How YouTube channels get Hacked (Fake Ripple, Tesla, etc)

Sdílet
Vložit
  • čas přidán 13. 06. 2024
  • In this video I test a particularly concerning Lumma Stealer variant.
    Official Discord Server - / discord
    Follow me on X - / atericparker
    Disclaimer: The content in this video is for education and entertainment purposes to showcase the dangers of malware & malicious software. I do not encourage any form of illegal hacking, nor do I encourage the usage of game cheats, cracks or hacks.
    Cracks are sometimes shown to highlight the dangers of software piracy, my content is not intended to teach anybody how to pirate, or maliciously hack.
    More Malware Investigation Videos:
    → The latest "NORD" Malware - Nordsecured: • The latest 'NORD' Malw...
    →🧧VIRUS WARNING🧧 NEW Optifine for Minecraft 1.16 SCAM: • 🧧VIRUS WARNING🧧 NEW Op...
    → The wilkreate CZcams stealer virus that started this whole trend: • Fake sponsor DESTROYS ...
    (C) Eric Parker 2024
  • Věda a technologie

Komentáře • 149

  • @EricParker
    @EricParker  Před 11 dny +120

    Since the other video probably wont be back until Monday, here's a bonus.

    • @angelblanco-pc
      @angelblanco-pc Před 11 dny +2

      pc

    • @goongleton
      @goongleton Před 11 dny +1

      oh bloody hell. i could have watched it but decided to put it off. its all on me

    • @Evan37645
      @Evan37645 Před 11 dny +2

      I was watching the setup one then I watched something else came back and it was gone lol

    • @UsuallyLime
      @UsuallyLime Před 11 dny

      Nice. Hoping to see the other one too cause of the claim at the beginning that it's the wildest malware ever reviewed on this channel. Just wondering what it did.

    • @maxtech66999
      @maxtech66999 Před 11 dny

      Great bonus. Thanks !

  • @elisa_5445
    @elisa_5445 Před 11 dny +492

    They sent a malware to a channel that analyses malwares, genious idea

    • @redlionstudio2750
      @redlionstudio2750 Před 11 dny +23

      yeah, that just shows how dumb scammers are XD
      but maybe this malware was redirected by a viewer?

    • @bombus_
      @bombus_ Před 11 dny +4

      yeah but what an own it'd be on the off chance they actually manage to infect the owner of a channel that analyses malware!

    • @RaveDecoy242
      @RaveDecoy242 Před 11 dny

      ​@@redlionstudio2750
      Scammers aren't dumb - but they always go for the dumbest targets.
      Remember those Nigerian Prince emails with terrible english? Those who respond to them prove that they have no knowledge about the scam or are dumb enough to believe anything, so those same people don't know that they're about to be scammed.
      That means those kinds of people won't report the scam, which will allow it to keep going for longer. Nigerian Prince scams have been estimated to have stolen more than a hundred million dollars over the past few decades, which means they've filtered their targets enough to keep milking them to this day.
      The only dumb people here are those who think that scammers are dumb. Always be on your toes.

    • @TheDZHEX
      @TheDZHEX Před 11 dny +12

      When the ruble is in rubble, they can get pretty desperate I guess lol

    • @CZghost
      @CZghost Před 11 dny +5

      Yeah. And of course send it to someone who knows how to bypass Cloudflare's proxy, and therefore knows how to get to the real C2 server's IP address, and the best thing that person does is to send that IP address to their friends to have a little fun :D

  • @samudotlol
    @samudotlol Před 11 dny +165

    getting linus tech tips flashbacks

  • @Minty_Meeo
    @Minty_Meeo Před 11 dny +243

    Ah yes, the classic "hide extensions of known file types" attack. Microsoft is the worst for inventing that "feature".

    • @EricParker
      @EricParker  Před 11 dny +47

      I guess technically it's probably smarter not to put the fake pdf if people are not accustomed to seeing file extensions.

    • @kevkevpurple
      @kevkevpurple Před 11 dny +39

      My thoughts exactly. File extensions should be enabled by default, they’re not hurting anyone.

