Jump to content

Linus Tech Tips, Tech Quickie, Tech Linked channels hacked

betav17
Message added by Spotty,

The Linus Tech Tips, TechLinked, and TechQuickie Youtube channels have been restored.

A video explaining what happened is now up:

 

 

I just got a Floatplane AD on YouTube with Linus saying saying the channel is hacked put FP is still up😂, they work fast. 

  • CPU
    Intel Core i5-13600k
  • Motherboard
    MSI Z790 Tomahawk WIFI
  • RAM
    Hyper X Fury 16GB*1 Slot DDR5-5200
  • GPU
    Asus TUF GeForce 3070TI
  • Case
    NZXT H510i
  • Storage
    Kingston KC3000 1 TB
  • PSU
    Cooler Master MWE 750W Gold Modular
  • Display(s)
    Samsung 27" Odyssey 165 HZ
  • Cooling
    Coolermaster Liquid ML240 Illusion
  • Keyboard
    Hyper X Alloy Origins CORE/PBT
  • Mouse
    Razer Deathadder V2 X wireless
  • Sound
    HyperX Cloud 2
  • Operating System
    Windows 10
  • Laptop
    MacBook Air M1
  • Phone
    iPhone 13 Pro
Link to comment
Share on other sites

Link to post
Share on other sites

@TylerD321I know about those platforms but don't touch them. Period. However, it now appears LMG has their LTT channel back and it seems in good order:

 

https://www.youtube.com/@LinusTechTips

 

So it looks like we're back to normal. Well, except for the staff who now are working overtime to check everything is OK and prevent another attack, cause you can count on these scammers to keep it up on their side, LMG is way too enticing to let it go!

"You don't need eyes to see, you need vision"

 

(Faithless, 'Reverence' from the 1996 Reverence album)

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, DanOnTheSpiral said:

I just got a Floatplane AD on YouTube with Linus saying saying the channel is hacked put FP is still up😂, they work fast. 

Is there a way to find the original uploaded video of an ad? Can anyone link it?

Link to comment
Share on other sites

Link to post
Share on other sites

anyone wanna discuss what was said in the FP video on Framework?

Link to comment
Share on other sites

Link to post
Share on other sites

Why Google not do anything with 2FA that would make impossible bypass it with just stealing cookies? It clearly show that 2FA have massive exploit that should be fixed. It's not first time than someone bypass 2FA with stealing cookies.

Link to comment
Share on other sites

Link to post
Share on other sites

8 hours ago, BondiBlue said:

It's pinned to the top of this page. There's a large box with the entire post from Floatplane. 

Aaaaah OK, thanks for the information!

I like cute animal pics.

Mac Studio | Ryzen 7 5800X3D + RTX 3090

Link to comment
Share on other sites

Link to post
Share on other sites

Someone could have downloaded a virus on their device and it has spread. MAKE SURE YOU HAVE ANTIVIRUS SOFTWARE INSTALLED. ANY SYSTEM AND SOFTWARE IS UP TO DATE OR THIS CAN HAPPEN.

Link to comment
Share on other sites

Link to post
Share on other sites

Hello there LMG and related parties.

 

I saw that you got hacked a while ago when I was gonna watch some YouTube and noticed that I did not see any of the LTT videos on my feed. Tried searching for the channel but it did not come up, only that the channel was hacked.

 

It was VERY sad to see it happen.

It's amazing to see the channel get restored so quickly.  Really good effort from the LMG Team, Google and YouTube.
Lets hope it does not happen again! The content you guys produce is amazing and I hope that you will keep up the awesome work!

I think I speak for the entire community when I say this:
Thank you guys for such amazing content over the years and we all wish you the very best and wishes for many more years of content to come!

 

Best regards, Pierre and the LTT community members!

