logo

YouTube Creators Under Siege Again: Clickflix Technique Fuels Malware Attacks

ID: 1830337f-88c7-5cff-a272-a578f8e87c9b

STIX ID: report--1830337f-88c7-5cff-a272-a578f8e87c9b

Feed Name: CloudSEK Blog

Threat Score
72/100

Date Published: 2025-03-25

Date Updated: 2026-04-27

...
...

This report details a targeted spearphishing campaign against YouTube creators that lures victims with fake brand collaboration materials and uses a 'Clickflix' technique to copy a Base64-encoded PowerShell command into victims' clipboards; when executed the script establishes persistence, downloads a Lumma stealer payload from attacker-controlled CDN/C2 domains (several .xyz domains and related IPs), and exfiltrates browser credentials, cookies, and cryptocurrency wallets. The analysis includes script breakdown, IOCs (domains, email addresses, Google Drive link, a SHA-256 hash), MITRE ATT&CK mappings, and recommendations for user training, email/web filtering, endpoint protection, and network controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.