Nasty new YouTube scam could land you in hot water

MacBook Pro open on a desk with YouTube logo on the screen
(Image credit: Alexey Boldin / Shutterstock.com)

A nasty new malware campaign has been identified, abusing Google’s advertising system to lay the foundations for all manner of cyberattacks.

Earlier this week, cybersecurity researchers from Malwarebytes discovered that unknown threat actors had bought an ad that is displayed on top of Google’s search engine results pages whenever someone types the keyword “YouTube”, or other relevant keywords.

The particularly nasty part is that it is impossible to distinguish the fake ad from a legitimate example. It features a genuine link (youtube.com) and comes with all of the usual advertising elements. In other words, even the most careful among us could be forgiven for falling for the scam.

Questionable activity

The red flags appear only after the link has been clicked. Instead of redirecting the victim to YouTube, the link leads them to a fake Windows Defender site, with a popup saying the computer is infected with a trojan. The pop-up states that the victim should call Windows Defender tech support immediately, or face a “complete malfunction” of their endpoint.

BleepingComputer called the number provided on the screen, and was connected to an overseas call center where a “support technician” asked them to download and run remote desktop software TeamViewer. The publication did not pursue the scam further, as it’s safe to assume that the fraudsters would use access to the computer to install some type of ransomware or similar device-locking malware. 

In all likelihood, they would then proceed to demand payment for a “premium service” or something else, in exchange for getting their device back. 

While we were unable to independently verify if the campaign is still active, Malwarebytes’ latest tweet would suggest it is. 

The easiest way to avoid the scam, it was said, is to have a VPN service running. The fake site will scan the device for any VPNs, and if it finds one, will redirect the device to the legitimate YouTube site.

Via BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A padlock resting on a keyboard.
Understanding and avoiding malvertizing attacks
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Mac users targeted with new malware, so be on your guard
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras