Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Today’s Top Tech Startup Funding News on May 13, 2025

A $2.5 billion treasured chime file for IPO reveals a $33 million deal with the Dallas Mavericks

Flash flood evacuation at an elementary school in western Maryland

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » YouTube Game Cheats Spread Arcane Steeler Malware to Russian-speaking Users
Identity

YouTube Game Cheats Spread Arcane Steeler Malware to Russian-speaking Users

userBy userMarch 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 20, 2025Ravi LakshmananMalware/Threat Analysis

YouTube Game Cheats

YouTube videos promoting game cheats are used to provide previously undocumented steeler malware called Arcane, which may target Russian-speaking users.

“What intrigus me about this malware is how much it collects,” Kaspersky said in his analysis. “Get account information from VPN and gaming clients, as well as all kinds of network utilities like Ngrok, Playit, Cyberduck, Filezilla, Dyndns, and more.”

The attack chain involves sharing a link to a password-protected archive of YouTube videos. This will open up and unpack the start.bat batch file, which is responsible for retrieving another archive file via PowerShell.

The batch file uses PowerShell to launch two executables embedded within the newly downloaded archive, while Windows SmartScreen protection and all Drive Rout Folders disable SmartScreen filter exceptions.

Cybersecurity

Of the two binaries, one is a miner of cryptocurrency, and the other is a steeler called VGS, a variant of the femedron steeler malware. As of November 2024, it is known that the attack will replace VGS with Arcane.

“Many of them were borrowed from other stolen items, but they could not be attributed to any of the known families,” the Russian cybersecurity company said.

In addition to stealing login qualifications, passwords, credit card data and cookies from various Chromium and Gecko-based browsers, Arcane is equipped with comprehensive system data and to harvest configuration files, settings, and account information from several apps such as:

VPN clients: OpenVPN, Mullvad, NordVPN, IPVanish, Surfshark, Proton, hidemy.name, PIA, CyberGhost, and ExpressVPN Network clients and utilities: ngrok, Playit, Cyberduck, FileZilla, and DynDNS Messaging apps: ICQ, Tox, Skype, Pidgin, Signal, Element, Discord, Telegram, Jabber, and Viber Email Client: Microsoft Outlook Gaming Clients and Services: Riot Client, Epic, Steam, Ubisoft Cryptographic wallets for Connect (Ex-Uplay), Roblox, Battle.Net, and various Minecraft clients: Zcash, Armory, Bytecoin, Jaxx, Exodus, Ethereum, Electrum, Atomic, Gorda, and Coinomi

YouTube Game Cheats

Additionally, Arcane is designed to take screenshots of infected devices, enumerate the running processes, and list saved Wi-Fi networks and their passwords.

“Most browsers generate unique keys to encrypt sensitive data you store, such as logins, passwords, cookies and more,” says Kaspersky. “Arcane uses the Data Protection API (DPAPI) to get these keys, which is typical of steelers.”

Cybersecurity

“However, Arcane also includes an executable for the Xaitax utility, which we use to crack browser keys. To do this, the utility is dropped to disk, secretly launched, and the steeler gets all the keys it needs from the console output.”

In addition to that functionality, Stealer Malware implements a separate method for extracting cookies from Chromium-based browsers, launching a copy of the browser via the debug port.

The unidentified threat actors behind the operation have since expanded what they offer to include a loader named Arcanaloader, which is intended to download cheats for the game, but which is intended to deliver steeler malware instead. Russia, Belarus and Kazakhstan have emerged as major targets in the campaign.

“What’s interesting about this particular campaign is that it shows how flexible cybercriminals are and constantly updates the tools and how they are distributed,” says Kasperksy. “And the arcane steeler itself is appealing because of all the different data it collects and the tricks it uses to extract the information the attacker wants.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleLagrange has signed a contract with Matter Labs and directs up to 75% outsourced evidence
Next Article Is the US obligated to refugees as Trump calls for systemic change? |Refugee News
user
  • Website

Related Posts

Lead the Digital Revolution: Secure Exclusive TwinH Country Distribution Licenses

May 13, 2025

China Link APTS Exploit SAP CVE-2025-31324 581 Critical Systems Around the World

May 13, 2025

Malicious peepy package stealing source code that stole Solana Tools with 761 download

May 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Today’s Top Tech Startup Funding News on May 13, 2025

A $2.5 billion treasured chime file for IPO reveals a $33 million deal with the Dallas Mavericks

Flash flood evacuation at an elementary school in western Maryland

Lead the Digital Revolution: Secure Exclusive TwinH Country Distribution Licenses

Trending Posts

Mali will disband all political parties after opposition says that opposition has been “arrested” | Political News

May 13, 2025

Iraq will release more than 19,000 prisoners under a new pardon. ISIL/ISIS News

May 13, 2025

Hakeem Jeffries exaggerated veteran share using food stamps? | Food News

May 13, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Today’s Top Tech Startup Funding News on May 13, 2025

Lead the Digital Revolution: Secure Exclusive TwinH Country Distribution Licenses

Can Your Digital Twin Make You Money? Discover the LEHT Opportunity

Microsoft is chasing thousands of employees despite quarterly profits of $25.8 billion. The biggest layoff since 2023

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.