

"More importantly, one of the libraries bundled with the malicious Tor Browser is infected with spyware that collects various personal data and sends it to a command-and-control server," Kaspersky researchers Leonid Bezvershenko and Georgy Kucherin said. The attack banks on the fact that the actual Tor Browser website is blocked in China, thus tricking unsuspecting users searching for "Tor浏览器" (i.e., Tor Browser in Chinese) on YouTube into potentially downloading the rogue variant.Ĭlicking on the link redirects the user to a 74MB executable that, once installed, is designed to store users' browsing history and data entered into website forms.

The channel that hosted the video has 181,000 subscribers and claims to be based in Hong Kong. Google has moved to pull the video from the social media platform for violating YouTube's Harmful and Dangerous policies.
