Google, in collaboration with Check Point researchers, dismantled a large-scale malware distribution campaign on YouTube known as the 'YouTube Ghost Network.' This operation involved over 3,000 malicious videos posted across compromised and fake YouTube accounts, which lured users with promises of cracked software and game cheats. Victims were instructed to disable antivirus protections and download archives from cloud storage services, which contained infostealers such as Rhadamanthys and Lumma. The campaign, active since at least 2021 and surging in 2025, weaponized YouTube engagement features—such as likes, comments, and community posts—to create a false sense of legitimacy and trust around the malicious content.
The Ghost Network's structure mirrored previous malware distribution tactics seen on other platforms, with different accounts assigned to upload videos, post community updates, and interact in comment sections to boost credibility. The majority of the malware distributed targeted user credentials, crypto wallets, and sensitive system data. Following the disruption of the Lumma infostealer, the network shifted to distributing Rhadamanthys. The takedown of these videos and accounts has significantly reduced the threat, but the campaign highlights the evolving sophistication of platform-based malware delivery and the risks associated with downloading pirated software from untrusted sources.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
On October 23, 2025, Check Point and subsequent coverage publicly exposed the 'YouTube Ghost Network,' detailing its tactics, malware families including Lumma and Rhadamanthys, and its use of legitimate platforms such as Google Drive, Dropbox, and MediaFire.
After Check Point reported the network to Google, the company removed most of the identified malicious YouTube videos, with one report characterizing the action as the takedown of roughly 3,000 videos.
Check Point Research identified a large coordinated malware distribution network tied to more than 3,000 YouTube videos, using compromised and fake accounts, comments, likes, and external file-hosting services to spread infostealers and loaders.
Researchers reported the operation's activity later surged, with output tripling during 2024 according to some reports, indicating a major escalation in the volume of malicious YouTube content.
Check Point said the 'YouTube Ghost Network' has been active since at least 2021, using YouTube videos to lure users seeking cracked software, pirated tools, and game cheats into downloading malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcezdnet.com
Open sourceresearch.checkpoint.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.