{"id":8615,"date":"2024-07-01T12:00:00","date_gmt":"2024-07-01T09:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/?p=8615"},"modified":"2026-06-14T19:39:40","modified_gmt":"2026-06-14T16:39:40","slug":"hijacked-how-hacked-youtube-channels-spread-scams-and-malware-2","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2024\/07\/01\/hijacked-how-hacked-youtube-channels-spread-scams-and-malware-2\/","title":{"rendered":"Hijacked: How hacked YouTube channels spread scams and malware"},"content":{"rendered":"<p>As one of today\u2019s <a href=\"https:\/\/www.statista.com\/statistics\/272014\/global-social-networks-ranked-by-number-of-users\/\">most popular social media platforms<\/a>, YouTube is often in the crosshairs of cybercriminals who exploit it to peddle scams and distribute malware. The lures run the gamut, but often involve videos posing as tutorials about popular software or ads for crypto giveaways. In other scenarios, fraudsters embed links to malicious websites in video descriptions or comments, disguising them as genuine resources related to the video\u2019s content.<\/p>\n<p>Thefts of popular YouTube channels up the game further. By extending the reach of the fraudulent campaigns to untold numbers of regular YouTube users, they give the attackers the most bang for their buck. Cybercriminals have long been known to <a href=\"https:\/\/therecord.media\/scammers-hijack-youtube-channels\">repurpose these channels<\/a> to spread <a href=\"https:\/\/www.welivesecurity.com\/en\/scams\/bitcoin-scams-hacks-heists-protect-yourself\/\">crypto and other scams<\/a> and a <a href=\"https:\/\/www.welivesecurity.com\/2023\/05\/16\/you-may-not-care-where-download-software-malware-does\/#:~:text=Similarly%2C%20they%20searched%20YouTube%20for%20a%20video%20about%20how%20to%20download%20a%20free%20or%20cracked%20version%20of%20a%20commercial%20software%20package%2C%20and%20then%20went%20to%20the%20website%20mentioned%20in%20the%20video%20or%20listed%20in%20its%20comments%20to%20download%20it.\">variety of info-stealing malware<\/a>, often through links to pirated and malware-laden software, movies and game cheats.<\/p>\n<p>Meanwhile, YouTubers who have had their accounts stolen are in for a highly distressing experience, with the consequences ranging from loss of income to lasting reputational damage.<\/p>\n<h2>How can cybercriminals take over YouTube channels?<\/h2>\n<p>More often than not, it all starts with good ol\u2019 phishing. Attackers create fake websites and send emails that look like they are from YouTube or Google and attempt to trick the targets into surrendering their \u201ckeys to the kingdom\u201d. In many cases, they also tout sponsorship or collaboration deals as the lure \u2013 the message includes an attachment or a link to a file where the terms and conditions are said to be detailed.<\/p>\n<p>Nothing could be further from the truth, however, with the threat becoming even more acute where the accounts were not protected by <a href=\"https:\/\/www.welivesecurity.com\/2019\/12\/13\/2fa-double-down-your-security\/\">two-factor authentication<\/a> (2FA) or where attackers circumvented this extra safeguard. (Since late 2021, content creators<a href=\"https:\/\/www.welivesecurity.com\/2021\/10\/06\/google-turn-on-2fa-default-150-million-users-2-million-youtubers\/\"> need to use 2FA<\/a> on the Google account associated with their YouTube channel).<\/p>\n<p>In some cases (cue the <a href=\"https:\/\/www.theverge.com\/2023\/3\/24\/23654996\/linus-tech-tips-channel-hack-session-token-elon-musk-crypto-scam\">breach of Linus Tech Tips<\/a>, a channel with 15 million subscribers at the time), attackers needed neither passwords nor 2FA codes to hijack the channels. Instead, they <a href=\"https:\/\/blog.google\/threat-analysis-group\/phishing-campaign-targets-youtube-creators-cookie-theft-malware\/\">stole session cookies<\/a> from the victims\u2019 browsers that ultimately enabled them to bypass the additional security checks involved in the authentication process.