Phemedrone Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
October 28, 2025
Last Seen
December 17, 2025

Phemedrone is a malware family tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed October 28, 2025; most recent activity December 17, 2025.

Overview

Phemedrone is presented in the context of the YouTube Ghost Network campaign as the malware family used by this operation. The campaign relies on thematic, 'spooky' social-engineering tactics to target YouTube users, highlighting platform-specific deception and payload delivery. This underscores a notable shift toward user-targeted threats on mainstream services.

Related Threat Clusters

  • Infostealer Campaigns Expand to Target macOS Systems

    Infostealer threats have shifted from primarily targeting Windows to macOS environments, as reported by the Microsoft Defender Security Research Team. Since late 2025, these campaigns have utilized cross-platform…

    13 articles · Updated February 4, 2026
  • YouTube Ghost Network Distributes Malware via Compromised Accounts

    Over 3,000 YouTube videos were removed by Google for distributing password-stealing malware disguised as cracked software. The operation, identified as the 'YouTube Ghost Network,' utilized compromised accounts to post…

    3 articles · Updated November 3, 2025
  • YouTube Ghost Network Distributes Malware via Compromised Accounts

    In 2025, Check Point Research identified a malware distribution network on YouTube, dubbed the 'YouTube Ghost Network.' This operation utilized compromised accounts and social engineering tactics to spread…

    3 articles · Updated November 3, 2025

Recent Intelligence Reports

  • The 2025 Infostealer Ecosystem: A Deep Dive — Reddit · December 17, 2025
  • YouTube Ghost Network Utilizes Spooky Tactics to Target Users — Darkreading · October 28, 2025

CVSS v3.1 Breakdown