{"id":3487,"date":"2021-10-21T19:03:09","date_gmt":"2021-10-21T13:33:09","guid":{"rendered":"https:\/\/xiarch.com\/blog\/?p=3487"},"modified":"2021-10-21T19:03:10","modified_gmt":"2021-10-21T13:33:10","slug":"youtubers-accounts-seized-with-cookie-hijacking-malware-google","status":"publish","type":"post","link":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/","title":{"rendered":"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google"},"content":{"rendered":"\n<p><p style=\"text-align: justify;\">Google says YouTube creators have been targeted with credentials hijacking malware in phishing attacks coordinated by financially motivated threat actors. Investigators with Google\u2019s Threat Analysis Group (TAG), who initially spotted the operations in late 2019, discover that multiple hack-for-hire actors inducted through job ads on Russian-speaking forums were behind these adversaries.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">The threat actors utilized social engineering (through fake software landing pages and social media accounts) and phishing emails to infect YouTube creators with data-hijacking malware, chosen based on each threat actor\u2019s weakness.<\/p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Channels Seized in Pass-The-Cookie Attacks<\/strong><\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">Malware recognized in the attacks includes commodity strains like RedLine, Vidar, Predator The Thief, Nexus stealer, Azorult, Raccoon, Grand Stealer, Vikro Stealer, Masad, and Kantal, as well as open-source ones like AdamantiumThief and leaked tools such as Sorano.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Once delivered on the targets&#8217; systems, the malware was used to steal their credentials and browser cookies which allowed the attackers to hijack the victims&#8217; accounts in pass-the-cookie attacks.&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">&#8220;While the technique has been around for decades, its resurgence as a top security risk could be due to a wider adoption of multi-factor authentication (MFA) making it difficult to conduct abuse, and shifting attacker focus to social engineering tactics,&#8221; said Ashley Shen, a TAG Security Engineer.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">&#8220;Most of the observed malware was capable of stealing both user passwords and cookies. Some of the samples employed several anti-sandboxing techniques including enlarged files, encrypted archive and download IP cloaking.&#8221;<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Google identified at least 1,011 domains linked to these attacks and roughly 15,000 actor accounts specifically created for this campaign and used to deliver phishing emails containing links redirecting to malware landing pages to YouTube creators&#8217; business emails.<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"1000\" height=\"482\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/10\/YouTubers-Accounts-Seized-with-Cookie-Hijacking-Malware\u2013Google-image1.png\" alt=\"YouTuber\u2019s-Accounts-Seized-with-Cookie-Hijacking-Malware\u2013Google-image1\" class=\"wp-image-3489\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/10\/YouTubers-Accounts-Seized-with-Cookie-Hijacking-Malware\u2013Google-image1.png 1000w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/10\/YouTubers-Accounts-Seized-with-Cookie-Hijacking-Malware\u2013Google-image1-300x145.png 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/10\/YouTubers-Accounts-Seized-with-Cookie-Hijacking-Malware\u2013Google-image1-768x370.png 768w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" \/><\/figure><\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Traded For up to $4,000 on Underground Markets<\/strong><\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">A meaningful number of YouTube channels seized in these attacks were later rebranded to represent high-profile tech managers or cryptocurrency exchange firms and used for live streaming cryptocurrency scams.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Others were marketed on covered account-trading markets, where they are worth anything between $3 to $4,000, depending on their total number of subscribers. Shen added that Google&#8217;s Threat Analysis Group cut down phishing emails linked to these attacks on Gmail by 99.6% since May 2021.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">&#8220;We blocked 1.6M messages to targets, displayed ~62K Safe Browsing phishing page warnings, blocked 2.4K files, and successfully restored ~4K accounts,&#8221; Shen said.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">&#8220;Including enhanced disclosure attempts, we have recognized attackers changing away from Gmail to another email providers mostly email.cz, seznam.cz, post.cz and aol.com.&#8221; Google also published this malicious activity to the FBI for further investigation to protect YouTube users and originators targeted in the operations.<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google says YouTube creators have been targeted with credentials hijacking malware in phishing attacks coordinated by financially motivated threat actors. Investigators with Google\u2019s Threat Analysis Group (TAG), who initially spotted the operations in late 2019, discover that multiple hack-for-hire actors inducted through job ads on Russian-speaking forums were behind these adversaries. The threat actors utilized [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3490,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.11 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google - Xiarch Solutions Private Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google - Xiarch Solutions Private Limited\" \/>\n<meta property=\"og:description\" content=\"Google says YouTube creators have been targeted with credentials hijacking malware in phishing attacks coordinated by financially motivated threat actors. Investigators with Google\u2019s Threat Analysis Group (TAG), who initially spotted the operations in late 2019, discover that multiple hack-for-hire actors inducted through job ads on Russian-speaking forums were behind these adversaries. The threat actors utilized [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/\" \/>\n<meta property=\"og:site_name\" content=\"Xiarch Solutions Private