Phemedrone is a malware family tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed October 28, 2025; most recent activity December 17, 2025.
Phemedrone is presented in the context of the YouTube Ghost Network campaign as the malware family used by this operation. The campaign relies on thematic, 'spooky' social-engineering tactics to target YouTube users, highlighting platform-specific deception and payload delivery. This underscores a notable shift toward user-targeted threats on mainstream services.
Infostealer threats have shifted from primarily targeting Windows to macOS environments, as reported by the Microsoft Defender Security Research Team. Since late 2025, these campaigns have utilized cross-platform…
Over 3,000 YouTube videos were removed by Google for distributing password-stealing malware disguised as cracked software. The operation, identified as the 'YouTube Ghost Network,' utilized compromised accounts to post…
In 2025, Check Point Research identified a malware distribution network on YouTube, dubbed the 'YouTube Ghost Network.' This operation utilized compromised accounts and social engineering tactics to spread…