CPU: Intel Core i3 4150 3.5GHz Socket 1150 GPU: MSI GeForce GTX 760 OC RAM: Corsair Vengeance 2x4GB Motherboard: Gigabyte Z97MX-Gaming 5

Link to comment
Share on other sites

Link to post
Share on other sites

linus channel is back, this truly is a moment in history

Dont forget to mark as solution if your question is answered

Note: My advice is amateur help/beginner troubleshooting, someone else can probably troubleshoot way better than me.

- I do have some experience, and I can use google pretty well. - Feel free to quote me I may respond soon.

 

Join team Red, my apprentice

 

STOP SIDING WITH NVIDIA

 

Setup:
Ryzen 7 5800X3DSapphire Nitro+ 7900XTX 24GB / ROG STRIX B550-F Gaming / Cooler Master ML360 Illusion CPU Cooler / EVGA SuperNova 850 G2 / Lian Li Dynamic Evo White Case / 2x16 GB Kingston FURY RAM / 2x 1TB Lexar 710 / iiYama 1440p 165HZ Montitor, iiYama 1080p 75Hz Monitor / Shure MV7 w/ Focusrite Scarlett Solo / GK61 Keyboard / Cooler Master MM712 (daily driver) Logitech G502-X (MMO mouse) / Soundcore Life Q20 w/ Arctis 3 w/ WF-1000XM3

 

CPU OC: -30 all cores @AutoGhz

GPU OC: 3Ghz Core 2750Mhz Memory w/ 25%W increase (460W)

Link to comment
Share on other sites

Link to post
Share on other sites

@Spotty when will the channel links come back on the right side of the site?

Dont forget to mark as solution if your question is answered

Note: My advice is amateur help/beginner troubleshooting, someone else can probably troubleshoot way better than me.

- I do have some experience, and I can use google pretty well. - Feel free to quote me I may respond soon.

 

Join team Red, my apprentice

 

STOP SIDING WITH NVIDIA

 

Setup:
Ryzen 7 5800X3DSapphire Nitro+ 7900XTX 24GB / ROG STRIX B550-F Gaming / Cooler Master ML360 Illusion CPU Cooler / EVGA SuperNova 850 G2 / Lian Li Dynamic Evo White Case / 2x16 GB Kingston FURY RAM / 2x 1TB Lexar 710 / iiYama 1440p 165HZ Montitor, iiYama 1080p 75Hz Monitor / Shure MV7 w/ Focusrite Scarlett Solo / GK61 Keyboard / Cooler Master MM712 (daily driver) Logitech G502-X (MMO mouse) / Soundcore Life Q20 w/ Arctis 3 w/ WF-1000XM3

 

CPU OC: -30 all cores @AutoGhz

GPU OC: 3Ghz Core 2750Mhz Memory w/ 25%W increase (460W)

Link to comment
Share on other sites

Link to post
Share on other sites

17 hours ago, LinusTech said:

Thanks for the concern everyone. We are still in recovery mode over here and working with YouTube to get everything restored. Will hopefully have a video (or at least an update on WAN Show) to share with you all ASAP, but we want to make sure we get the details right since smaller channels may rely on our experience to help harden their own security.

They're back!

Link to comment
Share on other sites

Link to post
Share on other sites

As a CISO with experience in this kind of stuff, I'd love to offer my services free of charge on figuring out the how, and the how to prevent this from happening in the future. KnowBe4 should be the first thing on your list.

Link to comment
Share on other sites

Link to post
Share on other sites

 

F@H
Desktop: i9-13900K, ASUS Z790-E, 64GB DDR5-6000 CL36, RTX3080, 2TB MP600 Pro XT, 2TB SX8200Pro, 2x16TB Ironwolf RAID0, Corsair HX1200, Antec Vortex 360 AIO, Thermaltake Versa H25 TG, Samsung 4K curved 49" TV, 23" secondary, Mountain Everest Max

Mobile SFF rig: i9-9900K, Noctua NH-L9i, Asrock Z390 Phantom ITX-AC, 32GB, GTX1070, 2x1TB SX8200Pro RAID0, 2x5TB 2.5" HDD RAID0, Athena 500W Flex (Noctua fan), Custom 4.7l 3D printed case

 

Asus Zenbook UM325UA, Ryzen 7 5700u, 16GB, 1TB, OLED

 

GPD Win 2

Link to comment
Share on other sites

Link to post
Share on other sites

20 minutes ago, Kilrah said:

 

Can you make this the new pinned comment for the hack megathread, or add it to a new top-banner announcement?

