Users on YouTube upload thousands of new videos every day, including entertainment, teaching, documentary and other content. You may not watch TV channels, but you will watch more or less videos on YouTube. Many videos on YouTube are produced with AI, but there are also many unscrupulous people who are taking advantage of AI and secretly placing malware download links on the platform. Don’t be greedy for petty gains.

Hackers are abusing AI on YouTube to spread dangerous malware, research firm finds
As AI becomes popular across multiple platforms, instances of profiting from it in malicious ways are also increasing. research company CloudSEK It was observed that since November 2022, the number of YouTube video descriptions with links to popular malware sources such as Vidar, RedLine, and Raccoon has increased by 200 to 300%. These videos usually attract users to click on the tutorial on how to obtain software cracking that requires a paid license key, such as Photoshop, Premiere Pro, Autodesk 3ds Max, AutoCAD and other products.

Typically these videos use screen recordings or audio to guide viewers through the steps of downloading and installing software, but there has been an increase in the number of these videos being generated with AI such as Synthesia and D-ID. It is known that films with human protagonists, especially those with certain facial features, make people lower their guard and increase trust, so recently there has been an increase in films featuring AI-generated characters across languages and platforms (Twitter, Youtube, Instagram), mainly for recruitment, education and training, and promotional marketing. This tactic is now also used by malicious actors.

In the description field, unscrupulous people will place confusing and malicious links to guide you to click and download malware information-stealing programs. After installation, it can access various private data of users, including passwords, credit card information, bank account numbers, etc., and then upload this data to the hacker’s command and control server. Other items that may be stolen include browser data, cryptocurrency data, Telegram conversation content, program files (such as .txt), and system information (such as IP addresses).

CloudSEK pointed out that this bad growth emerged with the AI revolution in November 2022, and it was not noticed by the media until early February 2023 because hackers used ChatGPT to generate malware code. Hackers who steal personal data also work with other threat actors (often called Traffers) and recruit partners to find and share information about potential victims through black markets, forums, and Telegram channels. Traffers are typically people who provide fake websites, phishing emails, YouTube tutorials, or social media posts to which information-stealing developers can attach their malware.

However, on YouTube, they are hacking accounts and uploading multiple videos at once to get the attention of viewers who care about the original author. Unscrupulous individuals will hack and take over popular accounts and accounts that are not updated frequently for different purposes. Just take over an account with over 100,000 subscribers and upload five or six videos with malware, and you’re bound to get a few clicks before the owner regains control of the account. Viewers may identify the video as malicious and report it to YouTube, which will eventually remove it. Accounts that are not updated frequently may have already been exploited, and the channel owner may not know about it for some time. In addition, these hackers will also add fake comments and shortened URLs such as bit.ly and cutt.ly links to make the download address containing the virus look more attractive.
Source: KOCPC Chinese