Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » YouTube Game Cheats distributes arcane theft malicious software for Russian users
Global Security

YouTube Game Cheats distributes arcane theft malicious software for Russian users

AdminBy AdminMarch 20, 2025No Comments3 Mins Read
YouTube Game Cheats
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 20, 2025Red LakshmananAnalysis of malicious programs / threats

YouTube Games Cheats

Video on YouTube that promote cheats games Concea Probably focusing on Russian users.

“What is intriguing in this malicious program is how much it collects,” Caspersorsky – Note In the analysis. “It seizes information about VPN and gaming customers, as well as all kinds of network utilities such as NGROK, Playit, CyberDuck, Filezilla and Dyndns.”

The attack networks provide for the sharing of the links to the archive, protected by the password on the YouTube video, which at the opening unpack the bath.bat package, which is responsible for obtaining another archive file via PowerShell.

Then the batch file uses PowerShell to launch two executable files, built into the recently uploaded archive, and disconnect Windows Smartscreen Afteryions and each root drive folder before the Smartscreen filter.

Cybersecurity

Of two binary files one – a miner cryptocurrency and the other is the theft called VGS, which is an option Feder Sorting for theft. As of November 2024, the attacks that replaced the VGS were detected.

“Although most of it was borrowed from other theft, we could not carry it by any of the famous families,” said the Russian cybersecurity campaign.

In addition to theft of login data, passwords, credit card data and files from different browsers based on chromium and gecko, Arcane is equipped to collect complex system data, as well as configuration files, settings and information about multiple applications, such as subsequent ones next- next- next The following- following- following, such as the following, such as the following,-

  • Customers VPN: Openvpn, Mullvad, Nordvpn, IPVANISH, Surfshark, Proton, Hidemy.name, Pia, CyberGhost and Expressvpn
  • Network Customers and Utilities: Ngrok, Playit, CyberDuck, Filezilla and Dyndns
  • Messaging applications: ICQ, Tox, Skype, Pidgin, Signal, Element, Discord, Telegram, Jabber and Viber
  • Email customers: Microsoft Outlook
  • Customers and Services Games: Customer Riot, Epic, Steam, Ubisoft Connect (Ex-Uplay), Roblox, Battle.net and Different Minecraft customers
  • Crypto -Choshes: Zcash, Armory, Bytecoin, XAX, Exodus, Ethereum, Electrum, Atomic, Guarda and Coinomi
YouTube Games Cheats

In addition, Arcane is designed to make screenshots of the infected device, list launch processes and list the stored Wi-Fi networks and their passwords.

“Most browsers generate unique keys to encrypt the sensitive data they store, such as entry, passwords, cookies, etc.,” Kaspersky said. “Arcane uses API data protection (DPAPI) to obtain these keys, which is characteristic of theft.”

Cybersecurity

“But Arcane also contains the executed Xaitax utility file, which it uses to hack the browser keys. To do this, the utility is dropped on the disk and launched, and the theft gets all the keys that are needed from the console output.”

Adding to its capabilities, malicious software the theft implements a separate method of extracting browsers based on chromium, which triggers a copy of the browser through debug.

Unknown threats behind the operation has since expanded its proposals to include a loader called Arcanaloader, which allegedly means downloading games, but instead provides malicious theft software. Russia, Belarus and Kazakhstan have become the main goals of the company.

“What’s interesting in this particular company is that it illustrates how flexible cybercrime is always updating its tools and methods of their distribution,” Caspersci said. “In addition, the stealing theft himself is fascinating from all the different data he collects, and the tricks he uses to receive the attackers want.”

Found this article interesting? Keep track of us next Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025

Learn the smarter way to protect modern applications

May 16, 2025

Meta to train AI on EU users since May 27 without consent; NOIB is threatened by lawsuits

May 15, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.