Skip to main content
Mallory
Back to threat actors
6 malware families

YouTube Ghost Network

Also known asyoutube_ghost_network

YouTube Ghost Network is a malware distribution operation identified by Check Point Research that abuses compromised YouTube accounts and bot activity to spread malware through malicious links placed in video descriptions. Check Point reported the operation has been active since 2021, identified at least 3,000 malicious YouTube videos tied to it, and assessed that its content output tripled in 2025. The operation prefers compromising established YouTube accounts rather than creating new ones, and organizes accounts into roles including "video accounts," "post accounts," and "interact accounts." Video accounts upload phishing videos and direct viewers to purported software downloads, post accounts publish messages and share external download links and passwords, and interact accounts add likes and positive comments to make the content appear legitimate. The campaign relies on social engineering and user self-infection, casting a wide net with lures centered primarily on video game cheats and hacks, followed by software cracks. Roblox is specifically identified as the most targeted game, while Adobe Photoshop and Adobe Lightroom are identified as the most targeted products in the software-crack category. Malware families observed in the operation include infostealers such as Lumma and Rhadamanthys, as well as StealC, RedLine, Odebug, other Phemedrone variants, and NodeJS-based loaders and downloaders. The content also links GachiLoader to a campaign associated with the YouTube Ghost Network. Check Point assessed the operation as evolving toward stealthier and more sophisticated malware distribution, with potential future tailoring of lures to specific industries or enterprise software.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal6

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.