There’s a growing trend in the cybercrime landscape, and the trend is for malware authors to distribute backdoored malware using promotional videos and hacking tutorials on YouTube.
While backdoored malware isn’t anything new, the trend of using YouTube videos is, and the main reason is because of YouTube’s reach and the site’s appeal to non-technical users and wannabe hackers.
This wasn’t always the case. For many years Google employees have patrolled the site for illegal content and removed it after reports. Things got out of hand in the last year, and the number of hacking-related “tutorials” and “demos” has gotten out of hand.
Your reporter has noticed this rise in hacking tutorials, presentation demos, and how-to use malware videos in the past few months.
Searching YouTube for “exploit wordpress” yields over 40k videos. This explains why so many WP sites get hijacked pic.twitter.com/H6DHPEUQYr
— Catalin Cimpanu (@campuscodi) September 3, 2016
There are 186,000 search results on YouTube for the word “keylogger” …. I wonder where so many skids get the idea that “hacking is easy” pic.twitter.com/7uy7qWkDVY
— Catalin Cimpanu (@campuscodi) October 19, 2016
Most of these videos contain links in their description that drive traffic and wannabe crooks to websites where they can purchase or download for free the hacking tools and malware they’ve just seen used in the video.
YouTube videos have become a solid alternative to driving potential customers to commercial malware and is now just as reliable as threads on underground hacking forums, ads on Dark Web marketplaces, and IRC or Jabber spam.
YouTube videos lead to backdoored phishing kits
But not all these YouTube videos lead to “professional” malware. Researchers from US security firm Proofpoint have uncovered a large number of these videos that advertise backdoored malware.
In a series of cases they present on their blog, researchers break down and analyze the source code of various phishing kits you can download from links spread via YouTube videos.
Phishing kits are packages of ready-made login pages for various online services, ranging from Gmail to Amazon, and from Microsoft to PayPal.
Crooks download phishing kits and deploy them with various campaigns, with the aim of collecting the login credentials of their targets.
Proofpoint says that a large number of phishing kits advertised via YouTube contain hidden code that sends the stolen credentials to the phishing kit’s creator, not only the crook that bothered downloading, customizing and deploying the phishing kit.
Some clever malware authors are taking advantage of fellow crooks and wannabe hackers, and they’re making a living on the side.
This trend doesn’t affect only phishing kits. The same is also true for more complex malware such as keyloggers, RATs, and others. For example, when the Darktrack RAT was released online for free over the summer on an underground hacking forum, the first question asked was if someone inspected the source code for backdoors.
While no doubt a veteran hacker would have examined the source code for backdoors, newcomers to the world of cybercrime are in for a surprise and may end up doing all the heavy lifting for some malware author sitting in the shadows.
