YouTube Ghost Network
YouTube Ghost Network is a malware distribution operation identified by Check Point Research that abuses compromised YouTube accounts and bot activity to spread malware through malicious links placed in video descriptions. Check Point reported the operation has been active since 2021, identified at least 3,000 malicious YouTube videos tied to it, and assessed that its content output tripled in 2025. The operation prefers compromising established YouTube accounts rather than creating new ones, and organizes accounts into roles including "video accounts," "post accounts," and "interact accounts." Video accounts upload phishing videos and direct viewers to purported software downloads, post accounts publish messages and share external download links and passwords, and interact accounts add likes and positive comments to make the content appear legitimate. The campaign relies on social engineering and user self-infection, casting a wide net with lures centered primarily on video game cheats and hacks, followed by software cracks. Roblox is specifically identified as the most targeted game, while Adobe Photoshop and Adobe Lightroom are identified as the most targeted products in the software-crack category. Malware families observed in the operation include infostealers such as Lumma and Rhadamanthys, as well as StealC, RedLine, Odebug, other Phemedrone variants, and NodeJS-based loaders and downloaders. The content also links GachiLoader to a campaign associated with the YouTube Ghost Network. Check Point assessed the operation as evolving toward stealthier and more sophisticated malware distribution, with potential future tailoring of lures to specific industries or enterprise software.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Associated malware families
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with a malware distribution campaign using a Node.js-based loader (GachiLoader) with heavy obfuscation and a previously undocumented PE injection technique; deploys a second-stage loader (Kidkadi) that abuses Vectored Exception Handling (VEH) via a technique dubbed 'Vectored Overloading' to load payloads.
A malware distribution operation leveraging compromised YouTube accounts (and other platforms like GitHub) plus bot-driven engagement to spread infostealers and other payloads via malicious links in video descriptions, commonly themed around game cheats/hacks and software cracks.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.