Logo
Cardano Ecosystem

Cryptocoin

11/21/2021

·

945 views


Crypto Scams: Hackers Are Targeting YouTube Channels

Google’s Thread Analysis Group has shed light on the methods of hackers who hijack YouTube channels and use them for cryptocurrency scams. Cookie theft is still a common account hijacking technique adopted by criminal groups. Have been tracking &...

Crypto Scams: Hackers Are Targeting YouTube Channels

.

Google’s Thread Analysis Group has shed light on the methods of hackers who hijack YouTube channels and use them for cryptocurrency scams.

Cookie theft is still a common account hijacking technique adopted by criminal groups. Have been tracking & disrupting this group with multiple security teams since I joined Google. Happy to share our results and finding in this blog. https://t.co/V9kfSe00g9

— Ashley Shen (@ashl3y_shen) October 20, 2021

Around 4,000 YouTube channels hacked over the past months

In a blog article published last week, a member of Google’s Thread Analysis Group, Ashley Shen, describes how hackers capture YouTube channels and sell them on account trading websites. According to her, hacked channels change hands for up to 4,000 USD, depending on the number of subscribers.

Very often, the accounts are rebranded and used for cryptocurrency scams. In March 2021, Cryptocoin.News spoke with Kevin Luge, the owner of one of the largest meme-compilation channels on YouTube, who fell victim to a hijacking attack. 

By his account, he received an email from someone claiming to be a representative for the mobile game Raid Shadow Legends offering a sponsorship deal, and was lured into opening a file attached to the mail. Few hours afterwards, his YouTube channel H-Matter was renamed and rebranded to resemble an official live-streaming channel of Cardano (ADA).

These seemingly official channels are in turn supposed to lure viewers into sending cryptocurrency to the scammers address, under the promise of a higher return. Shen’s report shows that this is a common occurrence, as Google has restored around 4,000 accounts and returned them to their rightful owners. 

Hackers shift to Social Engineering

The report also comments on how account stealing activities shift due to the countermeasures taken to prevent hacks. As Gmail uses tight filters against spam and phishing mails, attackers are increasingly using other email providers.

Furthermore, Shen reports that phishing emails become more personalized, often targeting a specific YouTube channel, instead of sending mass fishing emails. This method is also known as spearphishing. Oftentimes, the attackers impersonate an existing company and ask for a video advertisement collaboration.

Shen’s article also explains that Russian forums are involved in recruiting hackers to social engineer YouTubers and steal their accounts. 

Example of job descriptions for hack-for-hire attackers. Source: Google.

Due to the increasing usage of Multi-Factor-Authentication, hackers have developed a new type of attack for hacking logged-in accounts. The “pass-the-cookie” attack steals the user’s cookie from a logged-in session and sends it to the attacker, allowing the attacker to gain temporary account access. 

Up to 3 million leaked email addresses linked to CoinMarketCap 

Most recently, the cryptocurrency price information website CoinMarketCap may have been hacked as well. A total of 3.1 million email addresses were leaked on hacker forums. 

CoinMarketCap has confirmed that the email addresses correlate with their user base, but states that no passwords were leaked. Moreover, CoinMarketCap claims to have no evidence of a server-leak on their behalf, speculating that the email addresses come from a third-party source. 

AD

Delegate Your Voting Power to FEED DRep in Cardano Governance.

DRep ID: drep12ukt4ctzmtf6l5rj76cddgf3dvuy0lfz7uky08jfvgr9ugaapz4 | We are driven to register as a DRep by our deep dedication to the Cardano ecosystem and our aspiration to take an active role in its development, ensuring that its progress stays true to the principles of decentralization, security, and community empowerment.DELEGATE VOTING POWER!


Read Original Article on Cryptocoin

ORIGINAL SOURCE

https://cryptocoin.news/news/crypto-scam...

Disclaimer: Cardano Feed is a Decentralized News Aggregator that enables journalists, influencers, editors, publishers, websites and community members to share news about the Cardano Ecosystem. User must always do their own research and none of those articles are financial advices. The content is for informational purposes only and does not necessarily reflect our opinion.


An image that says Learn Blockchain technology and get ahead in the industry with a link to the Cardano Academy.

More from Cryptocoin

See more
Mesmo após atualização preço do Cardano não se abalou
Cryptocoin
Mesmo após atualização preço do Cardano não se abalou

09/23/2022

·

460 views

Related News

See more

Featured News

See more



    DEFAULTENGLISH (EN)SPANISH (ES)RUSSIAN (RU)GERMAN (DE)ITALIAN (IT)POLISH (PL)HUNGARIAN (HU)JAPANESE (JA)THAI (TH)ARABIC (AR)VIETNAMESE (VI)PERSIAN (FA)GREEK (EL)INDONESIAN (ID)ROMANIAN (RO)KOREAN (KO)FRENCH (FR)CZECH (CS)PORTUGUESE (PT)TURKISH (TR)