Hackers Using Fake YouTube Links to Steal Login Credentials
ID: 50652a73-f4e9-547f-a1aa-6b47af3b4b97
STIX ID: report--50652a73-f4e9-547f-a1aa-6b47af3b4b97
Feed Name: HackRead
Threat Score
This report details a credential‑harvesting phishing campaign that disguises malicious destinations using deceptive YouTube-like URIs and multiple redirect layers (including fake Cloudflare checks), attributed to the Storm1747 group leveraging the Tycoon 2FA phishing kit; IOCs and an ANY.RUN sandbox analysis are referenced for investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
