YouTube Ghost Network Utilizes Spooky Tactics to Target Users
The malware operation uses compromised accounts and bot networks to distribute infostealers and has tripled its output in 2025.
Threat actors are haunting YouTube, lurking in compromised accounts and using videos to trick unsuspecting users in downloading malware.
In a recent investigation, Check Point Research discovered a collection of malicious YouTube accounts, known as YouTube Ghost Network, promoting malicious links and distributing a wide variety of malware.
Though Ghost Network operates across multiple platforms, including GitHub , Checkpoint researchers identified at least 3,000 malicious videos on YouTube associated with the network, most of which have since been taken down. The group, which has been active since 2021, has been producing more and more content over the years, tripling its output in 2025.
Instead of using their own homegrown YouTube accounts and videos, Ghost Network favors compromising established accounts and hijacking the videos to spread malware. The vast majority if videos are focused on video game cheats and hacks , with the descriptions containing malicious links.
The compromised accounts included in the operation are given specific operation roles such as: video accounts, meant to upload phishing videos and provide descriptions for viewers to download "software"; post accounts, which are responsible for publishing messages and sharing external download links and passwords; and interact accounts, which endorse the malicious content being put up by affirming them with likes or positive , seemingly legitimizing the content to other viewers.
Check Point researchers have identified multiple malware families distributed through the videos, most of which are infostealers, such as Lumma and Rhadamanythys . Others include StealC , RedLine , Odebug and other Phemedrone variants, and NodeJS loaders and downloaders.
The researchers noted that the Ghost Network targets users by casting wide nets across the Web and hoping to reel in victims. The users who approach and engage with the content "essentially infect themselves," according to the Check Point report . What attracts the victims are solutions tailored to fix their specific problems; the user groups most frequently targeted are game hacks and cheats, followed by software cracks, miscellaneous groups, and lastly cryptocurrency/trading bots.
In the game hacks and cheats category, the most targeted game is Roblox, which boasts 380 million monthly active users. The most targeted products in the software cracks and piracy category are Adobe Photoshop and Lightroom. The most viewed malicious video targets Adobe Photoshop and amassed close to 300,000 views and 54 , according to Check Point.
Though threat actors are still utilizing every tool in their box, researchers find that their distribution methods remain ever-evolving, constantly shifting to more sophisticated strategies and attack methods. These large-scale campaigns showcase what the Check Point researchers refer to as a "new paradigm" where the threat actors systematically compromise accounts, build community through false trust, and maintain operational continuity even as accounts in their environments get taken down.
"This new method of malware distribution will grow and become stealthier and less easy to detect, even when targeting the general public," says Eli Smadja, group manager at Check Point Research. "Regarding businesses and enterprises, they should provide their employees with equipment that is used solely for corporate purposes and not shared with any family members."
It's likely that such campaigns will become more focused on enterprise, Smadja says.
"We still consider that future videos/content distributing malware will be more targeted to specific industry/company needs, making them more attractive for company employees," he added. "Possibly sharing 'plug-ins' for software used in a specific industry."
This makes it even more difficult for defenders to mitigate or disrupt the threat. Check Point said it's essential for security researchers, platform providers, and law enforcement agencies to collaborate in order to identify and fully shut down the distribution networks of malicious content. Individuals also need to be made aware of the threat that downloading software from unofficial or untrusted sources poses and utilize proper cybersecurity hygiene to ensure that they don't fall victim.
"By publishing our research on Ghost Networks, we aim to raise awareness this emerging threat that enables high infection rates through this new malware distribution method," Smadja says. "Individuals should remain cautious, even if they see positive engagement from other accounts, as our research shows these may be bots, and should always download software only from legitimate sources."
Associate Editor, Dark Reading
Skilled writer and editor covering cybersecurity for Dark Reading.
Miercom Test Results: PA-5450 Firewall Wins
Security Without Compromise Better security, higher performance and lower TCO
The Total Economic Impact™ Of Palo Alto Networks NextGeneration Firewalls
How Enterprises Are Harnessing Emerging Technologies in Cybersecurity
Worldwide Security Information and Event Management Forecast, 2025--2029: Continued Payment for One's SIEMs
The Cloud is No Longer Enough: Securing the Modern Digital Perimeter
Securing the Hybrid Workforce: Challenges and Solutions
Cybersecurity Outlook 2026
Threat Hunting Tools & Techniques for Staying Ahead of Cyber Adversaries
Measuring Ransomware Resilience: What Hundreds of Security Leaders Revealed
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
