YouTube Ghost Network Distributes Malware via Compromised Accounts

YouTube Ghost Network Distributes Malware via Compromised Accounts

First seen 4 Nov 2025, 11:10 UTC TheregisterDarkreadingFoxnews 80% similarity 31.4

Article Content

Browse articles
ThreatCluster

Over 3,000 YouTube videos were removed by Google for distributing password-stealing malware disguised as cracked software. The operation, identified as the 'YouTube Ghost Network,' utilized compromised accounts to post videos that misled users into downloading infostealers like Rhadamanthys and Lumma. This malware campaign has been active since 2021 and has significantly increased its output in 2025.

ThreatCluster AI

Community

Browse all →