• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Android

Links from YouTube video captions are being used to hide password-stealing malware

March 13, 2022
Share on FacebookShare on Twitter

Definitely don’t cross this RedLine


Malware can hide inside perfectly innocent-looking Play Store apps. One day you download something for two-factor authentication or even an app that looks like it was built to clean viruses off your phone and the next thing you know a hacker in Russia is logging in to your bank account. Malicious software can pretty much hide anywhere, not just app stores, and that includes captions for YouTube videos. In this case, the malware in question wants to steal your passwords and links to it have been associated with videos claiming to provide hacks and cheats for games.

This example was reported by Korean security specialists Asec, found via Bleeping Computer. The malware in this instance has been dubbed RedLine, and it wants to steal a lot of crucial information if it finds its way onto your device. Asec discovered links to download RedLine in the caption for a YouTube video that appeared to offer hacks for the free Windows game, “Valorant.” According to Bleeping Computer, it’s not even that hard for bad links of this kind to sneak onto the platform because “threat actors find it easy to bypass YouTube’s new content submission reviews or create new accounts when reported and blocked.”

ANDROIDPOLICE VIDEO OF THE DAY

So — say you’re a frustrated gamer looking to find something called an “auto-aiming bot” to help you level up in a shooter like “Valorant” and you find a video promoting a cheat with a link in the caption. It might take you to a file with a name like “Cheat installer.exe.” You download it thinking you’ll be able to insert it into the game and start racking up points, but what you’ve actually done is given RedLine a doorway to your private information. Asec listed all the data it can steal, and it includes passwords, credit card numbers, information saved for AutoFill forms, bookmarks, and cookies. RedLine can also drain crypto accounts and targeted wallets include Armory, AtomicWallet, BitcoinCore, Bytecoin, DashCore, Electrum, Ethereum, and Jaxx. Researchers also found RedLine uses Discord to send information back to the malware’s command and control system — a recent but not uncommon development.


If delivering malicious software by using a YouTube lure isn’t exactly new, researchers report it still isn’t quite as common as methods like phishing emails and SMS. The Infosec Institute analysis of RedLine itself indicates it began to show up more often in 2021, and it looks like it will continue spreading as threat operators find new and more creative ways to trick users into popping their poison pills. A good rule of thumb in this case? It might seem self-evident, but whatever you do, don’t trust random links found in YouTube captions or comments.



Image27
Google’s changes to the Android Beta Program have created a huge mess

But it would be simple to fix

Read Next


About The Author

Steve Huff
(57 Articles Published)

Steve is the Weekend News Editor for Android Police. He was previously the Deputy Digital Editor for Maxim magazine and has written for Inside Hook, Observer, and New York Mag. He’s the author of two official tie-ins books for AMC’s hit “Breaking Bad” prequel, “Better Call Saul.”

More
From Steve Huff

Next Post

Toyota, Lexus: Inventory, current and future, on dealer minds

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • NYT Pips hints, answers for April 7, 2026
  • Today’s Hurdle hints and answers for April 7, 2026
  • Pixel 10a gets stunning new Isai Blue finish, but it’s not coming to the US
  • Review: Marvel MaXimum Collection Welcomes You To Die… Of Nostalgia  – Entertainium
  • NYT Connections hints and answers for April 7. Tips to solve ‘Connections’ #1031.

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously