Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Trump administration cuts another $450 million with Harvard grants

Florida students have been accused of remaining in jail for massive shootings on campus

Government email alert system Govdelivery is used to send fraud messages

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » YouTube Game Cheats Spread Arcane Steeler Malware to Russian-speaking Users
Identity

YouTube Game Cheats Spread Arcane Steeler Malware to Russian-speaking Users

userBy userMarch 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 20, 2025Ravi LakshmananMalware/Threat Analysis

YouTube Game Cheats

YouTube videos promoting game cheats are used to provide previously undocumented steeler malware called Arcane, which may target Russian-speaking users.

“What intrigus me about this malware is how much it collects,” Kaspersky said in his analysis. “Get account information from VPN and gaming clients, as well as all kinds of network utilities like Ngrok, Playit, Cyberduck, Filezilla, Dyndns, and more.”

The attack chain involves sharing a link to a password-protected archive of YouTube videos. This will open up and unpack the start.bat batch file, which is responsible for retrieving another archive file via PowerShell.

The batch file uses PowerShell to launch two executables embedded within the newly downloaded archive, while Windows SmartScreen protection and all Drive Rout Folders disable SmartScreen filter exceptions.

Cybersecurity

Of the two binaries, one is a miner of cryptocurrency, and the other is a steeler called VGS, a variant of the femedron steeler malware. As of November 2024, it is known that the attack will replace VGS with Arcane.

“Many of them were borrowed from other stolen items, but they could not be attributed to any of the known families,” the Russian cybersecurity company said.

In addition to stealing login qualifications, passwords, credit card data and cookies from various Chromium and Gecko-based browsers, Arcane is equipped with comprehensive system data and to harvest configuration files, settings, and account information from several apps such as:

VPN clients: OpenVPN, Mullvad, NordVPN, IPVanish, Surfshark, Proton, hidemy.name, PIA, CyberGhost, and ExpressVPN Network clients and utilities: ngrok, Playit, Cyberduck, FileZilla, and DynDNS Messaging apps: ICQ, Tox, Skype, Pidgin, Signal, Element, Discord, Telegram, Jabber, and Viber Email Client: Microsoft Outlook Gaming Clients and Services: Riot Client, Epic, Steam, Ubisoft Cryptographic wallets for Connect (Ex-Uplay), Roblox, Battle.Net, and various Minecraft clients: Zcash, Armory, Bytecoin, Jaxx, Exodus, Ethereum, Electrum, Atomic, Gorda, and Coinomi

YouTube Game Cheats

Additionally, Arcane is designed to take screenshots of infected devices, enumerate the running processes, and list saved Wi-Fi networks and their passwords.

“Most browsers generate unique keys to encrypt sensitive data you store, such as logins, passwords, cookies and more,” says Kaspersky. “Arcane uses the Data Protection API (DPAPI) to get these keys, which is typical of steelers.”

Cybersecurity

“However, Arcane also includes an executable for the Xaitax utility, which we use to crack browser keys. To do this, the utility is dropped to disk, secretly launched, and the steeler gets all the keys it needs from the console output.”

In addition to that functionality, Stealer Malware implements a separate method for extracting cookies from Chromium-based browsers, launching a copy of the browser via the debug port.

The unidentified threat actors behind the operation have since expanded what they offer to include a loader named Arcanaloader, which is intended to download cheats for the game, but which is intended to deliver steeler malware instead. Russia, Belarus and Kazakhstan have emerged as major targets in the campaign.

“What’s interesting about this particular campaign is that it shows how flexible cybercriminals are and constantly updates the tools and how they are distributed,” says Kasperksy. “And the arcane steeler itself is appealing because of all the different data it collects and the tricks it uses to extract the information the attacker wants.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleLagrange has signed a contract with Matter Labs and directs up to 75% outsourced evidence
Next Article Is the US obligated to refugees as Trump calls for systemic change? |Refugee News
user
  • Website

Related Posts

China Link APTS Exploit SAP CVE-2025-31324 581 Critical Systems Around the World

May 13, 2025

Malicious peepy package stealing source code that stole Solana Tools with 761 download

May 13, 2025

Deepfake defense in the age of AI

May 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Trump administration cuts another $450 million with Harvard grants

Florida students have been accused of remaining in jail for massive shootings on campus

Government email alert system Govdelivery is used to send fraud messages

Experience12 and MCM London Comic Con Partners for Returning the Popcultr Marketing Summit

Trending Posts

Albanian dominant socialists secure a majority in parliamentary votes | Election news

May 13, 2025

Real Madrid vs Mallorca: Laliga – Vinicius Jr., Start, Team News, Lineup | Football News

May 13, 2025

Sean “Diddy” Combs Trial: Important takeout from day 1, what are you expecting today? |Sexual Assault News

May 13, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

The confusion of AI startups surges to a $14 billion valuation amid $500 million pay raises.

DoubleUp: A new generation of Gamblefi

Robinhood acquires Wonderfi with $250 million in cash to accelerate Global Crypto expansion

Moonx: BYDFI’s On-Chain Trading Engine – CEX to DEX Ticket

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.