{"id":5629,"date":"2025-07-25T10:03:35","date_gmt":"2025-07-25T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/25\/new-malware-attack-leverages-youtube-channels-and-discord-to-harvest-credentials-from-computer\/"},"modified":"2025-07-25T10:03:35","modified_gmt":"2025-07-25T10:03:35","slug":"new-malware-attack-leverages-youtube-channels-and-discord-to-harvest-credentials-from-computer","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/25\/new-malware-attack-leverages-youtube-channels-and-discord-to-harvest-credentials-from-computer\/","title":{"rendered":"New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer"},"content":{"rendered":"<p>    New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A newly uncovered campaign is exploiting gamers\u2019 enthusiasm for off-beat indie titles to plant credential-stealing malware on machines.<\/p>\n<p>Branded installers for nonexistent games such as \u201cBaruda Quest,\u201d \u201cWarstorm Fire,\u201d and \u201cDire Talon\u201d are pushed through slick YouTube trailers and Discord download links that imitate legitimate early-access promotions.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj50IFYpxKQkgKu9BXKeSFCsYyvRD-SBQ6cy7b0eFgSgpDDTK2cEcsvO_8m2ldwB9RQIo_-mlnb47orgujx8fKXYby5ZbWGOgp-vAV_uCpQtiLyCKBtoMYiRrY7l_vGv8dUSte2yfyI1rpjgY3yy2N5R1e0SJZwL9FG7XxtTX0Qgabz3LbLswbKrYUL3mU\/s16000\/Promotional%2520video%2520%28Source%2520-%2520Acronis%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Promotional video (Source \u2013 Acronis)<\/figcaption><\/figure>\n<\/div>\n<p>The lures contain Electron-based executables weighing 80 MB or more, a size that helps them evade casual inspection while bundling the Node.js runtime needed to execute the attack code.<\/p>\n<p>Once the victim clicks the Discord-hosted file, the installer launches a Nullsoft (NSIS) package that quietly extracts an <code>app.asar<\/code> archive holding the stealer\u2019s <a href=\"https:\/\/cybersecuritynews.com\/javascript-attacks-targeting\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> payload.<\/p>\n<p>Acronis analysts <a href=\"https:\/\/www.acronis.com\/en-us\/tru\/posts\/threat-actors-go-gaming-electron-based-stealers-in-disguise\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the operators sometimes forgot to strip the readable source from this archive, giving defenders a rare, unobfuscated view of their tactics and code lineage, which traces back to the Fewer Stealer family.<\/p>\n<p>Inside, researchers identified three active variants\u2014Leet Stealer, its customised fork RMC Stealer, and an apparently independent strain dubbed Sniffer Stealer.<\/p>\n<p>If the malware runs successfully, it can siphon browser passwords, cookies, Discord tokens, crypto-wallet files, and session keys for platforms like Steam and Telegram; victims risk account takeovers, financial loss, and sextortion-style blackmail.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhfDaB7AJNz0AnYqE8l1n5cPpmjewp-ZN4YXILYKtUSu6GMHxp4tYPFpU2a1rN90denYoZe2IeyPivauDgqyWxoYGWULzg0Kh3m3CbyLyEGBBmknQV3ElWg2I_3AfpA5RUW_tOi44ujnDWJ26jwMleWvIsGy-iyogYrbh5PKS9FOyCj-btR1qtVddtPPgk\/s16000\/Fake%2520website%2520-%2520www%255B.%255Dbarudaquest%255B.%255Dcom%2520%28Source%2520-%2520Acronis%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake website \u2013 www[.]barudaquest[.]com (Source \u2013 Acronis)<\/figcaption><\/figure>\n<\/div>\n<p>This shows one spoofed download portal that even reroutes Android and macOS clicks to the legitimate <a href=\"https:\/\/cybersecuritynews.com\/overcoming-social-media-distractions\/\" target=\"_blank\" rel=\"noreferrer noopener\">social game<\/a> Club Cooee while serving Windows users a weaponised <code>.exe<\/code>, illustrating how convincingly the operators blend real and fake assets to widen their reach.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism: Sandbox Detection and Silent Browsers<\/strong><\/h2>\n<p>Every sample first verifies that it is not executing inside a security <a href=\"https:\/\/cybersecuritynews.com\/3-soc-metrics-improved-with-sandbox-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">sandbox<\/a>. Hard-coded blacklists flag Hyper-V, VirtualBox, and low-RAM hosts; matching any item triggers a faux \u201cgame error\u201d dialog and terminates the process, a ploy that lets the malware masquerade as a faulty beta build while frustrating automated analysis.<\/p>\n<p>The critical logic looks like this:-<\/p>\n<pre class=\"wp-block-code\"><code>const blacklistedGPUs = [\n  'VMware SVGA 3D',\n  'VirtualBox Graphics Adapter'\n];\nexec('wmic path win32_VideoController get name', (err, out) =&gt; {\n  if (blacklistedGPUs.some(gpu =&gt; out. Includes(gpu))) {\n    showFakeError(); \/\/ abort on virtual hardware\n  } else {\n    launchStealer();\n  }\n});<\/code><\/pre>\n<p>Passing these checks, the malware spawns the victim\u2019s own Chrome-family browser in headless debug mode, pointing it at <code>https:\/\/mail.google.com<\/code> while exposing a remote-debugging port.<\/p>\n<p>Through that port the script extracts fresh cookies and autofill data directly from live memory, sidestepping disk-level encryption and locked files.<\/p>\n<p>Collected artefacts are zipped and uploaded to <code>gofile.io<\/code>; fallback hosts such as <code>file.io<\/code>, <code>catbox.moe<\/code>, and <code>tmpfiles.org<\/code> ensure exfiltration even if one service is blocked.<\/p>\n<p>A separate thread forwards the resulting download URL to the attacker\u2019s command-and-control server together with harvested <a href=\"https:\/\/cybersecuritynews.com\/discord-malware-attacking-linux-india\/\">Discord<\/a> tokens, providing immediate, full-session access to victims\u2019 chat histories and social graphs.<\/p>\n<p>By fusing polished social-media marketing with technical tricks like VM-aware execution and browser-debug extraction, the campaign demonstrates how modern commodity stealers are maturing into multi-layered threats that can outsmart both users and automated defenses alike.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\">Experience faster, more accurate phishing detection and enhanced protection for your business with real-time sandbox analysis-&gt;\u00a0<strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=article&amp;utm_campaign=freemium-exclusive&amp;utm_content=plans1&amp;utm_term=220725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN now<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-malware-attack-leverages-youtube-channels-and-discord\/\">New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-malware-attack-leverages-youtube-channels-and-discord\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Malware Attack Leverages YouTube Channels and Discord to Harvest Credentials from Computer A newly uncovered campaign is exploiting gamers\u2019 enthusiasm for off-beat indie titles to plant credential-stealing malware on machines. Branded installers for nonexistent games such as \u201cBaruda Quest,\u201d \u201cWarstorm Fire,\u201d and \u201cDire Talon\u201d are pushed through slick YouTube trailers and Discord download links [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5629","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5629"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5629"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5629\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5629"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}