Over 200,000 creators on YouTube have been targeted by cybercriminals impersonating major brands in a newly discovered phishing campaign.

Fraudsters send malicious emails with subject lines such as "Cooperation Proposal" and "Marketing Opportunity," with the aim of tricking their victims into clicking or opening attachments containing malware, according to Cloudsek.
Read more: Europe: Authorities arrest members of “phishing gang”
Password-protected files hosted on cloud platforms like OneDrive contain malicious executables disguised as deals or promotional materials.
Once extracted, the files activate malware designed to steal sensitive information, such as login credentials and session cookies, or gain remote access to the victim's device.
Hackers can then take control of the victim's YouTube account and use this access to spam followers with more malicious messages .
The malware used in this global campaign has been linked by Cloudsek to threats related to Lumma Stealer.
See more: New phishing campaign: Malicious applications distribute the banking trojan Antidot
The security provider reported that over 340 SMTP servers are used in the campaign and that over 46 remote desktop protocol (RDP) systems are operating, with the aim of helping to compromise systems or activate malware.
Cloudsek has also recorded more than 26 SOCKS5 servers, which are used to anonymize traffic and maintain the concealment of command and control (C2) communications.
"This campaign is not just about account theft; it's about leveraging the trust and influence of creators on YouTube to fuel scams," said Mayank Sahariya, a security researcher at Cloudsek.

Read also: Teenager hacks telecommunications companies and sends millions of phishing messages
“Hackers are exploiting these accounts to promote scams and fraudulent activities, reaching millions of unsuspecting followers. The scale of this operation means not only financial losses for victims but also long-term damage to the creators’ reputations, highlighting the urgent need for better security awareness and strong protective measures.”
Source: infosecurity-magazine
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
