SharpCovertTube is a program created to control Windows systems remotely by uploading videos to Youtube.
The program monitors a Youtube channel until a video is uploaded, decodes the QR code from the thumbnail of the uploaded video and executes a command.
The QR codes in the videos can use cleartext or AES-encrypted values.
It has two versions, binary and service binary, and it includes a Python script to generate the malicious videos. Its purpose is to serve as a persistence method using only web requests to the Google API.
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMFPOgLyPd7qnhLPXP7uJ5XodQ9iNQ2rGGu48fEe3OQrOIOQaRsZYkryU3wgZP7XdMj6daTDFICJWQnKgGCzdvJcD5GrL5i6A2eKDeHlbxlyxayZacHJCc6S9eKhFvyQEgO2zF0vgv6rCZ4v8fpKpxV_thoIfJI5NoyXyO65ZWHFqgrPkpSmIXOuyZTkav/s16000/Screenshot_0.webp)
Usage
Run the listener in your Windows system:
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7K7gfGMTt9FPEXLEqBBlMOCb30PQnf0CMsuN47QM4JxXE74P7Jdbwtb_OPLJn4qdAoorkHGpvwIGtjrtPeWRbBEagBddkGQmQpUwtfIqCd79vN6SK5AinBRJTCdP02fqg4AeZrLCdVlV_uvVYkNjOI58l1SY2oXLL9kX_Jk4GiHnkbSWcJwkwylG0lX-9/s16000/Screenshot_1.webp)
It will check the Youtube channel every a specific amount of time (10 minutes by default) until a new video is uploaded. In this case, we upload “whoami.avi” from the folder example-videos:
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhfXp4qgT7MV5tc922t5Wb1kiDWqLQfqHrceDJfhsshF5wx_QU3Jj6oKdYUbj-qaDu9PJWY9ZXtZL59v277B9t-bCvhr10uvfHb7UTKoeceNdWDdnSQZ4PMNaxfT0j37ZwNz3xoBmGg_l8a38VxUs-Jza3Dw2AdUTtHsM20RwqsDp14Bqo_dKZGw4X5pFVb/s16000/Screenshot_2.webp)
After finding there is a new video in the channel, it decodes the QR code from the video thumbnail, executes the command and the response is base64-encoded and exfiltrated using DNS:
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgELjTp5PZwjB5fvgYamE3YL-KKV0IyDldBK_yTwU5MEySTnx2geXSy_Tfj83CmMe5Zm2tH3duGClYq3avLzenJ4PHhNA-Zj-8V20r19MsEdpOSufZ1b6rx7FX29QQWKc3tjdbzAirQdunFuF-qRCh3uSllbccVqBDEIHkdOGzY8DmDD09G_VkKy-x34aj0/s16000/Screenshot_3.webp)
For more information click here