Security researchers at Bromium have discovered that hackers were spreading malware onto computers while unsuspecting users were watching YouTube videos.
The drive-by-download attack was distributed via adverts shown on the YouTube website, and used an exploit kit to infect Windows PCs with a version of the Caphaw banking Trojan.
According to a blog post by Bromium, the attack relied upon the exploitation of a Java vulnerability (CVE-2013-2460, patched by Oracle in mid-2013).
According to the security firm, whose vSentry technology intercepted the attack, the exploit kit used by the hackers was the same one which was recently used to infect visitors to the Hasbro toys website.
To its credit, Bromium worked with the Google security team over the weekend to resolve the issue on YouTube.
However, it’s quite possible that some users have still had their computers infected by the malware attack, and could be having their banking credentials stolen as a result.
Once again, this incident acts as timely advice to either ensure that your installation of Java is properly updated with the latest security patches or (better) disabled entirely inside your browser.
And, of course, make sure that you have a layered defence in place to reduce the risks of malware attack.
More details of the attack, and the malware which was distributed by YouTube’s ad network, can be found in Bromium’s blog post.
Found this article interesting? Follow Graham Cluley on Twitter or Mastodon to read more of the exclusive content we post.
One comment on “YouTube ads spread banking malware”
I guess this gave people a reason to use an ad blocker even if they normally don't have one…