Google squashes phishing campaign targeting YouTubers

Hook on Keyboard
(Image credit: wk1003mike / Shutterstock)

YouTube content creators have been subjected to financially motivated phishing campaigns since late 2019, according to Google’s cybersecurity researchers.

The search giant’s Threat Analysis Group (TAG) has shared details about such thwarted campaigns that are orchestrated using Cookie Theft malware.

“In collaboration with YouTube, Gmail, Trust & Safety, CyberCrime Investigation Group and Safe Browsing teams, our protections have decreased the volume of related phishing emails on Gmail by 99.6% since May 2021,” shares TAG researcher Ashley Shen in a blog post.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

TAG attributes the campaigns to threat actors recruited through a Russian-speaking underground forum. 

Smash and grab

Shen says that the hackers lure their target with fake collaboration opportunities, before using the infected software to hijack their channel, which they either then sell to the highest bidder (for upto $4000), or use it to broadcast cryptocurrency scams.

The Cookie Theft technique employed by the attackers enabled them to hijack the victim’s user accounts through the session cookies stored in their web browsers

"While the technique has been around for decades, its resurgence as a top security risk could be due to a wider adoption of multi-factor authentication (MFA) making it difficult to conduct abuse, and shifting attacker focus to social engineering tactics," shares Shen.

Interestingly Shen says the malware used in the campaign was run in non-persistent to ensure that it doesn’t linger on a compromised system, long enough to attract the attention of security products. 

Migrated elsewhere

Commenting on the size of the campaigns, Shem says that TAG identified over 1000 domains along with about 15000 user accounts that were created solely for the purpose of orchestrating the scam.

The email accounts were used to deliver phishing emails containing links redirecting to malware landing pages to YouTube creators' business emails. TAG helped block about 1.6 million messages, and even successfully restored access to about 4000 accounts.

“With increased detection efforts, we’ve observed attackers shifting away from Gmail to other email providers (mostly email.cz, seznam.cz, post.cz and aol.com),” concludes Shen, hinting that the campaign has only switched email providers and is perhaps still active. 

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Google Gemini Flash 2.0 Images
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's Flash 2.0
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts&#039; web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all