Google said that for two years now it has been preventing phishing attacks on YouTube channel owners that it connects with the audience of Russian-speaking forums.
“Those behind this campaign, which we associate with a group of hackers hired on a Russian-speaking forum, lure the victim with fake joint projects (usually previews of antiviruses, VPN services, players, graphic editors or games), seize control of the channel, and then resell it or used for cryptocurrency scams,” the company writes.
The company writes that it has identified more than a thousand domains created to capture channels. In addition, internal protection has reduced the flow of phishing emails by 99.6% since May of this year (which provoked spammers to leave Gmail for Czech email services). Approximately 4,000 channels have been restored, information about the attacks has been handed over to the FBI.
Google notes that the attackers used a decades-old tactic to intercept cookies. They attribute its revival to the introduction of two-factor authentication account protection: the old tactic, combined with social engineering, sometimes made it possible to bypass it.
The attack began with a letter to the official mail of the channel owner with a proposal for cooperation. If the owner agreed, for example, to advertise an antivirus, he was sent a link to a download page for a malicious program disguised as this product. The deceived victim installed one of the well-known hacking tools on the computer, allowing them to intercept both passwords and cookies. Thus, the attackers gained access to the account and changed its content to cryptoscams.