YouTube ads spread banking malware


YouTube malwareSecurity researchers at Bromium have discovered that hackers were spreading malware onto computers while unsuspecting users were watching YouTube videos.

The drive-by-download attack was distributed via adverts shown on the YouTube website, and used an exploit kit to infect Windows PCs with a version of the Caphaw banking Trojan.

According to a blog post by Bromium, the attack relied upon the exploitation of a Java vulnerability (CVE-2013-2460, patched by Oracle in mid-2013).

According to the security firm, whose vSentry technology intercepted the attack, the exploit kit used by the hackers was the same one which was recently used to infect visitors to the Hasbro toys website.

Bromium vSentry report

To its credit, Bromium worked with the Google security team over the weekend to resolve the issue on YouTube.

However, it’s quite possible that some users have still had their computers infected by the malware attack, and could be having their banking credentials stolen as a result.

Once again, this incident acts as timely advice to either ensure that your installation of Java is properly updated with the latest security patches or (better) disabled entirely inside your browser.

And, of course, make sure that you have a layered defence in place to reduce the risks of malware attack.

More details of the attack, and the malware which was distributed by YouTube’s ad network, can be found in Bromium’s blog post.

Tags: , , , , , , , , ,

Share this article:

   Join thousands of others and sign up to our free "GCHQ" newsletter.

Smashing Security podcast
Check out "Smashing Security", the award-winning weekly audio podcast, with Graham Cluley, Carole Theriault, and special guests from the world of information security.

"It's brilliant!" • "Three people having fun in an industry often focused on bad news" • Winner of the Best Security Podcast 2018

Latest episodes:
Listen on Apple Podcasts Listen on Google Podcasts

, , , , , , , , ,

One Response

  1. Xane M.

    March 13, 2015 at 8:13 pm #

    I guess this gave people a reason to use an ad blocker even if they normally don’t have one…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.