Third Crypto Cycle

Dogecoin has gained 10% in value over the past week, maintaining support above $0.18 while showing a 5% daily increase.Market analysts predict DOGE could...

SEC Closes Immutable Investigation, No Enforcement Action Taken

SEC has closed its investigation into Immutable with no enforcement action, ending a five-month probe into potential securities law violations related to the IMX...

Napster returns with $207M acquisition, plans music-focused metaverse

Artificial Intelligence startup Infinite Reality has acquired music streaming service Napster in a $207 million deal.The acquisition aims to transform Napster into a music-focused...

SIX MINING: UK Crypto Firm Offers Green Passive Income Opportunity

SIX MINING, established in the UK in 2018, offers cryptocurrency investment opportunities focused on Passive income generation.The company emphasizes environmental responsibility through a commitment...

Cboe Seeks SEC Approval for Fidelity’s Solana ETF Amid Crypto Surge

Cboe has filed with the SEC to list shares of Fidelity's Solana ETF, marking a significant step in the approval process.Solana-based investment products have...

SEC to Host Four More Crypto Roundtables on Tokenization and DeFi

The SEC's Crypto Task Force will hold four additional roundtable discussions this spring on topics including crypto trading, custody, tokenization, and DeFi.Commissioner Hester Peirce...
- Advertisement -

Must Read

Top 8 Best Anonymous Web Hosting Companies That Accept Crypto

Nowadays, there is plenty of information about people online, and malicious people use them to carry out inappropriate activities. If you want to keep...

Read Next
Recommended to you