YouTube ads spread banking malware

Graham Cluley

YouTube malwareSecurity researchers at Bromium have discovered that hackers were spreading malware onto computers while unsuspecting users were watching YouTube videos.

The drive-by-download attack was distributed via adverts shown on the YouTube website, and used an exploit kit to infect Windows PCs with a version of the Caphaw banking Trojan.

According to a blog post by Bromium, the attack relied upon the exploitation of a Java vulnerability (CVE-2013-2460, patched by Oracle in mid-2013).

According to the security firm, whose vSentry technology intercepted the attack, the exploit kit used by the hackers was the same one which was recently used to infect visitors to the Hasbro toys website.

Bromium vSentry report

To its credit, Bromium worked with the Google security team over the weekend to resolve the issue on YouTube.

However, it’s quite possible that some users have still had their computers infected by the malware attack, and could be having their banking credentials stolen as a result.

Once again, this incident acts as timely advice to either ensure that your installation of Java is properly updated with the latest security patches or (better) disabled entirely inside your browser.

And, of course, make sure that you have a layered defence in place to reduce the risks of malware attack.

More details of the attack, and the malware which was distributed by YouTube’s ad network, can be found in Bromium’s blog post.

Graham Cluley Graham Cluley is a veteran of the anti-virus industry having worked for a number of security companies since the early 1990s when he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows. Now an independent security analyst, he regularly makes media appearances and is an international public speaker on the topic of computer security, hackers, and online privacy. Follow him on Twitter at @gcluley, or drop him an email.

One Reply to “YouTube ads spread banking malware”

  1. I guess this gave people a reason to use an ad blocker even if they normally don't have one…

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Never miss a thing. Sign up for the free GCHQ newsletter from Graham Cluley.
GET UPDATES