Today > vulnerabilities   -   You can now download lists of IOCs here!

How Threat Actors Exploit Brand Collaborations to Target Popular YouTube Channels

Dec. 17, 2024, 10:04 a.m.

Description

Cybercriminals are targeting YouTube creators through sophisticated phishing campaigns that impersonate trusted brands offering collaboration deals. The malware is disguised as legitimate documents and delivered via password-protected files on platforms like OneDrive. Once downloaded, it steals sensitive information and grants remote access to victims' systems. The campaign uses YouTube parsers to collect email addresses, automation tools for bulk phishing, and multiple SMTP servers for distribution. Attackers leverage templates impersonating brands and PR entities to create convincing emails. The malware communicates with command and control servers to exfiltrate data, using techniques to evade detection. This global campaign highlights the need for content creators and marketers to verify collaboration requests and implement robust cybersecurity measures.

Date

Published: Dec. 17, 2024, 12:24 a.m.

Created: Dec. 17, 2024, 12:24 a.m.

Modified: Dec. 17, 2024, 10:04 a.m.

Indicators

564de0f055afa822add5e46761cba0c422f6a5e060ab7d2133599d8759598d50

d8b7c7178fbadbf169294e4f29dce582f89a5cf372e9da9215aa082330dc12fd

vm95039.vps.client-server.site

Attack Patterns

Lumma Stealer

T1217

T1589.002

T1566.002

T1590

T1016

T1082

T1057

T1083

T1071

T1055

T1036

T1056

T1041

T1078

T1003

T1059

Additional Informations

Technology

Media