    • @CZghost
      @CZghost Před 11 dny +21

      Microsoft did it in an attempt to prevent people from accidentally changing the file type by renaming the extension (which by design is fairly wrong in so many occasions, because file type should NOT be determined solely by its extension). Renaming a file to a different extension might cause it to break compatibility, so Microsoft by default hides extensions to prevent dumb users to rename program files for example (causing them to no longer work).
      It is dumb, not gonna lie. First of all, Microsoft assuming users are dumb they don't understand extensions, that's insulting. Second of all, it's a bad design. Unix-like OS doesn't determine the file type by its extension, rather does it through file header. If that file header might correspond to many file formats (example being text files, which do not actually have a header), then the file format might be determined by the file name extension (for example: C source code files). If Windows adopted this behaviour from Unix, then it would be so nice, and there would not be many issues with renaming a file extension. Fun fact: In Unix-like OS, the file doesn't even need an extension, it can be simply just "file" with no extension, and it will still function according to its file type that's associated with the header inside. As an example, many log files might be extension-less, C++ source code header files are sometimes files without an extension (remember writing "#include " in your C++ program? That file has no extension), and some programs (including Windows Copilot and Recall) have extensions from their log files removed (which on Windows it's more of a measure to prevent users from poking around and looking for stuff they're not supposed to be poking around).
      Also, Windows is fully capable of opening extensionless files. Of course, you won't be able to assign a permanent application to open them, but you can still open the file by manually selecting the editor that is designed to open that file (if you know the format of the file). Not only that, Windows Command Line is capable of dumping extensionless text files into the console, the same goes for Windows Powershell (or Powershell for those who installed the latest version), and of course Command Line and Powershell don't hide the file extensions even if that is enabled in Windows.

    • @atsizbalik
      @atsizbalik Před 11 dny +4

      @@kevkevpurple the little timmy would get scared after seeing the .exe file format

    • @lritzdorf
      @lritzdorf Před 10 dny +12

      ​@@CZghostExcellent point about protecting users from themselves - you just know someone's going to rename a JPEG to PNG and expect it to work.
      On the other hand, even with file extensions shown, you get a warning popup if you attempt to edit the extension - which is all that should really be needed, Microsoft!

  • @toxicisgaming
    @toxicisgaming Před 11 dny +56

    ah yes. sending a malicious file to a youtuber who investigates malware. very smart.

  • @POLARTTYRTM
    @POLARTTYRTM Před 11 dny +88

    I keep asking WHO is behind this Tesla scam, because it is so widespread it CANNOT be a single person, it has to be an enormous group trying to do something that has nothing really to do with crypto. One of the things people used to do a long time ago, and still do, is taking channels with a noticeable following and selling them for a fairly good amount of money, same goes for game accounts.

    • @user-in2cs1vp6o
      @user-in2cs1vp6o Před 11 dny +25

      It's going to be the same scam run by different people. Best you can do is keep track of crypto wallets and the transactions they make

    • @EricParker
      @EricParker  Před 11 dny +22

      Many different groups.

    • @POLARTTYRTM
      @POLARTTYRTM Před 11 dny

      @@user-in2cs1vp6o probably. There are also known market places where you can buy youtube channels, they go up in value a lot depending on what you are looking for, for example channel age, number of subscribers, monetization, etc. Game accounts because of in-game valuable items, account age, no restrictions in place, hours played, rank. Many variables.

    • @zchen27
      @zchen27 Před 9 dny

      I wouldn't be surprised if the entire thing is sold as a Malware As A Service package. The stealer, the C2 servers, the crypto filler content when they do get access.

    • @user-lu4me4dw4s
      @user-lu4me4dw4s Před 9 dny

      Lots and lots of groups from CIS. You can check out some Russian formus like Lolzteam, many of them do this collectively. But Lumma is kinda expensive, so there could be a more profession team.

  • @guilhemedemassenaladario
    @guilhemedemassenaladario Před 11 dny +21

    The malware appears to be sending compressed files with your browser DB to steal your logged sessions. If you look at the packages sniffed in the proxy, they send multipart form data with a file attached. The files have a PK header, which could be a ZIP file. Have you tried to take a look at it? Would be cool if we can see what exactly they are scrapping from victim PCs

  • @lkn900l
    @lkn900l Před 11 dny +18

    Funny thing that, if you copy Firefox appdata file with passwords and logins, and then paste it to another PC with fresh Firefox, it will have all the passes from copied one. I guess this virus uses this vulnerability.

  • @TheRealScottMusic
    @TheRealScottMusic Před 11 dny +18

    Eric you are criminally underrated you make some great cyber security content which I constantly find myself coming back to

  • @sfisher923
    @sfisher923 Před 11 dny +12

    Acai's OBS Plugin Incident was a different approach that ended up with the same
    So anyone watching his streams on Twitch this is why chat has to remind him to not download any executables past 9pm his time (US Eastern)

    • @marqueemoon3220
      @marqueemoon3220 Před 9 dny

      I tried searching for it on YT and google and can’t find it, do you have a link for it?

  • @l8wt5
    @l8wt5 Před 11 dny +6

    Would be interesting to see if Smart App Control in Windows 11 can protect against these stealers. It should only allow "known reputable apps" to run, but I haven't seen anyone test that yet. It does have some false positives, but in an environment where security really matters, it might be a good idea to enable it if it does block these threats.

  • @lyndon2274
    @lyndon2274 Před 11 dny +13

    can you do a video on Valorant's anticheat software vanguard?

  • @opposite342
    @opposite342 Před 11 dny +5

    7:59 correct me if I'm wrong but MingW is a c compiler for windows. I think it uses gcc which is why it shows gnu here.

  • @baribari1000
    @baribari1000 Před 11 dny +1

    hope you're near Las Vegas! going to def con sure sounds like a lot of fun

  • @kavylavx
    @kavylavx Před 11 dny +12

    hell- classic.
    also funfact no one watched the full vid yet.
    glad i dont do sponsorships.
    edit: woah i was 1st (actually before eric)

  • @kiendra
    @kiendra Před 11 dny +5

    Canadian endermanch

  • @devilcookie9924
    @devilcookie9924 Před 11 dny +11

    hi, Eric. what happened to the activator video? did you delete it or YT did?

    • @EricParker
      @EricParker  Před 11 dny +14

      Taken down by CZcams, I appealed.

    • @devilcookie9924
      @devilcookie9924 Před 11 dny +4

      @@EricParker it seems YT has keyword filters for the subject of video. thanks for reply!

    • @EricParker
      @EricParker  Před 11 dny +17

      Yeah, since covid they started allowing AI to take down videos without review, sometimes it gets it wrong. On balance it is a good thing.

    • @gozuken8985
      @gozuken8985 Před 10 dny

      @@EricParker are you going that upload that video again? CZcams or on another platform?

  • @YumiizArts
    @YumiizArts Před 11 dny +9

    This actually happened to me. Got a sponsorship from Stray (the game). Turned out to be a fake PDF. I ended up contacting CZcams via Twitter..
    The hacker hacked my entire gmail account and locked me out entirely haha. Thankfully, CZcams did help me get my CZcams and gmail account back. Safe to say I invested in safety precautions and a key.

  • @washere3432
    @washere3432 Před 11 dny

    Love the recent videos!!! Keep it Upppp!!!

  • @hoonzotales5752
    @hoonzotales5752 Před 11 dny +4

    You should have responded that the download didn't work and that you would like a new link to see what else they would send you.

  • @JoCaTen
    @JoCaTen Před 3 dny

    Awareness of these things must be brought.
    We must raise awareness, we can't just keep loosing our channels just like that.

  • @efg786
    @efg786 Před 10 dny

    sorry if you’ve been asked this before, but what is the software you use to monitor network traffic? i’m interested in downloading it, i thought it might be glass wire because that’s the only application i’ve heard that does something like this but im not sure

    • @EricParker
      @EricParker  Před 7 dny +1

      mitmproxy.
      The setup I use is a wireguard VPN outside the VM. It can either be a second VM or the host (don't do if the host is windows).

  • @isaackingvideos
    @isaackingvideos Před 10 dny +1

    Because of this. I will never login to my account to my computer again until Microsoft fixes this problem

  • @eggs4561
    @eggs4561 Před 11 dny

    Was looking for a video like this after Nexus got hacked.

  • @AdrX003
    @AdrX003 Před 11 dny

    Sadly ive seen two channels that i had set the bell on with this happening to them. got a vid notification that i clearly had not subscribed before

  • @WeencieRants
    @WeencieRants Před 11 dny +1

    Another great video

  • @tribes2archivist
    @tribes2archivist Před 8 dny +1

    Controlled folder access says "unauthorised changes" in the description, so it defends against suspicious, high entropy writes that you would see when a file is encrypted for ransomware, nothing else.

  • @JoshuaPeisach
    @JoshuaPeisach Před 11 dny

    Man I need to look at those obvious spam emails in VMs now

  • @maxniftynine
    @maxniftynine Před 11 dny +2

    Do a video on the new windows WiFi vulnerability

  • @teamruddy611
    @teamruddy611 Před 11 dny +2

    Did you report the website the data was sent to as malicous, so it could be taken down?

    • @xXball_smasherXx
      @xXball_smasherXx Před 11 dny

      you're right, one could notify cloudflare for abuse and boom, cloudflare protection gone from the site

  • @CopyrightedCup
    @CopyrightedCup Před 7 dny +2

    Why don't anti-virus software auto flag reading of cookies in browsers? I can only think of one scenario where it could be useful and that would be installing a new browser and moving all your data over. Or if anything detect the behavior of copying and sending of the cookies file over the internet. I can't think of a use for it not being flagged.

