YTStealer

First seen
2022-02-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Last IoC activity
2026-07-14 17:25:04
Profile updated
2026-07-07 14:43:03

Targeted industries: media-and-entertainment

Context

According to Intezer, YTStealer is a malware whose objective is to steal YouTube authentication cookies. As a stealer, it operates like many other stealers. The first thing it does when it’s executed is to perform some environment checks. This is to detect if the malware is being analyzed in a sandbox.

Reports & references

  • blog.sekoia.io — Privateloader The Loader Of The Prevalent Ruzki Ppi Service (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ytstealer (report)
  • intezer.com — Ytstealer Malware Youtube Cookies (report)

External references