How Threat Actors Exploit Brand Collaborations to Target Popular YouTube Channels
Dec. 17, 2024, 10:04 a.m.
Tags
External References
Description
Cybercriminals are targeting YouTube creators through sophisticated phishing campaigns that impersonate trusted brands offering collaboration deals. The malware is disguised as legitimate documents and delivered via password-protected files on platforms like OneDrive. Once downloaded, it steals sensitive information and grants remote access to victims' systems. The campaign uses YouTube parsers to collect email addresses, automation tools for bulk phishing, and multiple SMTP servers for distribution. Attackers leverage templates impersonating brands and PR entities to create convincing emails. The malware communicates with command and control servers to exfiltrate data, using techniques to evade detection. This global campaign highlights the need for content creators and marketers to verify collaboration requests and implement robust cybersecurity measures.
Date
Published: Dec. 17, 2024, 12:24 a.m.
Created: Dec. 17, 2024, 12:24 a.m.
Modified: Dec. 17, 2024, 10:04 a.m.
Indicators
564de0f055afa822add5e46761cba0c422f6a5e060ab7d2133599d8759598d50
d8b7c7178fbadbf169294e4f29dce582f89a5cf372e9da9215aa082330dc12fd
vm95039.vps.client-server.site
Attack Patterns
Lumma Stealer
T1217
T1589.002
T1566.002
T1590
T1016
T1082
T1057
T1083
T1071
T1055
T1036
T1056
T1041
T1078
T1003
T1059
Additional Informations
Technology
Media