YouTube Creators Under Siege Again: Clickflix Technique Fuels Malware Attacks
ID: 1830337f-88c7-5cff-a272-a578f8e87c9b
STIX ID: report--1830337f-88c7-5cff-a272-a578f8e87c9b
Feed Name: CloudSEK Blog
This report details a targeted spearphishing campaign against YouTube creators that lures victims with fake brand collaboration materials and uses a 'Clickflix' technique to copy a Base64-encoded PowerShell command into victims' clipboards; when executed the script establishes persistence, downloads a Lumma stealer payload from attacker-controlled CDN/C2 domains (several .xyz domains and related IPs), and exfiltrates browser credentials, cookies, and cryptocurrency wallets. The analysis includes script breakdown, IOCs (domains, email addresses, Google Drive link, a SHA-256 hash), MITRE ATT&CK mappings, and recommendations for user training, email/web filtering, endpoint protection, and network controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
