Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

YouTube Ghost Malware Campaign: Over 3,000 Infected Videos Target Users

Check Point Research has identified a large-scale malware distribution operation known as the YouTube Ghost Network, which utilizes over 3,000 malicious videos to disseminate information-stealing malware.

Check Point Research has identified a large-scale malware distribution operation known as the YouTube Ghost Network, which utilizes over 3,000 malicious videos to disseminate information-stealing malware.

This network has been active since at least 2021, with a notable increase in activity by 2025, as perpetrators increasingly exploit the credibility of YouTube to circumvent conventional security protocols.

The YouTube Ghost Network employs a structured approach with three types of compromised accounts:

Video Accounts: Upload malicious content. Post Accounts: Share download links and passwords. Interact Accounts: Enhance perceived legitimacy through positive comments and engagement.

This framework allows the network to sustain operations despite individual account bans, as new accounts can quickly replace those that are compromised.

The network primarily targets users interested in "Game Hacks/Cheats" and "Software Cracks/Piracy." The most successful video targeted Adobe Photoshop, achieving 293,000 views and 54 comments, while another on FL Studio garnered 147,000 views.

The network's malware preferences have evolved due to law enforcement actions against major malware families. Before the Lumma infostealer disruption in early 2025, it was the most distributed malware in the network. Post-disruption, Rhadamanthys became the preferred tool.

Threat actors demonstrate adaptability by shifting tactics in response to security countermeasures. The campaign, likely beginning on September 8, includes files disguised as legitimate software, with modification timestamps confirming this timeline.

The malware primarily consists of infostealers designed to extract user credentials, financial information, and other sensitive data. Threat actors employ advanced evasion techniques such as:

Password-protected archives Frequent payload updates Rotation of command-and-control infrastructure every 3-4 days

These methods target automated detection systems, complicating identification and prevention by traditional security solutions.

The YouTube Ghost Network employs a structured approach with three types of compromised accounts: Video Accounts: Upload malicious content.
Eleanor Tate · Thehackingpost

Detailed analysis reveals sophisticated operational tactics. In one case, a compromised channel with 9,690 subscribers was used to distribute Rhadamanthys infostealer via cryptocurrency-themed videos. Redundant hosting on platforms like Google Sites, MediaFire, and Dropbox ensured persistence despite detection efforts.

Another campaign targeted content creators with malware disguised as cracked Adobe products, appealing specifically to YouTubers. Malicious archives included functional software and hidden malware, complicating detection as users experienced intended functionality while unknowingly installing infostealers.

The technical execution involves multi-stage deployment, beginning with MSI installers delivering HijackLoader, which then deploys the final Rhadamanthys payload. This strategy helps to evade detection by focusing on the entire infection chain rather than just the initial file.

Campaign Description Value

Campaign I Set-up.zip 92c26a15336f96325e4a3a96d4206d6a5844e6a735af663ba81cf3f39fd6bdfe

Campaign I Set-up.exe, Rhadamanthys b429a3e21a3ee5ac7be86739985009647f570548b4f04d4256139bc280a6c68f

Campaign I Rhadamanthys C&C hxxps://94.74.164[.]157:8888/gateway/6xomjoww.1hj7n

Campaign I Set-up.zip, 23/9 da36e5ec2a8872af6e2f7e8f4d9fdf48a9c4aa12f8f3b3d1b052120d3f932f01

Campaign I Set-up.exe, 23/9, Rhadamanthys b41fb6e936eae7bcd364c5b79dac7eb34ef1c301834681fbd841d334662dbd1d

Advertisement

Campaign I Set-up.exe, 23/9, Rhadamanthys C&C hxxps://openai-pidor-with-ai[.]com:6343/gateway/pqnrojhl.adc7k

Campaign I Set-up.exe, 23/9, Rhadamanthys C&C hxxps://178.16.53[.]236:6343/gateway/pqnrojhl.adc7k

Campaign II Adobe.Photoshop.2025.rar 7d9e36250ce402643e03ac7d67cf2a9ac648b03b42127caee13ea4915ff1a524

Campaign II Set-Up.msi ad81b2f47eefcdce16dfa85d8d04f5f8b3b619ca31a14273da6773847347bec8

Campaign II Rhadamanthys C&C hxxps://5.252.155[.]99/gateway/r2sh55wm.a56d3

Campaign II Adobe.Photoshop.2025.rar, 24/9 19b6bb806978e687bc6a638343b8a1d0fbd93e543a7a6a6ace4a2e7d8d9a900b

Campaign II Set-Up.msi, 24/9 270121041684eab38188e4999cc876057fd7057ec4255a63f8f66bd8103ae9f2

Campaign II C&C, 24/9 hxxps://5.252.155[.]231/gateway/3jw9q65j.b3tit

The YouTube Ghost Network exemplifies how cybercriminals adapt to security environments by exploiting trusted platforms and social engineering. This evolution necessitates a coordinated response from security researchers, platform operators, and law enforcement to combat effectively.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories