logo

From Cracked to Hacked: Malware Spread via YouTube Videos

ID: c526d472-9586-59fc-9191-281f7041cd6f

STIX ID: report--c526d472-9586-59fc-9191-281f7041cd6f

Feed Name: Cybereason Blog

Threat Score
65/100

Date Published: 2024-02-12

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

This report describes an active campaign (TropiCracked) that hijacks older YouTube accounts to distribute cracked-software lures which redirect through Rebrandly/Telegraph to file-sharing sites hosting commodity infostealers (notably Redline and RaccoonStealer). The analysis covers the infection flow, payload analysis, infrastructure and binary-swap tactics, provides IoCs (file hashes, C2 IP, malicious URLs), and recommends detection and mitigation steps including behavior-based controls and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.