Foxnews
YouTube Ghost Network Distributes Malware via Compromised Accounts
First seen 4 Nov 2025, 11:10 UTC
•

•80% similarity
•31.4
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Over 3,000 YouTube videos were removed by Google for distributing password-stealing malware disguised as cracked software. The operation, identified as the 'YouTube Ghost Network,' utilized compromised accounts to post videos that misled users into downloading infostealers like Rhadamanthys and Lumma. This malware campaign has been active since 2021 and has significantly increased its output in 2025.
ThreatCluster AI