YTStealer
- First seen
- 2022-02-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-14 17:25:04
- Profile updated
- 2026-07-07 14:43:03
Targeted industries: media-and-entertainment
Context
According to Intezer, YTStealer is a malware whose objective is to steal YouTube authentication cookies. As a stealer, it operates like many other stealers. The first thing it does when it’s executed is to perform some environment checks. This is to detect if the malware is being analyzed in a sandbox.
Reports & references
- blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ytstealer (report)
- intezer.com — Ytstealer Malware Youtube Cookies (report)