{"id":72870,"date":"2025-10-25T10:54:54","date_gmt":"2025-10-25T07:54:54","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=72870"},"modified":"2025-10-25T10:54:54","modified_gmt":"2025-10-25T07:54:54","slug":"massive-youtube-malware-ring-uncovered-by-researchers","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/technology\/72870\/massive-youtube-malware-ring-uncovered-by-researchers\/","title":{"rendered":"Massive YouTube Malware Ring Uncovered by Researchers"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Check Point researchers uncovered a large-scale malware operation called the &#8220;YouTube Ghost Network&#8221; that used over 3,000 videos on compromised or fake channels.<br>&#8211; The network lured viewers with offers of game cheats and cracked software but instead delivered malware or phishing pages through download links.<br>&#8211; Similar to the Stargazers Ghost Network on GitHub, it used specialized accounts for uploading videos, posting links, and creating fake endorsements to appear legitimate.<br>&#8211; The operation was designed to be resilient by using compromised channels, frequently updating links and payloads, and employing password-protected archives to evade detection.<br>&#8211; Despite Google removing over 3,000 malicious videos after being alerted, the network has been active since 2021 and its operators are unlikely to cease their efforts.<br><\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"color:#f34c3e\" class=\"has-inline-color\">S<\/mark>ecurity researchers have exposed a massive and deceptive malware operation on <a href=\"https:\/\/digitrendz.blog\/z\/entity\/youtube\/\" class=\"acp-entity-link\" data-entity-id=\"21\" data-entity-category=\"Technology\" title=\"Learn more about YouTube\" target=\"_blank\" rel=\"noopener noreferrer\">YouTube<\/a>, which they named the \u201c<a href=\"https:\/\/digitrendz.blog\/z\/entity\/youtube-ghost-network\/\" class=\"acp-entity-link\" data-entity-id=\"141870\" data-entity-category=\"Event\" title=\"Learn more about YouTube Ghost Network\" target=\"_blank\" rel=\"noopener noreferrer\">YouTube Ghost Network<\/a>.\u201d This sophisticated scheme used thousands of videos across fake or hijacked channels to distribute dangerous software and phishing links. Viewers were tricked by promises of <strong>free game cheats, cracked applications, or pirated software<\/strong>, only to be directed toward harmful downloads instead.<\/p>\n\n<p class=\"wp-block-paragraph\">The operation mirrors a previous campaign known as the <a href=\"https:\/\/digitrendz.blog\/z\/entity\/stargazers-ghost-network\/\" class=\"acp-entity-link\" data-entity-id=\"141871\" data-entity-category=\"Event\" title=\"Learn more about Stargazers Ghost Network\" target=\"_blank\" rel=\"noopener noreferrer\">Stargazers Ghost Network<\/a>, which misused <a href=\"https:\/\/digitrendz.blog\/z\/entity\/github\/\" class=\"acp-entity-link\" data-entity-id=\"198\" data-entity-category=\"Organization\" title=\"Learn more about GitHub\" target=\"_blank\" rel=\"noopener noreferrer\">GitHub<\/a> accounts in a similar way. Both networks function like a <a href=\"https:\/\/digitrendz.blog\/z\/topic\/malware-distribution\/\" class=\"acp-topic-link\" data-topic-id=\"76498\" title=\"Explore: malware distribution\" target=\"_blank\" rel=\"noopener noreferrer\">malware distribution<\/a> service, carefully organized to appear legitimate while targeting unsuspecting users.<\/p>\n\n<p class=\"wp-block-paragraph\">In the YouTube version, different types of accounts played specific roles. Video accounts uploaded enticing content, such as offers for <a href=\"https:\/\/digitrendz.blog\/z\/entity\/adobe-photoshop\/\" class=\"acp-entity-link\" data-entity-id=\"1763\" data-entity-category=\"Technology\" title=\"Learn more about Adobe Photoshop\" target=\"_blank\" rel=\"noopener noreferrer\">Adobe Photoshop<\/a> cracks or <a href=\"https:\/\/digitrendz.blog\/z\/entity\/roblox\/\" class=\"acp-entity-link\" data-entity-id=\"18129\" data-entity-category=\"Technology\" title=\"Learn more about Roblox\" target=\"_blank\" rel=\"noopener noreferrer\">Roblox<\/a> hacks, and included links to password-protected files hosted on services like <a href=\"https:\/\/digitrendz.blog\/z\/entity\/dropbox\/\" class=\"acp-entity-link\" data-entity-id=\"7547\" data-entity-category=\"Organization\" title=\"Learn more about Dropbox\" target=\"_blank\" rel=\"noopener noreferrer\">Dropbox<\/a> or <a href=\"https:\/\/digitrendz.blog\/z\/entity\/google-drive\/\" class=\"acp-entity-link\" data-entity-id=\"7676\" data-entity-category=\"Technology\" title=\"Learn more about Google Drive\" target=\"_blank\" rel=\"noopener noreferrer\">Google Drive<\/a>. Instructions often advised users to disable <a href=\"https:\/\/digitrendz.blog\/z\/entity\/windows-defender\/\" class=\"acp-entity-link\" data-entity-id=\"57799\" data-entity-category=\"Technology\" title=\"Learn more about Windows Defender\" target=\"_blank\" rel=\"noopener noreferrer\">Windows Defender<\/a> before installation, a major red flag for security risks.