Edited by Needfuldoer
Apparently you can! Thanks! Hopefully this video won't get good-faith spammed on the forum now...

I sold my soul for ProSupport.

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, gamebrigada said:

As a CISO with experience in this kind of stuff, I'd love to offer my services free of charge on figuring out the how, and the how to prevent this from happening in the future. KnowBe4 should be the first thing on your list.

Social engineering can never be 100% secure, the only way is to have a good plan of recovery and minimize admin access as much as possible. Security awareness training is always good also 😄

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, MartyS said:

Looks like all they need is some automated way of removing the crypto scam line from all the video descriptions, the original descriptions are all there, the crypto scam link was just added to the top of each one.

 

Hope they don't have to manually make all the private videos private again, that will take so many hour of work.

then just dont private

Dont forget to mark as solution if your question is answered

Note: My advice is amateur help/beginner troubleshooting, someone else can probably troubleshoot way better than me.

- I do have some experience, and I can use google pretty well. - Feel free to quote me I may respond soon.

 

Join team Red, my apprentice

 

STOP SIDING WITH NVIDIA

 

Setup:
Ryzen 7 5800X3DSapphire Nitro+ 7900XTX 24GB / ROG STRIX B550-F Gaming / Cooler Master ML360 Illusion CPU Cooler / EVGA SuperNova 850 G2 / Lian Li Dynamic Evo White Case / 2x16 GB Kingston FURY RAM / 2x 1TB Lexar 710 / iiYama 1440p 165HZ Montitor, iiYama 1080p 75Hz Monitor / Shure MV7 w/ Focusrite Scarlett Solo / GK61 Keyboard / Cooler Master MM712 (daily driver) Logitech G502-X (MMO mouse) / Soundcore Life Q20 w/ Arctis 3 w/ WF-1000XM3

 

CPU OC: -30 all cores @AutoGhz

GPU OC: 3Ghz Core 2750Mhz Memory w/ 25%W increase (460W)

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, n0stalghia said:

Verge is reporting a common vector of attacks by fake sponsors sending fake sponsor videos for YouTubers to use, which turns out to be malware. They are citing YouTube as the source for this information. Mind you, they are reporting this as a general thing that happens, not claiming that this is what happened to LMG.

It's been confirmed by Linus that this was indeed the vector of attack.

I like cute animal pics.

Mac Studio | Ryzen 7 5800X3D + RTX 3090

Link to comment
Share on other sites

Link to post
Share on other sites

yeah, but all the company everybody and Linus and family had to be in so much stress I cant even imagine, and the fallout IF somebody was so not wise enough and clicked the links for the crypto and got infected or scammed I cant imagine what is now going in LMG like in management , since they have not even posted one thread or video, shorts about this, at leas I cant find any, and what is going on there what is the dmg and if they will be alright , but still cudos to management on LMG and YT channels to resolve this within 24h .

Cant wait for that WAN show too .

All well and hope you restore and be back up in the "machine" back for not loose so much money.

I go and buy a shirt and water bottle just for support, even with one two days they had to lose so much money, and they got 100ppl to feed . 

Hope they didn´t lose any sensitive internal information 😞 don´t know if they would inform on that and even if they know, to be hacked in such massive was not one but all channels can point to that they had some kind of malware internally for long time and the perpetrators planned this for some time and how long how deep were they in the systems. 

God nobody is safe in this day/age from this however good big  and good security you have in place, one human error to click on link form legit looking sponsor email and its in the system . 

I read on megathread and on other articles it seems to come from china? or that´s misinformation? 

