Wednesday, April 23, 2025
HomeBrowserNew Arcane Stealer Spreads via YouTube, Stealing VPN and Browser Login Credentials

New Arcane Stealer Spreads via YouTube, Stealing VPN and Browser Login Credentials

Published on

SIEM as a Service

Follow Us on Google News

A new malware campaign has been uncovered, involving a sophisticated stealer known as Arcane, which is distributed through YouTube videos promoting game cheats.

This campaign highlights the evolving tactics of cybercriminals, who continue to exploit popular platforms to spread malware.

The Arcane stealer is notable for its extensive data collection capabilities, targeting a wide range of applications including VPN clients, network utilities, and browsers.

- Advertisement - Google News

Distribution and Functionality

The distribution method begins with YouTube videos that include links to password-protected archives.

New Arcane Stealer
Original distribution scheme

Once unpacked, these archives contain a batch file that downloads additional malware components using PowerShell.

The batch file also disables Windows SmartScreen to evade detection by adding all drive roots to the SmartScreen filter exceptions and modifying registry keys to disable SmartScreen altogether.

The malware then launches executable files from the downloaded archive, which include a miner and the Arcane stealer itself.

Arcane is particularly adept at extracting sensitive information from various applications.

According to the SecureList Report, it targets VPN clients like OpenVPN, NordVPN, and ExpressVPN, as well as network utilities such as ngrok and FileZilla.

Additionally, it steals login credentials from browsers, including Chromium and Gecko-based browsers, using the Data Protection API (DPAPI) and an executable utility named Xaitax to crack browser encryption keys.

Arcane also secretly launches browsers with a remote-debugging-port argument to extract cookies from popular websites like Gmail and Steam.

ArcanaLoader and Target Audience

Following the discovery of Arcane, researchers observed a shift in distribution tactics with the introduction of ArcanaLoader.

This loader, advertised on YouTube channels, promises to download popular cracks and cheats but actually delivers malware.

The loader includes a link to a Discord server where users can access updates and support.

New Arcane Stealer
Discord server invitation

The attackers primarily target a Russian-speaking audience, as evidenced by the language used in their communications and the geographical distribution of victims, mainly in Russia, Belarus, and Kazakhstan.

The campaign underscores the adaptability of cybercriminals in using popular platforms to spread malware.

To protect against such threats, users should be cautious of suspicious software promotions and use robust security software to detect evolving malware.

The Arcane stealer’s ability to collect a broad spectrum of data makes it a significant threat, emphasizing the need for vigilance in online activities.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup – Try for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Hackers Exploit NFC Technology to Steal Money from ATMs and POS Terminals

In a disturbing trend, cybercriminals, predominantly from Chinese underground networks, are exploiting Near Field...

Threat Actors Leverage TAG-124 Infrastructure to Deliver Malicious Payloads

In a concerning trend for cybersecurity, multiple threat actors, including ransomware groups and state-sponsored...

Ransomware Actors Ramp Up Attacks Organizations with Emerging Extortion Trends

Unit 42’s 2025 Global Incident Response Report, ransomware actors are intensifying their cyberattacks, with...

New SMS Phishing Attack Weaponizes Google AMP Links to Evade Detection

Group-IB’s High-Tech Crime Trends Report 2025 reveals a sharp 22% surge in phishing websites,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Hackers Exploit NFC Technology to Steal Money from ATMs and POS Terminals

In a disturbing trend, cybercriminals, predominantly from Chinese underground networks, are exploiting Near Field...

Threat Actors Leverage TAG-124 Infrastructure to Deliver Malicious Payloads

In a concerning trend for cybersecurity, multiple threat actors, including ransomware groups and state-sponsored...

Ransomware Actors Ramp Up Attacks Organizations with Emerging Extortion Trends

Unit 42’s 2025 Global Incident Response Report, ransomware actors are intensifying their cyberattacks, with...