Cybercriminals are increasingly targeting popular YouTube creators with fake brand collaboration offers as part of a sophisticated phishing campaign designed to distribute malware, according to a recent report by cybersecurity firm CloudSEK. The attackers use convincing tactics to trick content creators into downloading malicious files that steal sensitive data and compromise their systems.
The malware is typically disguised as legitimate documents such as contracts or promotional materials. To evade detection, these files are hosted on platforms like OneDrive and protected with passwords. Once downloaded, the malware can harvest sensitive information, including login credentials, financial details, and intellectual property, while also granting attackers remote access to the victim’s systems.
Security researcher Mayank Sahariya highlighted the organized and resourceful nature of the threat actors, stating, “The attackers use malware hidden within attachments like Word documents, PDFs, or Excel files, often masquerading as business proposals or agreements.”
The phishing emails are sent from spoofed or compromised addresses, making them appear credible to recipients. The email typically includes a link to a password-protected zip file hosted on platforms like OneDrive, with instructions to access promotional materials and contracts. When the victim opens the files, the malware installs itself and begins extracting sensitive data or enabling remote access for the attackers.
Businesses and individuals in marketing, sales, and executive positions are particularly vulnerable to these schemes due to their regular engagement in brand promotions and partnerships.
This campaign underscores the importance of verifying collaboration requests and adopting robust cybersecurity practices to avoid falling victim to such attacks. Content creators, marketers, and other professionals are advised to double-check the authenticity of emails and collaboration offers before engaging with them.
CloudSEK urges creators and businesses to remain vigilant and employ security measures such as multi-factor authentication, regular system updates, and email filtering to protect against these threats. With hackers leveraging increasingly advanced techniques, safeguarding digital ecosystems has become more critical than ever.

