A malicious network of YouTube accounts is publishing and promoting videos that lead to malware downloads, essentially taking advantage of the popularity and trust that users place on the video hosting platform.
Active since 2021, the network has published more than 3,000 malicious videos, with the volume of these videos tripling since the beginning of the year. Check Point analysts have codenamed the network the “YouTube Ghost Network.” Google has stepped in and removed the majority of the videos.
The campaign exploits compromised accounts and replaces their content with malicious videos focused on pirated software and cheats for Roblox. The hackers aim to infect unsuspecting users who make such searches with info-stealer malware . Some of these videos have garnered hundreds of thousands of views, ranging from 147,000 to 293,000.
See also: Evolution of phishing attacks to bypass defenses

“This operation exploited trust signals, such as views, likes, and comments, to make malicious content appear safe,” said Eli Smadja, director of the security research group at Check Point. “What may seem like a useful tutorial may actually be a well-crafted cybertrap. The scale, modularity, and complexity of this network make it a model for how threat actors are now using interaction tools to spread malware.”
Abuse of YouTube and other legitimate services to distribute malware
Using YouTube to distribute malware is not a new phenomenon. For years, threat actors have been observed taking over legitimate channels or using new accounts to post tutorial-style videos with descriptions that lead to malicious links that, when clicked, lead to malware.
These attacks are part of a broader trend where attackers are using legitimate platforms for malicious purposes, turning them into an effective avenue for distributing malware. While some of the campaigns have abused legitimate ad networks, such as those associated with search engines like Google or Bing, others have exploited GitHub as a delivery vehicle, as in the case of the Stargazers Ghost Network.
One of the main reasons why Ghost Networks have taken off is that they can reinforce the perceived legitimacy of the links they share and maintain operational continuity even when accounts are banned or removed by platform owners, thanks to their role-based structure.
See also: Lazarus hackers targeted European defense companies

“These accounts exploit various features of the platform, such as videos, descriptions, posts, and comments, to promote malicious content and distribute malware while creating a false sense of trust,” said security researcher Antonis Terefos.
“The majority of the network consists of compromised YouTube accounts, which are given specific operational roles. This role-based structure allows for more stealthy distribution, as banned accounts can be quickly replaced without disrupting overall operation“.
How do malicious YouTube accounts work?
Video accounts upload phishing videos and provide descriptions containing links to download the advertised software, while the links are shared as pinned comments or provided directly in the video as part of the installation process. Post-accounts to publish community messages and posts containing links to external websites. Finally, there are Interact-accounts, which like and post encouraging comments to give the videos a veneer of trust and credibility.
The links direct users to a wide range of services such as MediaFire, Dropbox or Google Drive, or to phishing pages hosted on Google Sites, Blogger and Telegraph that embed links to download the supposed software. In many cases, the links are hidden using URL shorteners to mask the real destination.
See also: Impacket tool in Kali Repo has new attack routes
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Some of the malware families distributed via the YouTube Ghost Network include Lumma Stealer, Rhadamanthys Stealer, StealC Stealer, RedLine Stealer, Phemedrone Stealer , and other Node.js-based loaders and downloaders.
“The continued evolution of malware distribution methods demonstrates the remarkable adaptability and resourcefulness of threat actors in circumventing conventional security defenses,” Check Point said. “Adversaries are increasingly turning to more sophisticated strategies, most notably the deployment of ghost networks.”
«These networks leverage the trust inherent in legitimate accounts and the engagement mechanisms of popular platforms to organize large-scale, persistent, and highly effective malware campaigns.».
