Beware: Russian YouTube Gaming Cheats Conceal Powerful Arcane Stealer Malware


# New Stealer Malware “Arcane” Targets Gamers Through YouTube Cheat Videos

A sophisticated malware campaign is using YouTube videos promoting game cheats to distribute a previously undocumented stealer called “Arcane,” primarily targeting Russian-speaking users.

“What’s intriguing about this malware is how much it collects,” reports Kaspersky. “It grabs account information from VPN and gaming clients, and all kinds of network utilities like ngrok, Playit, Cyberduck, FileZilla, and DynDNS.”

## Attack Methodology

The infection chain begins when users click links to password-protected archives shared in YouTube videos. Once opened, these archives unpack a batch file that retrieves additional malicious content via PowerShell. The process disables Windows SmartScreen protections and adds exceptions to enhance the attack’s success.

Initially, the campaign deployed two executables: a cryptocurrency miner and a stealer variant called VGS (related to Phemedrone Stealer). By November 2024, VGS was replaced with the more advanced Arcane malware.

## Comprehensive Data Theft

Arcane’s capabilities are extensive, targeting:

– Browser data: Credentials, passwords, credit card information, and cookies from Chromium and Gecko-based browsers
– VPN clients: OpenVPN, Mullvad, NordVPN, Surfshark, Proton, and others
– Network tools: ngrok, Playit, Cyberduck, FileZilla, DynDNS
– Messaging apps: Discord, Telegram, Signal, Skype, ICQ, and more
– Email clients: Microsoft Outlook
– Gaming platforms: Steam, Epic, Riot Client, Ubisoft Connect, Roblox, Battle.net, Minecraft
– Cryptocurrency wallets: Exodus, Ethereum, Electrum, Atomic, and others

The malware also captures screenshots, lists running processes, and extracts Wi-Fi network credentials.

## Advanced Techniques

Arcane employs sophisticated methods to extract sensitive data:
– Uses Data Protection API (DPAPI) to obtain browser encryption keys
– Deploys the Xaitax utility to crack browser keys
– Implements a specialized method for extracting cookies from Chromium browsers through debug ports

The threat actors have expanded their operation with “ArcanaLoader,” which masquerades as a game cheat downloader but delivers the stealer instead. Russia, Belarus, and Kazakhstan are the primary targets.

“This campaign illustrates how flexible cybercriminals are, always updating their tools and distribution methods,” Kaspersky concluded.

Share This Article