  • @skzulka
    @skzulka Před 2 dny

    you are so clever! great works man

  • @vladik_yt3186
    @vladik_yt3186 Před 11 dny +2

    When hackers sent malware to PC Security Channel i laughed, now i question their IQ level

    • @chri-k
      @chri-k Před 11 dny +4

      It's likely automatic

    • @vladik_yt3186
      @vladik_yt3186 Před 11 dny +2

      @@chri-k Ye but still pretty funny
      Btw on which ending did you finished oneshot? Besides Solstice

    • @chri-k
      @chri-k Před 11 dny +4

      @@vladik_yt3186 I don't even remember anymore due to seeing so many let's plays of it. I think it broke the sun?

    • @vladik_yt3186
      @vladik_yt3186 Před 11 dny +1

      @@chri-k Good boi

  • @edyroc
    @edyroc Před 11 dny

    props to you for doing these daily uploads you saw the algorithm was in your favor and you took action and now you’re on your way to become a full time tuber GZ

  • @tomatobrush3283
    @tomatobrush3283 Před 11 dny +2

    At 70 mb that is a RAT for sure.

  • @greatvegetables
    @greatvegetables Před dnem

    One of my favorite things about these videos is how in most of his Windows VMs he sets the username to Lain

  • @thesketchboysgaming7752

    Actually 2 of the biggest gaming channels in sweden got hacked exactly like this today with tesla lives running on the channels.

  • @user-dw6fj1py1o
    @user-dw6fj1py1o Před 2 dny

    Good Work!

  • @georgitzu3150
    @georgitzu3150 Před 11 dny +1

    7:45 I’ve found that sometimes VirusTotal won’t detect malware at all in a file (Kaspersky, Malwarebytes, etc) but upon scanning it on my own system it finds malware, does anyone know why this is the case? I’ve also had a case where a scan didn’t detect any issues (Malwarebytes) but a day later a file I had on my pc for a long time that I created got flagged.

    • @PaLaS0
      @PaLaS0 Před 11 dny

      many possible reasons like versions or timing or sigs but did you actually only scan it or also run it? I would like such sample if you are able to scan it with both at same time and both of them showing different results.

    • @georgitzu3150
      @georgitzu3150 Před 10 dny

      @@PaLaS0 I believe it was only scan. It has happened very few times but I do remember distinctly the different results. I’m not too familiar with how virus scanners work but I thought maybe it saw a potential vulnerability with how the file would interact with other files on my computer specifically in comparison to the sandbox in virustotal but I’ve got no idea.

  • @DamageXYZ39
    @DamageXYZ39 Před 9 dny

    That fucking restart at 10:33 scared the shit out of me. I thought I restarted my own pc

  • @tee_the_vee
    @tee_the_vee Před 11 dny +1

    not the polish email adress

  • @TheMeowthTeamV2
    @TheMeowthTeamV2 Před 11 dny +4

    I remember watching a video from 2009 called shreks crap or something it wasn't an sml video but it was funny but unfortunately it was deleted along with the channel and I never could watch the video again so all i have now is the memory of it

  • @kevin.7z
    @kevin.7z Před 11 dny +7

    Day 1 of asking Eric to collab with The PC Security Channel because they sound like the same person

    • @electrolyteorb
      @electrolyteorb Před 11 dny

      TPSC sounds more "bright"

    • @kevin.7z
      @kevin.7z Před 11 dny

      @@electrolyteorb and eric sounds like tpsc with a voice changer

  • @DonaldDucksRevenge
    @DonaldDucksRevenge Před 10 dny

    Miss your Activation exploit vid too bad YT censored

  • @xxxxxx3q
    @xxxxxx3q Před 7 dny

    2:48 lain mentioned

  • @gyroninjamodder
    @gyroninjamodder Před 11 dny

    8:43 PK header is a zip file

  • @NullPointer
    @NullPointer Před 4 dny

    8:14 zip files always start with PK, so those are all non encrypted zip files

  • @GatsuTheBranded
    @GatsuTheBranded Před 11 dny

    This definitely happend to quelaag

  • @frstwhsprs
    @frstwhsprs Před 9 dny

    The hacker who wanted to hijack Eric Parker's channel to promote Tesla bullshit: "GOD DAMMIT, WHERE IS HIS CHANNEL"

  • @lockout5731
    @lockout5731 Před 11 dny +1

    Above time this legand is talking about this Elon musk Tesla live stream scam about damn time

  • @Electro-tw9um
    @Electro-tw9um Před 6 dny

    The zip file should have the MOTW. Why doesn't it? If it did, SmartScreen would block the unknown executable.

  • @tubgold
    @tubgold Před 11 dny

    smart..

  • @henrygoldberg1248
    @henrygoldberg1248 Před 11 dny

    I like your user name for your file

  • @blackbonnieiscool
    @blackbonnieiscool Před 2 dny

    They sent Mr. antivirus a malware and thought they will go unnoticed, *amatures*

  • @artman40
    @artman40 Před 9 dny

    How WHAT happens to my favorite CZcams Channels?

  • @BlueIsLeet
    @BlueIsLeet Před 11 dny

    "PK" prefix means its a zip file

  • @MrReeTart
    @MrReeTart Před 2 dny

    Tristan Tate but computer science

    • @ayefare
      @ayefare Před 2 hodinami

      That's exactly what I was thinking. Sounds so much like him.

  • @BlueIsLeet
    @BlueIsLeet Před 11 dny

    dont pull a LTT and have it happen to you now lol

  • @angelblanco-pc
    @angelblanco-pc Před 11 dny +1

    bro

  • @corewwwi
    @corewwwi Před 11 dny

    lain

  • @nicememes0676
    @nicememes0676 Před 11 dny

    Hello

  • @PABLOPeanutman
    @PABLOPeanutman Před 11 dny

    Hi eric

  • @Kimarnic
    @Kimarnic Před 11 dny +2

    Of course Russian 🙄

  • @MysLouis
    @MysLouis Před 11 dny

    classical scam now 😂

  • @RandomytchannelGD
    @RandomytchannelGD Před 11 dny

    hi

  • @Ratiqon
    @Ratiqon Před 11 dny +4

    Oh eric my love i will die for you my lebron my pookie❤

  • @freenull
    @freenull Před 11 dny +3

    Is Lumma sold with domains, too? Because this .shop domain is the same pattern as the one from your "Tracking Malicious "Tutorials" on CZcams" video, and the API is the same. Was thinking it may be the same actors, but I guess it might also be a full package you get from them?

    • @EricParker
      @EricParker  Před 11 dny +1

      API and the software is the same, AFAIK you set it up on your own domain / server.
      Most stealer sites look roughly the same, many will also feature a special useragent to make DoS'ing it a bit trickier.

  • @vladwolfaction.
    @vladwolfaction. Před 2 dny +1

    As russian i can say, we love Elon Musk. Thx for scam scheme.

  • @ardwetha
    @ardwetha Před 11 dny +3

    If they got Linus tech tips like this, they should stop making videos asap.

    • @EricParker
      @EricParker  Před 11 dny +11

      It's actually easier (in general) to hack enterprises than random people. If you want to hack my channel you have to hack me, if you want to hack linus, there are 100 employees of varying levels of tech saviness that could be compromised.

    • @Kimarnic
      @Kimarnic Před 11 dny +3

      ​@@EricParkerthis, they probably have editors that don't know about PCs but are great at editing videos

  • @edwin3928ohd
    @edwin3928ohd Před 5 dny

    Ween

  • @LightingMcqueen636
    @LightingMcqueen636 Před 11 dny

    50th

  • @Stratxgy.
    @Stratxgy. Před 8 dny

    i love when elon gives free crypto!!!!!!!!11

  • @AlphaOmegaSigma
    @AlphaOmegaSigma Před 11 dny +3

    bro just tried to base64 decode an encyrypted payload lmao

    • @丷
      @丷 Před 11 dny

      thats about as far as his malware analysis abilities go lol

    • @testtest-ez3mp
      @testtest-ez3mp Před 11 dny +1

      Yes, I cringe every time when I see that lol​@@丷

    • @chri-k
      @chri-k Před 11 dny +1

      where's the issue with that?

    • @AlphaOmegaSigma
      @AlphaOmegaSigma Před 11 dny

      @@chri-k you can tell just by looking at it that it's nowhere near base64. rookie mistake.

    • @chri-k
      @chri-k Před 11 dny +1

      @@AlphaOmegaSigma It looks exactly like base64. In fact, there is a 99% chance that it is base64.

  • @IlIlIIlIlIlIlIlIl
    @IlIlIIlIlIlIlIlIl Před 11 dny +1

    Drop your xmr address for defcon ticket

    • @EricParker
      @EricParker  Před 8 dny +1

      Appreciated
      84zByvq2sPRWBNmbu7NfcFP5LYzR3fyU9CAPUnfs8au6BwNf4f2cqweFKqoaSXw7Ga4BYHgzbJNRqfbTfrYvtigHJYZsA59

  • @asbfabfoaijfo8
    @asbfabfoaijfo8 Před 8 dny

    lain