HomeLatest NewsCyber SecurityFortnite V-bucks YouTube scams affect tens of thousands of users with malware

Fortnite V-bucks YouTube scams affect tens of thousands of users with malware

Web-based game-streaming platform Rainway, reported that tens of thousands of Fortnite players that have infected their systems with a piece of malware

Preferred Source of Google

Recently a Web-based game-streaming platform Rainway, reported that tens of thousands of Fortnite players that have infected their systems with a piece of malware that hijacks encrypted Web sessions in order to inject fraudulent ads into every website a user visits.

Rainway CEO Andrew Sampson published a blog post (linked below) in which he said that the company began receiving hundreds of thousands of error reports from its server logs last week and after investigating, the team found that the systems of their users were attempting to connect with various ad platforms.

Since Rainway system allows only whitelisted domains, users can connect only to approved URLs and every ad-related requests got blocked which in return resulted in errors that helped Rainway identify the issue..

Advertisement
VeeamON 2026 Tour India - Delhi
VeeamON 2026 Tour India - Delhi
A VeeamON 2026 India Leadership Series Delhi for senior public sector and government technology leaders.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

As these errors kept flowing in, the company examined the root cause of such errors by analysing what these users had in common. According to the company, their ISPs were different, they did not share any hardware and in fact, their systems were also up to date. There was just one thing that was common – they all played Fortnite.

How were the systems infected?

It was discovered that the affected users had installed cracked versions of Fornite tools which were being advertised through Youtube videos. These tools claimed to generate free V-bucks to give those users an unfair advantage over other players.

Advertisement

However, in reality, these hacks installed a root certificate on the infected computers that allowed modify all network traffic using a man-in-the-middle attack, even if the web session is encrypted.

The hackers leveraged the popularity of the Fortnite game to spread adware that alters the pages of a web request to serve its own ads.

According to the reports, the malware had already been downloaded 78,000 times before it was taken down.

Advertisement

According to Ankush Johar, Director at Ventures, gamers are often tempted to install these kinds of cheats, cracks, mods etc, however, one thing that should be kept in mind is that – Nothing comes for free. There is almost a 99% certainty that game cheats and hack tools that are available on the contain some sort of malware/adware that can affect user’s systems and then used to generate using ads or selling data in the black market, else what’s the benefit to the crackers?

The attack methodology used here i.e. installing a root certificate is one of the most dangerous things an attacker can do. This makes the compromised machines trust the https certificates generated by hackers and show a green lock in the browser even when the certificate is not what its supposed to be. So, a hacker can, in fact, using a man in the middle attack, make users redirect to phishing look-alikes of websites they visit such as Facebook, Gmail etc and users won’t have any idea as the browser will show that the website is trusted.

Get the day's headlines from Tech Observer straight in your inbox

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
- Advertisement -
Powered By Veeam Logo
- Advertisement -

Subscribe to our Newsletter

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
- Advertisement -

BHASHINI launches VYOMA Challenge with ₹80 lakh prize for offline AI solutions

The Digital India BHASHINI Division has launched the VYOMA Innovation Challenge with prizes worth ₹80 lakh for multilingual AI solutions that work offline. Twenty shortlisted teams will receive developer kits and mentorship.

RELATED ARTICLES