How Threat Actors Exploit Brand Collaborations to Target Popular YouTube Channels
ID: e66ed699-0054-563e-a2ce-e255ca824414
STIX ID: report--e66ed699-0054-563e-a2ce-e255ca824414
Feed Name: CloudSEK Blog
This report details a large-scale phishing campaign targeting businesses and YouTube creators by impersonating brands and sending password-protected archives hosted on OneDrive; extracted payloads (AutoIt-based executables and a RegAsm-injected .NET component) deploy a credential- and cookie-stealing infostealer linked to Lumma Stealer, communicating with identified C2 infrastructure and leaving multiple IoCs (file hashes, domains, IPs) and operational artifacts (SMTP accounts, stealer logs, automation tools).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
