The Phishing Website that Hacked Linus Tech Tips

The Phishing Website that Hacked Linus Tech Tips

Source: YouTube · John Hammond · published Aug 14, 2024 · 27:13

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video provides a technical breakdown of the phishing campaign that compromised the Linus Tech Tips X account, examining the fake email, the malicious website's code, and how it harvested credentials 0:00.

Key Takeaways:
• The attack originated from a spoofed "new login" email sent via the legitimate SendGrid service, which bypassed some security filters and included a tracking link 0:42.
• The phishing site dynamically pre-filled the target's profile picture and username using parameters passed in the URL, making the fake page appear highly personalized 6:07.
• Client-side JavaScript code captured sensitive data—including passwords, 2FA codes, and geolocation—and sent it to the attacker's server via AJAX requests before redirecting the user 14:04.
• The video creator was contacted by the attacker, who claimed to be Turkish and demanded the investigative content be removed to prevent people from distrusting the method 21:51.

The video concludes by advising viewers to use password managers, as they will not autofill credentials on fraudulent domains 25:59.

Sources:

  • 0:00 Introduction to the phishing site and Linus Tech Tips context
  • 0:42 Explanation of the SendGrid click tracking link in the email
  • 6:07 How the site extracts username from URL to pre-fill data
  • 14:04 AJAX request sending passwords and 2FA to the server
  • 21:51 The threat actor messages the creator demandin

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

this is the real fishing website that lonus Tech tips fell for leading to his Twitter or X account takeover on August 11th 2024 now if you're asking hey how do you know that it's the real one well Luke from their team sent it to me and if you're asking how do you know that lonus fell for it well he said so from his own personal Twitter account now I know that I've already made like two videos about this trying to track and cover the story but this video genuinely seriously has some technical Merit we will dive into and analyze what the website is made up of how the fish came to life and how this compromise really happened we will showcase the fishing website and the code behind it but first I want to tell you about the malicious link that was included in the fishing email this is the URL t…