Security News > 2022 > October > Popular YouTube Channel Caught Distributing Malicious Tor Browser Installer

Popular YouTube Channel Caught Distributing Malicious Tor Browser Installer
2022-10-04 15:39

A popular Chinese-language YouTube channel has emerged as a means to distribute a trojanized version of a Windows installer for the Tor Browser.

The malicious version of the Tor Browser installer is being distributed via a link present in the description of a video that was uploaded to YouTube on January 9, 2022.

The attack banks on the fact that the actual Tor Browser website is blocked in China, thus tricking unsuspecting users searching for "Tor浏览器" on YouTube into potentially downloading the rogue variant.

"More importantly, one of the libraries bundled with the malicious Tor Browser is infected with spyware that collects various personal data and sends it to a command-and-control server," Kaspersky researchers Leonid Bezvershenko and Georgy Kucherin said.

What's notable about the command-and-control server is that it's a visual replica of the original Tor Browser website and its download links lead to the legitimate Tor Browser website.

The development echoes another campaign in which gamers looking for cheats and cracks on YouTube are being directed to videos containing links to a malicious archive file distributing information stealers and crypto miners.


News URL

https://thehackernews.com/2022/10/popular-youtube-channel-caught.html