Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Anthropic CEO Dario Amodei calls OpenAI’s message about military agreement a ‘blatant lie,’ report says

Google settles with Epic Games, lowers Play Store fees to 20%

MacBook Neo, iPhone 17e, and everything else Apple announced this week

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » YouTube Game Cheats Spread Arcane Steeler Malware to Russian-speaking Users
Identity

YouTube Game Cheats Spread Arcane Steeler Malware to Russian-speaking Users

userBy userMarch 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 20, 2025Ravi LakshmananMalware/Threat Analysis

YouTube Game Cheats

YouTube videos promoting game cheats are used to provide previously undocumented steeler malware called Arcane, which may target Russian-speaking users.

“What intrigus me about this malware is how much it collects,” Kaspersky said in his analysis. “Get account information from VPN and gaming clients, as well as all kinds of network utilities like Ngrok, Playit, Cyberduck, Filezilla, Dyndns, and more.”

The attack chain involves sharing a link to a password-protected archive of YouTube videos. This will open up and unpack the start.bat batch file, which is responsible for retrieving another archive file via PowerShell.

The batch file uses PowerShell to launch two executables embedded within the newly downloaded archive, while Windows SmartScreen protection and all Drive Rout Folders disable SmartScreen filter exceptions.

Cybersecurity

Of the two binaries, one is a miner of cryptocurrency, and the other is a steeler called VGS, a variant of the femedron steeler malware. As of November 2024, it is known that the attack will replace VGS with Arcane.

“Many of them were borrowed from other stolen items, but they could not be attributed to any of the known families,” the Russian cybersecurity company said.

In addition to stealing login qualifications, passwords, credit card data and cookies from various Chromium and Gecko-based browsers, Arcane is equipped with comprehensive system data and to harvest configuration files, settings, and account information from several apps such as:

VPN clients: OpenVPN, Mullvad, NordVPN, IPVanish, Surfshark, Proton, hidemy.name, PIA, CyberGhost, and ExpressVPN Network clients and utilities: ngrok, Playit, Cyberduck, FileZilla, and DynDNS Messaging apps: ICQ, Tox, Skype, Pidgin, Signal, Element, Discord, Telegram, Jabber, and Viber Email Client: Microsoft Outlook Gaming Clients and Services: Riot Client, Epic, Steam, Ubisoft Cryptographic wallets for Connect (Ex-Uplay), Roblox, Battle.Net, and various Minecraft clients: Zcash, Armory, Bytecoin, Jaxx, Exodus, Ethereum, Electrum, Atomic, Gorda, and Coinomi

YouTube Game Cheats

Additionally, Arcane is designed to take screenshots of infected devices, enumerate the running processes, and list saved Wi-Fi networks and their passwords.

“Most browsers generate unique keys to encrypt sensitive data you store, such as logins, passwords, cookies and more,” says Kaspersky. “Arcane uses the Data Protection API (DPAPI) to get these keys, which is typical of steelers.”

Cybersecurity

“However, Arcane also includes an executable for the Xaitax utility, which we use to crack browser keys. To do this, the utility is dropped to disk, secretly launched, and the steeler gets all the keys it needs from the console output.”

In addition to that functionality, Stealer Malware implements a separate method for extracting cookies from Chromium-based browsers, launching a copy of the browser via the debug port.

The unidentified threat actors behind the operation have since expanded what they offer to include a loader named Arcanaloader, which is intended to download cheats for the game, but which is intended to deliver steeler malware instead. Russia, Belarus and Kazakhstan have emerged as major targets in the campaign.

“What’s interesting about this particular campaign is that it shows how flexible cybercriminals are and constantly updates the tools and how they are distributed,” says Kasperksy. “And the arcane steeler itself is appealing because of all the different data it collects and the tricks it uses to extract the information the attacker wants.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleLagrange has signed a contract with Matter Labs and directs up to 75% outsourced evidence
Next Article Is the US obligated to refugees as Trump calls for systemic change? |Refugee News
user
  • Website

Related Posts

149 hacktivist DDoS attacks hit 110 organizations in 16 countries after Middle East conflict

March 4, 2026

Coruna iOS exploit kit uses 23 exploits across 5 chains targeting iOS 13 to 17.2.1

March 4, 2026

New RFP template for AI usage control and AI governance

March 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Anthropic CEO Dario Amodei calls OpenAI’s message about military agreement a ‘blatant lie,’ report says

Google settles with Epic Games, lowers Play Store fees to 20%

MacBook Neo, iPhone 17e, and everything else Apple announced this week

149 hacktivist DDoS attacks hit 110 organizations in 16 countries after Middle East conflict

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.