<\/p>\n<p>In another tried-and-tested technique, attackers leverage lists of <a href=\"https:\/\/www.welivesecurity.com\/how-to\/the-murky-world-of-password-leaks-and-how-to-check-if-youve-been-hit\/index.html\">usernames and passwords from past data breaches<\/a> to break into existing accounts, relying on the fact that many people <a href=\"https:\/\/www.welivesecurity.com\/2020\/05\/28\/people-know-reusing-passwords-risky-most-do-it-anyway\/\">reuse passwords across different sites<\/a>. In brute-force attempts, meanwhile, attackers use automated tools to <a href=\"https:\/\/www.welivesecurity.com\/2022\/01\/05\/5-ways-hackers-steal-passwords-how-stop-them\/\">try numerous password combinations<\/a> until they find the correct one. This method yields fruits especially if people use <a href=\"https:\/\/www.welivesecurity.com\/2023\/01\/02\/most-common-passwords-what-do-if-yours-list\/\">weak or common passwords<\/a> and skimp on 2FA.<\/p>\n<figure><img decoding=\"async\" alt=\"Figure 1. YouTube scam message\" height=\"\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2024\/6-2024\/figure-1-youtube-scam-message.jpeg\" title=\"Figure 1. Example of a phishing email sent to a YouTuber. It delivers malware that deletes the user\u2019s browser cookies, forcing them to re-enter their login credentials. Those are then sent to the attacker. (Source: The PC Security Channel)\" width=\"\"><figcaption><em>Figure 1. Example of a phishing email sent to a YouTuber. It delivers malware that deletes the user\u2019s browser cookies, forcing them to re-enter their login credentials. Those are then sent to the attacker. (Source: <a href=\"https:\/\/www.youtube.com\/watch?v=5FzsM3V5xRo\">The PC Security Channel<\/a>)<\/em><\/figcaption><\/figure>\n<p>Just weeks ago, the AhnLab Security Intelligence Center (ASEC) <a href=\"https:\/\/asec.ahnlab.com\/en\/63980\/\">wrote about a growing number of cases<\/a> where cybercriminals hijack popular YouTube channels, including one with 800,000 subscribers, and exploit them to distribute malware such as <a href=\"https:\/\/www.sleuthcon.com\/life-on-a-crooked-redline\">RedLine Stealer<\/a>, Vidar and <a href=\"https:\/\/web-assets.esetstatic.com\/wls\/en\/papers\/threat-reports\/eset-threat-report-h22023.pdf#page=14\">Lumma Stealer<\/a>.<\/p>\n<p>As described in the <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/eset-threat-report-h2-2023\/\">ESET Threat Report H2 2023<\/a>, Lumma Stealer made a splash particularly in the second half of last year. This infostealer-for-hire is known for <a href=\"https:\/\/www.welivesecurity.com\/2022\/01\/12\/cryptocurrency-scams-what-know-how-protect-yourself\/\">targeting crypto wallets<\/a>, login credentials and 2FA browser extensions, as well as for exfiltrating information from compromised machines. As the <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/eset-threat-report-h1-2024\/\">ESET Threat Report H1 2024<\/a> shows, both tools remain a major menace and often pose as cheating software or video game cracks, including via YouTube.<\/p>\n<figure><img decoding=\"async\" alt=\"Figure 2. YouTube channel spreading malware\" height=\"\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2024\/6-2024\/figure-2-youtube-channel-spreading-malware.png\" title=\"Figure 2. YouTube video offering a cracked version of Adobe After Effects and downloading RedLine\" width=\"\"><figcaption><em>Figure 2. YouTube video offering a cracked version of Adobe After Effects and downloading RedLine<\/em><\/figcaption><\/figure>\n<figure><img decoding=\"async\" alt=\"Figure 3. YouTube channel spreading malware\" height=\"\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2024\/6-2024\/figure-3-youtube-channel-spreading-malware.png\" title=\"Figure 3. Cracked \u2013 and malicious \u2013 version of Adobe After Effects\" width=\"\"><figcaption><em>Figure 3. Cracked \u2013 and malicious \u2013 version of Adobe After Effects<\/em><\/figcaption><\/figure>\n<p>In some scenarios, criminals hijack existing Google accounts and in the span of minutes create and post thousands of videos that distribute info-stealing malware. People who fall victim to the attacks may end up having their devices compromised with malware that also steals their accounts on other major platforms such as Instagram, Facebook, X, Twitch and Steam.