logo

How Threat Actors Exploit Brand Collaborations to Target Popular YouTube Channels

ID: e66ed699-0054-563e-a2ce-e255ca824414

STIX ID: report--e66ed699-0054-563e-a2ce-e255ca824414

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2024-12-16

Date Updated: 2026-04-27

...
...

This report details a large-scale phishing campaign targeting businesses and YouTube creators by impersonating brands and sending password-protected archives hosted on OneDrive; extracted payloads (AutoIt-based executables and a RegAsm-injected .NET component) deploy a credential- and cookie-stealing infostealer linked to Lumma Stealer, communicating with identified C2 infrastructure and leaving multiple IoCs (file hashes, domains, IPs) and operational artifacts (SMTP accounts, stealer logs, automation tools).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.