PULSE NAME
Threat Actors Deliver Malware via YouTube Video Game Cracks
WHITE AlienVault 2024-04-03 Modified: 2024-04-03
18
IOCs
MEDIUM VOLUME
Proofpoint identified malicious actors distributing information stealers like Vidar, StealC, and Lumma Stealer on YouTube by promoting cracked video games and software. The actors leverage video descriptions containing links leading to malware downloads disguised as cracks or cheats. This activity primarily targets consumer users without enterprise-grade security, exploiting their interest in pirated content. Tactics involve using compromised YouTube accounts with large followings, creating temporary accounts for malware distribution, and impersonating popular cracking groups like Empress. The threat actors often provide instructions to disable antivirus software and use bloated executable files to evade detection. Command and control infrastructure leverages social platforms like Telegram, Steam, and Discord to blend in with regular network traffic.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Vidar StealC Lumma Stealer
Indicators of Compromise (18)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 2c1e42d5e1eaf851b3b1ce14f6646a94 2024-04-03
FileHash-MD5 477a4bbb17eb966c637f1fbdb5219fbf 2024-04-03
FileHash-MD5 679dff0691158b5367ef511a57e7a1fc 2024-04-03
FileHash-MD5 82574182bfe062e72bb750ee1e641e08 2024-04-03
FileHash-MD5 dd0f7e40960943820da54ef28e1ffafb 2024-04-03
FileHash-MD5 e1f4c125e7ec9e784198518ade924a40 2024-04-03
FileHash-SHA1 5c1ced94ddfe084c88d66aabfa0ec899073e1e83 2024-04-03
FileHash-SHA256 8f0c665c9553661e80666a526e9c939ca9da69bd0bd75b935d5952f80d4687ab 2024-04-03
domain detectordiscusser.shop 2024-04-03
domain edurestunningcrackyow.fun 2024-04-03
domain lighterepisodeheighte.fun 2024-04-03
domain pooreveningfuseor.pw 2024-04-03
domain problemregardybuiwo.fun 2024-04-03
domain sideindexfollowragelrew.pw 2024-04-03
domain technologyenterdo.shop 2024-04-03
URL https://mediafire.com/folder/ol5512r4mova/Setup 2024-04-03
URL https://steamcommunity.com/profiles/76561199637071579 2024-04-03
URL https://t.me/karl3on 2024-04-03