<\/p>\n<h2>Staying out of harm\u2019s way on YouTube<\/h2>\n<p>These tips will go a long way towards keeping you safe on the platform, including if you\u2019re a YouTuber yourself.<\/p>\n<ul>\n<li>Use strong and unique login credentials<\/li>\n<\/ul>\n<p>Create strong passwords or passphrases and avoid reusing them across multiple sites. <a href=\"https:\/\/www.welivesecurity.com\/2023\/06\/20\/passwords-out-passkeys-in-ready-make-switch\/\">Explore passkeys<\/a> as another form of authentication offered by Google.<\/p>\n<ul>\n<li>Use a strong form of 2FA<\/li>\n<\/ul>\n<p>For an added layer of security, use 2FA not just on your Google account, but on all your other accounts. Wherever possible, choose 2FA involving authentication apps or hardware security keys instead of SMS-based methods.<\/p>\n<ul>\n<li>Be cautious with emails and links<\/li>\n<\/ul>\n<p>Be skeptical of emails or messages claiming to be from YouTube or Google, doubly when they ask for your personal information or account credentials. Check the sender\u2019s email address and look for signs of phishing. Just as importantly, avoid clicking on suspicious links or downloading attachments from unknown sources. The same goes for apps or other software that is promoted on YouTube unless they come from trusted and verified sources.<\/p>\n<ul>\n<li>Keep your operating system and other software updated<\/li>\n<\/ul>\n<p>Ensure your operating system, browser, and other software <a href=\"https:\/\/www.welivesecurity.com\/2022\/10\/24\/5-reasons-keep-software-devices-up-to-date\/\">are up to date<\/a> to protect against known vulnerabilities.<\/p>\n<ul>\n<li>Keep tabs on your account activity<\/li>\n<\/ul>\n<p>Regularly check your account activity for any suspicious actions or login attempts. If you suspect your channel has fallen prey to an attack, refer to <a href=\"https:\/\/support.google.com\/youtube\/answer\/76187?hl=en&amp;sjid=1383990412354715963-EU\">this guidance from Google<\/a>.<\/p>\n<ul>\n<li>Educate yourself<\/li>\n<\/ul>\n<p>Stay informed about the latest cyberthreats and scams targeting you online, including on YouTube. Knowing what to look out for can help you avoid falling victim to these threats.<\/p>\n<ul>\n<li>Report and block suspicious content<\/li>\n<\/ul>\n<p>Report any suspicious or harmful content, comments, links, or users to YouTube. Blocking such users can prevent them from contacting you further.<\/p>\n<ul>\n<li>Secure your devices<\/li>\n<\/ul>\n<p>Use multi-layered security software across your devices to protect against a variety of threats.<\/p>\n<div>\n<blockquote>\n<p><em>Before you go: <\/em><a href=\"https:\/\/www.welivesecurity.com\/2023\/05\/03\/using-discord-privacy-security-risks\/\"><em>Using Discord? Don\u2019t play down its privacy and security risks<\/em><\/a><\/p>\n<\/blockquote>\n<\/div>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/en\/scams\/hijacked-hacked-youtube-channels-scams-malware\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here\u2019s how cybercriminals go after YouTube channels and use them as conduits for fraud \u2013 and what you should watch out for when watching videos on the platform<\/p>\n","protected":false},"author":5,"featured_media":8616,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[147],"tags":[],"class_list":["post-8615","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybercrime"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8615","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8615"}],"version-history":[{"count":1,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8615\/revisions"}],"predecessor-version":[{"id":9267,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8615\/revisions\/9267"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8616"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8615"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8615"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8615"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}