Limited\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/xiarch\/\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-21T13:33:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-10-21T13:33:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/10\/YouTubers-Accounts-Seized-with-Cookie-Hijacking-Malware\u2013Google-featured-image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"525\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Xiarch Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@xiarch\" \/>\n<meta name=\"twitter:site\" content=\"@xiarch\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Xiarch Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/\"},\"author\":{\"name\":\"Xiarch Security\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\"},\"headline\":\"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google\",\"datePublished\":\"2021-10-21T13:33:09+00:00\",\"dateModified\":\"2021-10-21T13:33:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/\"},\"wordCount\":433,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"articleSection\":[\"Vulnerabilities\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/\",\"url\":\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/\",\"name\":\"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google - Xiarch Solutions Private Limited\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#website\"},\"datePublished\":\"2021-10-21T13:33:09+00:00\",\"dateModified\":\"2021-10-21T13:33:10+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/xiarch.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/xiarch.com\/blog\/#website\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"name\":\"Xiarch Solutions Private Limited\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/xiarch.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\",\"name\":\"Xiarch\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"contentUrl\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"width\":300,\"height\":300,\"caption\":\"Xiarch\"},\"image\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/xiarch\/\",\"https:\/\/twitter.com\/xiarch\",\"https:\/\/www.linkedin.com\/company\/xiarch\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\",\"name\":\"Xiarch Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"caption\":\"Xiarch Security\"},\"sameAs\":[\"https:\/\/xiarch.com\/blog\/\"],\"url\":\"https:\/\/xiarch.com\/blog\/author\/vector\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google - Xiarch Solutions Private Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/","og_locale":"en_US","og_type":"article","og_title":"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google - Xiarch Solutions Private Limited","og_description":"Google says YouTube creators have been targeted with credentials hijacking malware in phishing attacks coordinated by financially motivated threat actors. Investigators with Google\u2019s Threat Analysis Group (TAG), who initially spotted the operations in late 2019, discover that multiple hack-for-hire actors inducted through job ads on Russian-speaking forums were behind these adversaries. The threat actors utilized [&hellip;]","og_url":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/","og_site_name":"Xiarch Solutions Private Limited","article_publisher":"https:\/\/www.facebook.com\/xiarch\/","article_published_time":"2021-10-21T13:33:09+00:00","article_modified_time":"2021-10-21T13:33:10+00:00","og_image":[{"width":1000,"height":525,"url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/10\/YouTubers-Accounts-Seized-with-Cookie-Hijacking-Malware\u2013Google-featured-image.jpg","type":"image\/jpeg"}],"author":"Xiarch Security","twitter_card":"summary_large_image","twitter_creator":"@xiarch","twitter_site":"@xiarch","twitter_misc":{"Written by":"Xiarch Security","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/#article","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/"},"author":{"name":"Xiarch Security","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c"},"headline":"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google","datePublished":"2021-10-21T13:33:09+00:00","dateModified":"2021-10-21T13:33:10+00:00","mainEntityOfPage":{"@id":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/"},"wordCount":433,"commentCount":0,"publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"articleSection":["Vulnerabilities"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/","url":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/","name":"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google - Xiarch Solutions Private Limited","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/#website"},"datePublished":"2021-10-21T13:33:09+00:00","dateModified":"2021-10-21T13:33:10+00:00","breadcrumb":{"@id":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/xiarch.com\/blog\/youtubers-accounts-seized-with-cookie-hijacking-malware-google\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/xiarch.com\/blog\/"},{"@type":"ListItem","position":2,"name":"YouTuber\u2019s Accounts Seized with Cookie-Hijacking Malware \u2013 Google"}]},{"@type":"WebSite","@id":"https:\/\/xiarch.com\/blog\/#website","url":"https:\/\/xiarch.com\/blog\/","name":"Xiarch Solutions Private Limited","description":"","publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/xiarch.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/xiarch.com\/blog\/#organization","name":"Xiarch","url":"https:\/\/xiarch.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","contentUrl":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","width":300,"height":300,"caption":"Xiarch"},"image":{"@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/xiarch\/","https:\/\/twitter.com\/xiarch","https:\/\/www.linkedin.com\/company\/xiarch"]},{"@type":"Person","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c","name":"Xiarch Security","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","caption":"Xiarch Security"},"sameAs":["https:\/\/xiarch.com\/blog\/"],"url":"https:\/\/xiarch.com\/blog\/author\/vector\/"}]}},"_links":{"self":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/3487"}],"collection":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/comments?post=3487"}],"version-history":[{"count":1,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/3487\/revisions"}],"predecessor-version":[{"id":3491,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/3487\/revisions\/3491"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media\/3490"}],"wp:attachment":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media?parent=3487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/categories?post=3487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/tags?post=3487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}