logo

Dissecting YouTube’s Malware Distribution Network

ID: 87f17fcf-efcb-505e-903a-02a04eca6b3f

STIX ID: report--87f17fcf-efcb-505e-903a-02a04eca6b3f

Feed Name: Check Point Research

Threat Score
75/100

Date Published: 2025-10-23

Date Updated: 2026-04-27

Author: [email protected]

...
...

Check Point Research discovered and analyzed the "YouTube Ghost Network," a role-based collection of compromised YouTube accounts that systematically promoted cracked software and game cheats to distribute infostealer malware (primarily Lumma and Rhadamanthys). The investigation identified over 3,000 malicious videos (with substantial view counts), detailed operational tactics (video/post/interact account roles, password-protected archives, shortened/redirected links, redundant hosting), enumerated IOCs including hashes and C2 endpoints, and documented rapid malware/C2 rotation that enabled evasive, persistent campaigns; researchers reported the content to Google and provided detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.