<\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/digitrendz.blog\/z\/topic\/post-accounts\/\" class=\"acp-topic-link\" data-topic-id=\"118798\" title=\"Explore: post accounts\" target=\"_blank\" rel=\"noopener noreferrer\">Post accounts<\/a> shared the same malicious links through YouTube\u2019s community tab, while <a href=\"https:\/\/digitrendz.blog\/z\/topic\/interact-accounts\/\" class=\"acp-topic-link\" data-topic-id=\"118799\" title=\"Explore: interact accounts\" target=\"_blank\" rel=\"noopener noreferrer\">interact accounts<\/a> flooded video comment sections with fake positive feedback. This created an illusion of trustworthiness, making the scam harder for viewers to detect.<\/p>\n\n<p class=\"wp-block-paragraph\">Researchers pointed out that while email phishing is still common, cybercriminals are increasingly turning to platform-based strategies like Ghost Networks. These campaigns exploit the built-in trust people place in established platforms and use engagement features, such as comments and community posts, to run large-scale, persistent malware operations. One expert described the method as \u201ccasting nets across the web,\u201d where users essentially infect themselves by following the attackers\u2019 instructions.<\/p>\n\n<p class=\"wp-block-paragraph\">The YouTube Ghost Network was built to be both stealthy and resilient. Most accounts were legitimate channels that had been compromised. If one channel got banned, the operators simply replaced it. Because responsibilities were divided among many accounts, the network could continue operating even after partial takedowns.<\/p>\n\n<p class=\"wp-block-paragraph\">Threat actors regularly refreshed download links and malware payloads, allowing infections to persist despite removal efforts. They used password-protected archives, multiple file hosting platforms, and frequently updated command-and-control servers to avoid automated detection and manual review by security teams.<\/p>\n\n<p class=\"wp-block-paragraph\">Most of the malware distributed through this network consisted of information stealers, with <strong>Lumma Stealer and Rhadamanthys<\/strong> being the most prominent. These programs are designed to harvest sensitive data like passwords, cryptocurrency wallets, and browser cookies from infected devices.<\/p>\n\n<p class=\"wp-block-paragraph\">Although the network has been active since at least 2021, the volume of malicious videos tripled in 2025. Following reports from researchers, <a href=\"https:\/\/digitrendz.blog\/z\/digital-marketing\/224988\/chatgpt-ranked-in-top-10-most-impersonated-brands-for-phishing\/\" class=\"acp-article-link\" data-article-id=\"224988\" title=\"ChatGPT Ranked in Top 10 Most Impersonated Brands for Phishing\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a> removed more than 3,000 harmful videos, significantly disrupting the operation. However, security experts warn that the individuals behind these campaigns are unlikely to stop, and similar threats are expected to reemerge on other platforms.<\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <a href=\"https:\/\/www.helpnetsecurity.com\/2025\/10\/23\/youtube-malware-distribution-network-ghost\/\" target=\"_blank\" rel=\"noreferrer noopener\">HelpNet Security<\/a>)<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Security researchers uncovered the &#8220;YouTube Ghost Network,&#8221; a deceptive malware operation using fake or hijacked channels to distribute harmful software and phishing links through enticing offers like free game cheats or cracked applications. The network employed a sophisticated structure with di&#8230;<\/p>\n","protected":false},"author":1,"featured_media":72869,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[6579,3297,3327,3254],"tags":[12462,106561,105538,52803,106562],"entities":[933,8299,44692,4893,1356,4937,106563,11913,106565,39441,763,106564],"class_list":["post-72870","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bigtech-companies","category-cybersecurity","category-newswire","category-technology","tag-cybersecurity-threats","tag-ghost-network","tag-information-stealers","tag-lumma-stealer","tag-youtube-malware","entity-adobe-photoshop","entity-check-point","entity-check-point-research","entity-dropbox","entity-github","entity-google-drive","entity-mediafire-2","entity-roblox","entity-stargazers-ghost-network","entity-windows-defender","entity-youtube","entity-youtube-ghost-network"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/72870","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=72870"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/72870\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/72869"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=72870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=72870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=72870"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=72870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}