Threat Actors Exploit Fake Brand Collaborations to Target YouTube Channels
ID: 921d183d-235b-51ea-b775-e070a0fddf02
STIX ID: report--921d183d-235b-51ea-b775-e070a0fddf02
Feed Name: securityonline.info
CloudSek reports on a sophisticated global phishing campaign targeting YouTube creators: attackers impersonate brands to send OneDrive-hosted, password-protected ZIPs that unpack obfuscated payloads (e.g., webcams.pif, RegAsm.exe) which install infostealers that harvest browser credentials, cookies and clipboard data. The operation uses automation tools to collect targets, multi-layer compression/obfuscation to evade antivirus, C2 servers for exfiltration, and an extensive send infrastructure (hundreds of SMTP servers and proxies), with identified IOCs including domains, file names, and proxy counts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
