216.73.217.22

YouTube Creators Under Siege Again: Clickflix Technique Fuels Malware Attacks

· Published 25/03/2025 17:37 · Modified 25/03/2025 18:50

Export JSON

Essential information

Published
25/03/2025 17:37
Modified
25/03/2025 18:50
Tags
2025-03-25 clickflix credential-theft cryptocurrency lumma stealer powershell social engineering spearphishing youtube
Related entities
5 observables, 10 techniques (mitre), 1 malware, 2 others

Description

Cybercriminals are targeting creators with a sophisticated malware campaign using the technique. Attackers impersonate popular brands and offer fake collaboration opportunities to lure victims. The campaign employs emails with malicious attachments and links to fake Microsoft webpages. These pages trick users into executing scripts that download and run malware, such as . The malware steals browser data, wallet information, and other sensitive data, transmitting it to command and control servers. The attack chain includes stealth and persistence mechanisms to evade detection. This campaign exploits content creators' interest in brand deals and partnerships, representing an evolution of previously observed tactics against channels.

External references