• News/
  • https://www.theregister.com/2025/10/23/youtube_ghost_network_malware/

Google nukes 3,000 YouTube videos that sowed malware disguised as cracked software

The Register
·
Carly Page
·
Published Oct 23, 2025
·
Updated

Google has taken down thousands of YouTube videos that were quietly spreading password-stealing malware disguised as cracked software and game cheats. Researchers at Check Point say the so-called "YouTube Ghost Network" hijacked and weaponized legitimate YouTube accounts to post tutorial videos that promised free copies of Photoshop, FL Studio, and Roblox hacks, but instead lured viewers into installing infostealers such as Rhadamanthys and Lumma. The campaign, which has been running since 2021, surged in 2025, with the number of malicious videos tripling compared to previous years. More than 3,000 malware-laced videos have now been scrubbed from the platform after Check Point worked with Google to dismantle what it called one of the most significant malware delivery operations ever seen on YouTube. Check Point says the Ghost Network relied on thousands of fake and compromised accounts working in concert to make malicious content look legitimate. Some posted the "tutorial" videos, others flooded comment sections with praise, likes, and emojis to give the illusion of trust, while a third set handled "community posts" that shared download links and passwords for the supposed cracked software. "This operation took advantage of trust signals, including views, likes, and comments, to make malicious content seem safe," said Eli Smadja, security research group manager at Check Point. "What looks like a helpful tutorial can actually be a polished cyber trap. The scale, modularity, an...

Read full article

Affected Software

4 affected components
Google YouTube
Adobe Photoshop
Image-Line FL Studio
Roblox Roblox
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What prompted Google to take down these YouTube videos?

Google removed the videos after discovering they were spreading password-stealing malware disguised as cracked software and game cheats.

2

How many YouTube videos were affected by this malware?

Approximately 3,000 YouTube videos were taken down due to their involvement in distributing the malware.

3

What type of malware was being spread through the YouTube videos?

The malware was a password-stealing variety masquerading as cracked software.

4

Which popular software products were associated with this malware incident?

The affected software products included Google YouTube, Adobe Photoshop, Image-Line FL Studio, and Roblox.

5

Who reported the discovery of this malware distribution network?

The Check Point researchers were responsible for uncovering the so-called 'YouTube Ghost Network' malware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203