I suggest anyone that can and wanted to buy something from LTTstore now is the time, mof me its CPU Tshirt and that new sweet Wbottle , i have only the OG big one 🙂 

Ciao , all the best 

Link to comment
Share on other sites

Link to post
Share on other sites

Good response and insight from Linus! Go for regular awareness training, tabletop exercises, and a few social engineering tests throughout the year.

Once a baseline is established, one should also push for more extensive testing, such as an adversarial attack simulation. Might be some good content for the channel as well "Why we now pay hackers to hack us".

 

Happy to see the channel back up 🥰

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, Mr.Prevo said:

yeah, but all the company everybody and Linus and family had to be in so much stress I cant even imagine, and the fallout IF somebody was so not wise enough and clicked the links for the crypto and got infected or scammed I cant imagine what is now going in LMG like in management , since they have not even posted one thread or video, shorts about this, at leas I cant find any, and what is going on there what is the dmg and if they will be alright , but still cudos to management on LMG and YT channels to resolve this within 24h .

Cant wait for that WAN show too .

All well and hope you restore and be back up in the "machine" back for not loose so much money.

I go and buy a shirt and water bottle just for support, even with one two days they had to lose so much money, and they got 100ppl to feed . 

Hope they didn´t lose any sensitive internal information 😞 don´t know if they would inform on that and even if they know, to be hacked in such massive was not one but all channels can point to that they had some kind of malware internally for long time and the perpetrators planned this for some time and how long how deep were they in the systems. 

God nobody is safe in this day/age from this however good big  and good security you have in place, one human error to click on link form legit looking sponsor email and its in the system . 

I read on megathread and on other articles it seems to come from china? or that´s misinformation? 

I suggest anyone that can and wanted to buy something from LTTstore now is the time, mof me its CPU Tshirt and that new sweet Wbottle , i have only the OG big one 🙂 

Ciao , all the best 

They posted a follow up video around 30 minutes ago, and a video went up on floatplane yesterday mid-crisis - 

 

Current Gaming Build:

 

CPU: AMD Ryzen 5 2600  |  GPU: GTX 1660 6GB   |  Motherboard: MSI B450M PRO-VDH MAX AM4  |  RAM: 16GB Corsair Vengeance LPX DDR4-3200  |  PSU: AeroCool 750W 80+ Bronze Semi-Modular  |  Storage: 120GB Palit SSD, 1TB WD Blue, 1TB HDD, 1TB Toshiba P300 HDD  |  Cooler: Hyper 212 Evo  |  Case: Be Quiet! Pure Base 500

Link to comment
Share on other sites

Link to post
Share on other sites

As much as we call this "social engineering", maybe "business engineering" makes more sense?  For anyone that doesn't watch the full video that just went up, it was in malware loaded PDF from what was likely a well laid out sponsor opportunity offer email. Hopefully there isn't a full Redline or other root kit on the system. Because you start to get into issues of large scale compromises. LMG might actually be lucky if it was only a "smash and grab" approach grabbing credentials. 

 

Upper Echelon Gaming had a video on someone trying to hit him with a much more serious malware package, but generally the same approach. I do feel for the Sales staff got hit at LMG. PDFs fail on their own regularly enough that few would actually think twice about it not working.

 

Though the most disturbing result in all of this: apparently Linus sleeps in the nude.

Link to comment
Share on other sites

Link to post
Share on other sites

i mean google and youtube could be seen as to be the cause. this has been happening to so many people they need to figure out how to stop it

Link to comment
Share on other sites

Link to post
Share on other sites

Tech blog, CVS entry, payload, version of software affected etc ?
This could be super useful to help others protect against, not to mention that it's wild that a "pdf" can still do such damage in 2023. 

Link to comment
Share on other sites

Link to post
Share on other sites

Not sure this has been answered anyone else - but has the malware been shared somewhere with the infosec community? I know a lot of people who'd like to pull it apart, so any and all relevant IOCs can be shared.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×