216.73.217.22

Dissecting YouTube's Malware Distribution Network

· Published 23/10/2025 13:51 · Modified 24/10/2025 11:49

Export JSON

Essential information

Published
23/10/2025 13:51
Modified
24/10/2025 11:49
Tags
0debug 2025-10-23 compromised accounts ghost network hijackloader lumma redline rhadamanthys stealc youtube
Related entities
16 techniques (mitre), 7 malware

Description

Check Point Research uncovered a sophisticated malware distribution campaign operating on , dubbed the . This network utilizes over 3,000 malicious videos to spread malware, primarily targeting users seeking game cheats and pirated software. The operation involves with specific roles: video uploaders, community posters, and interaction simulators. The network has been active since 2021, with a significant increase in activity in 2025. It mainly distributes infostealer malware, with and being prevalent. The campaign employs various tactics to evade detection, including password-protected archives and frequent updates to payloads and C2 infrastructure. This research highlights the evolving nature of malware distribution methods and the need for enhanced cybersecurity measures.

External references