Description
A newly discovered information-stealing malware, Arcane, is actively targeting YouTube and Discord users through malicious game cheats and cracks. This malware is designed to steal extensive user data, including VPN account credentials, gaming client data, messaging app information, and sensitive data stored in web browsers. Unlike previous stealer families, Arcane has no direct links to Arcane Stealer V, which has been in circulation on the dark web for years. The campaign behind Arcane began in November 2024 and has undergone multiple iterations, including changes in primary payloads and distribution methods. Cybersecurity firm Kaspersky has observed that most infections occur in Russia, Belarus, and Kazakhstan, a rare occurrence since many threat actors in Russia typically avoid targeting users within their own country.
Attack Details
Arcane Stealer is being distributed through YouTube videos and Discord channels that promote game cheats and cracks. Unsuspecting users are tricked into downloading a password-protected archive, which contains an obfuscated ‘start.bat’ script. When executed, this script fetches another archive with malicious executables that install the infostealer on the victim’s system.
The malware operates by modifying Windows Defender’s SmartScreen filter settings, either by disabling it entirely or adding exclusions to all drive root folders. Additionally, Arcane can profile infected systems by gathering hardware and software details such as:
Arcane’s most notable feature is its broad scope of data theft, targeting account credentials and configurations from:
Additionally, Arcane captures screenshots from infected machines and retrieves saved Wi-Fi passwords, further increasing the risk of financial fraud, identity theft, and extortion.
Indicators of Compromise (IOCs)
File Hashes (Examples based on previous infostealers):
Malicious Domains and URLs:
IP Addresses:
Remediation
To protect against the Arcane Infostealer, users must adopt strict security practices:
The Guyana National CIRT recommends that users and administrators review this alert and apply it where necessary.
PDF Download: Arcane Infostealer Infects YouTube and Discord Users via Game Cheats
References