Cyber Security News

YouTube Creators Under Attack via Brand Collaborators Requests Using Clickflix Technique

A sophisticated phishing campaign dubbed the “Clickflix Technique” has emerged targeting YouTube content creators through seemingly legitimate brand collaboration requests.

This new attack vector exploits creators’ eagerness to secure sponsorship deals by disguising malware payloads as partnership documentation.

Cybercriminals initiate contact via email or social media, posing as marketing representatives from established brands offering lucrative deals that require the creator to review “campaign materials” hosted on compromised domains or cloud storage.

The attackers typically approach creators with subscriber counts between 10,000 and 500,000, carefully crafting messages that reference the creator’s content style and previous sponsorships to establish credibility.

Upon clicking the malicious links, creators are directed to professional-looking landing pages mimicking popular file-sharing services where they’re prompted to download what appears to be a PDF contract or campaign brief.

CloudSek researchers identified this campaign in early March 2025, noting that the malware employs a multi-stage infection process designed to evade traditional security solutions.

Mindmap of malware campaign (Source – Cloudsek)

Their analysis revealed that over 2,300 creators have been targeted across gaming, technology review, and lifestyle niches, with approximately 18% of targets successfully compromised.

The attack leverages social engineering principles combined with technical deception, often including time-sensitive offers to pressure creators into hasty decisions.

Victims report receiving customized messages referencing specific videos they’ve produced, indicating significant reconnaissance efforts by the threat actors prior to initiating contact.

Infection Mechanism Exploits JavaScript Obfuscation

The malware’s primary infection vector employs a sophisticated JavaScript downloader that executes when victims open what appears to be a standard HTML preview page.

Process Tree (Source – Cloudsek)

The initial payload utilizes multiple layers of obfuscation, with the final stage resembling this simplified example:-

const decoderKey = navigator.userAgent.slice(0,8);
eval(function(p,a,c,k,e,d){
  /* heavily obfuscated PowerShell downloader */  return p;
}('powershell -w hidden -e JGNsaWVudCA9...'))

This obfuscated code ultimately triggers a PowerShell command that downloads a stealer targeting browser data with particular emphasis on YouTube Studio credentials, Google authentication tokens, and cryptocurrency wallet information.

The malware establishes persistence through Windows Registry modifications and scheduled tasks with innocuous names like “GoogleUpdateTask” to avoid detection during routine system inspections.

The attack demonstrates the growing sophistication of targeted campaigns against content creators who increasingly represent valuable targets due to their monetization potential and access to engaged audience networks.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker

Hackers are turning ordinary searches and gaming videos into malware traps. A long-running campaign used…

31 minutes ago

Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process

Hackers are using a familiar Windows automation tool to hide AsyncRAT, a remote-access trojan, inside…

1 hour ago

NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected

The Dutch National Cyber Security Center (NCSC) has issued an urgent warning over two critical…

3 hours ago

Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories

This week's roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate…

5 hours ago

Critical Dell ObjectScale Vulnerabilities Allows Malicious Users to Compromise the Affected system

Dell Technologies released a security advisory about multiple vulnerabilities affecting Dell ObjectScale and Elastic Cloud…

18 hours ago

Revolut Data Breach Exposes Customers’ Passport Copies and Full Transaction Histories to Hackers

Revolut has disclosed a data-security incident in which sensitive customer information was released after the…

1 day ago