Full Report
Fake giveaways hit bitcoiners again. Now on YouTube
Analysis Summary
# Incident Report: Massive Cryptocurrency Giveaway Scams via YouTube Live
## Executive Summary
Cybercriminals orchestrated a large-scale fraud campaign leveraging hijacked high-subscriber YouTube channels to broadcast fake cryptocurrency giveaways. By using deepfakes or stolen footage of industry figures (e.g., Elon Musk, Gary Vaynerchuk), attackers lured victims to phishing sites that stole funds through "double your money" schemes or seed phrase theft. The incident highlights a sophisticated infrastructure involving thousands of fraudulent domains and automated stream promotion.
## Incident Details
- **Discovery Date:** February - March 2022 (Reported by Group-IB)
- **Incident Date:** Ongoing (Peak activity noted in early 2022)
- **Affected Organization:** YouTube (Platform), various hijacked channel owners
- **Sector:** Cryptocurrency / Social Media
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** Variable; preceding live broadcasts.
- **Vector:** Hijacking of existing YouTube accounts.
- **Details:** Attackers gained control of popular YouTube channels, often through phishing or session hijacking, to utilize their established subscriber bases.
### Lateral Movement
- **Details:** Not applicable in the traditional network sense; however, attackers pivoted from hijacked YouTube accounts to external fraudulent infrastructure (domain networks).
### Data Exfiltration/Impact
- **Details:** Direct theft of cryptocurrency from victims' wallets. In NFT-specific variants, attackers exfiltrated wallet seed phrases and private keys via phishing forms.
### Detection & Response
- **Detection:** Identified by Group-IB Digital Risk Protection (DRP) via monitoring of automated stream titles and domain registrations.
- **Response:** Reporting of fraudulent channels to YouTube for termination; blacklisting of identified phishing domains.
## Attack Methodology
- **Initial Access:** Account takeover (ATO) of high-traffic YouTube channels.
- **Persistence:** Maintaining control of the YouTube account until the platform intervenes.
- **Defense Evasion:** Using legitimate, high-authority YouTube channels to bypass spam filters; using QR codes to redirect users to avoid URL scanning.
- **Credential Access:** Phishing for crypto wallet seed phrases and private keys.
- **Discovery:** Identifying high-subscriber accounts to hijack.
- **Collection:** Gathering victim wallet information via malicious web forms.
- **Impact:** Financial loss through "multiplier" scams (send 1 BTC, get 2 back) and unauthorized wallet drainage.
## Impact Assessment
- **Financial:** Significant; one analyzed wallet showed roughly $1.6M in stolen funds over a short period.
- **Data Breach:** Loss of private cryptographic keys and seed phrases for affected users.
- **Operational:** Disruption to legitimate YouTube creators whose channels were hijacked and subsequently banned.
- **Reputational:** Damage to the reputation of the celebrities featured in the deepfakes and to YouTube’s brand safety.
## Indicators of Compromise
- **Network Indicators:**
- `ark-tesla[.]io` (Example Phishing Domain)
- `teslagive[.]org` (Example Phishing Domain)
- `eth-musk[.]com` (Example Phishing Domain)
- **Behavioral Indicators:**
- YouTube streams featuring looped footage of tech celebrities with "Live" overlays.
- Descriptions containing "Giveaway" links or QR codes.
- Disabled chat or chat filled with bot-driven "proof" of payouts.
## Response Actions
- **Containment:** Suspension of hijacked YouTube accounts by Google/YouTube.
- **Eradication:** Taking down phishing domains through registrars and hosting providers.
- **Recovery:** Account recovery processes for the original channel owners.
## Lessons Learned
- **The "High-Sub" Trap:** Users often trust content based on the subscriber count of the channel, not realizing the channel was hijacked minutes prior.
- **Deepfake Effectiveness:** Even low-quality deepfakes or recycled footage remain highly effective when combined with the "urgency" of a live broadcast.
- **Automation:** Attackers are using sophisticated tools to spin up thousands of domains simultaneously, making manual takedowns difficult.
## Recommendations
- **For Users:**
- Enable Hardware Security Keys (U2F) for YouTube/Google accounts to prevent hijacking.
- Never share a 12- or 24-word seed phrase with any website or individual.
- Treat any "multiplier" giveaway (send money to get more back) as a guaranteed scam.
- **For Platforms:**
- Implement stricter monitoring for live streams on recently recovered or suddenly active accounts.
- Use AI to detect recycled or "looped" footage associated with known scam keywords.