How hackers are hijacking YouTube accounts to run ads for cryptocurrency scams

Hacker
(Image credit: Caroline Purser/Getty)

Google's Threat Analysis Group has shared details about a long-running phishing campaign targeting YouTubers. The campaign, apparently being carried out by hackers recruited in a Russian-speaking forum, uses "fake collaboration opportunities" to attract YouTubers, then hijacks their channel using a "pass-the-cookie attack," with the goal of either selling it off or using it to broadcast—of course—cryptocurrency scams.

The attacks begin with a phishing email offering a promotional collaboration. Once the deal is agreed, the YouTuber is sent a link to a malware page disguised to look like a download URL. This is where the real action begins: When the target runs the software, it pulls cookies from their PCs and uploads them to "command and control servers" operated by the hackers. 

Having those cookies, as Google explains, "enables access to user accounts with session cookies stored in the browser." This means hackers don't need to worry about stealing the YouTuber's login credentials, because the cookies makes remote sites think they're already logged in.

"Cookie theft" is actually an old digital hijacking technique that's enjoying a resurgence among unscrupulous actors, possibly because of the widespread adoption of security precautions that have made newer hacking techniques more difficult to pull off. Two-factor authentication, for instance, is a common security feature on major websites these days, but is ineffective against cookie theft. (You should still definitely be using it wherever possible, though.)

"Additional security mechanisms like two-factor authentication can present considerable obstacles to attackers," University of Illinois Chicago computer scientist Jason Polakis told Ars Technica. "That renders browser cookies an extremely valuable resource for them, as they can avoid the additional security checks and defenses that are triggered during the login process."

A "large number" of channels hijacked this way are rebranded to impersonate large technology firms or cryptocurrency exchanges, and then begin running streams promising cryptocurrency giveaways in exchange for an up-front payment. Those that are sold off on account-trading markets fetch from $3 to $4000, depending on the number of subscribers they have.

Google said it's reduced the amount of phishing emails related to these attacks by 99.6% since May 2021, and has blocked roughly 1.6 million emails and 2,400 files sent to targets. As a result, attackers are starting to move to non-Gmail providers, "mostly email.cz, seznam.cz, post.cz and aol.com." But the big challenge in cybersecurity, as always, is the human factor. Phishing emails can be remarkably deceptive (I've fallen for at least one myself, and I know about this stuff), and once the wheels start turning on that process it can be very difficult to stop. 

The promise of "something for nothing" has great allure too: The big Twitter hack that occurred in 2020 (which actually began with a "phone spear phishing attack") siphoned more than $100,000 from victims in a single day, simply by promising to double their Bitcoin contributions as a way of "giving back to the community."

Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Read more
A man holding a smartphone with a Youtube logo and small YouTube logos displayed on a screen are seen in L'Aquila, Italy, on October 9th, 2024. (Photo by Lorenzo Di Cola/NurPhoto via Getty Images)
Those YouTube ads everyone hates made $10.4 billion in just three months
One YouTuber has been poisoning AI tools that access her videos with .ass subtitle files and you can too
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
 In this photo illustration a novelty Bitcoin token is photographed on a US Dollar bank note, on January 4, 2025 in Bath, England. The Cryptocurrency market has recently received a significant boost by the election of Donald Trump with hopes of the start of a policy framework that could see Bitcoin as a strategic asset
Man charged with $65,000,000 worth of cryptocurrency heists was reportedly discovered through chatting on Discord with a company they allegedly stole from
Mature professional business man suffering from a headache while working online on computer checking emails alone at work. One male manager feeling overworked, stressed and tired due to a deadline - stock photo
A 2023 study concluded CAPTCHAs are 'a tracking cookie farm for profit masquerading as a security service' that made us spend 819 million hours clicking on traffic lights to generate nearly $1 trillion for Google
Fuzzy children's show character with blue fur but rendered monstrous with void eyes and rows of shark teeth
Creator of horror game Poppy Playtime sues Google for refusing to remove 'bait-and-switch scam' apps that pretend to be the real thing then charge users up to $95 for literally nothing
Latest in Software
A screenshot from game Mudborne of a little humanoid frog in a marsh
Five new Steam games you probably missed (March 24, 2025)
CHINA - 2025/02/11: In this photo illustration, a Roblox logo is seen displayed on the screen of a smartphone. (Photo Illustration by Sheldon Cooper/SOPA Images/LightRocket via Getty Images)
'Humans still surpass machines': Roblox has been using a machine learning voice chat moderation system for a year, but in some cases you just can't beat real people
OpenAI logo displayed on a phone screen and ChatGPT website displayed on a laptop screen are seen in this illustration photo taken in Krakow, Poland on December 5, 2022.
ChatGPT faces legal complaint after a user inputted their own name and found it accused them of made-up crimes
A photo of a monitor displaying the output screen of Razer's AI QA Copilot system
It's not for PC gamers but Razer's new AI QA Copilot could ultimately benefit every PC gamer out there, and it's looking like it could be a killer app that AI needs right now
Public Eye trailer still - dead-eyed police officer sitting for an interview
I'm creeped out by this trailer for a generative AI game about people using an AI-powered app to solve violent crimes in the year 2028 that somehow isn't a cautionary tale
Microsoft Copilot
A rather pleasing Windows 11 update bug automatically uninstalls Copilot and unpins it from the taskbar, which is jolly nice of it
Latest in News
Shadow of Mordor's beloved nemesis system exists because the publisher threw a tantrum about second-hand sales
Silent Hill f transmission trailer screenshots
Silent Hill f is not messing around – now it's been banned in Australia
MOUNTAIN VIEW, CALIFORNIA - AUGUST 22: A view of Google Headquarters in Mountain View, California, United States on August 22, 2024.
'Google must divest the Chrome browser:' DOJ renews call for Google to sell Chrome, and Android could be next
Victory screen of Big Rigs showing infamous "You're Winner" message under a three-handle gold trophy
One of the worst games ever made is coming to Steam, but we won't know how cruel this joke is until we see the price tag
Sci-fi character from Dune
Dune: Awakening promises us a breath of fresh air, skipping early access for a full launch with no monthly subscription in May
Baldur's Gate 3 Karlach concept art
'The dream of the tech industry is to sell off your company at an overinflated price and retire,' says actor behind Baldur's Gate 3's Karlach, 'And I feel that's being done with game studios right now'