HackproofHacks
Research 11 min read

Cybercriminals Target YouTube to Spread Malware: How the Scam Works

Attackers are using YouTube videos, cracked software lures and hijacked channels to spread information-stealing malware. Here is how the scheme works and how to stay safe.

Hassan Ansari

Hassan Ansari

· Updated Jul 22, 2026
A research card showing a fake YouTube tutorial luring a viewer to a malicious download in the description

Cybercriminals Target YouTube to Spread Malware

YouTube is one of the most trusted places on the internet. People go there to learn how to do things, to fix problems, and to get software working, which is exactly why criminals have made it a hunting ground. By dressing up malware as the helpful free download you were already looking for, attackers turn the platform’s trust and reach into a highly effective malware distribution channel.

This scheme has become common enough that everyone should understand how it works, both to avoid falling for it and to recognise it when it targets friends and family. So let me break down the anatomy of these campaigns, the malware they deliver, and the simple habits that keep you out of the trap.

The lure: free things that cost you everything

The whole scam is built on a very old form of bait, the promise of something valuable for nothing. The videos almost always offer one of a few things. Cracked versions of expensive paid software, so you get the professional tool without paying. Game cheats, hacks, or mod menus, so you gain an unfair advantage. Or activators and key generators that claim to unlock premium features for free.

These lures work because they target people who are already looking for exactly this and who have, in a small way, already decided to cut a corner. Someone searching for a free version of costly software is primed to click, to trust, and to follow instructions, because they want the thing to work. That psychological state, wanting something enough to overlook the warning signs, is what the attacker is really exploiting. The software is just the wrapper.

The actual delivery is simple. The video shows off the supposed software and points you to a download link in the description or a pinned comment. That link does not lead to the promised program. It leads to malware, sometimes bundled with a non-working decoy of the real thing so the victim does not immediately realise what happened.

The trick that gives it away: disable your antivirus

There is one step in these fake tutorials that, once you know it, becomes a dead giveaway. At some point the video or the instructions will tell you to turn off your antivirus before running the download.

They always have a plausible-sounding reason. They will say the crack triggers a false positive, that security software wrongly flags cracked programs, that this is a normal and necessary step to make it work. It sounds reasonable to someone who does not know better, and that is precisely the point. In reality, your antivirus is flagging the file because the file is malicious. The warning is correct. The attacker is simply talking you into removing the one thing standing between you and infection.

Internalise this single rule and you defeat a huge share of these attacks. Any download that instructs you to disable your security software is malicious, full stop. There is no legitimate free software that needs you to blind your own defences before installing it.

The credibility problem, and how they solve it

A brand new channel with no subscribers posting a suspicious download link is easy to distrust. Attackers know this, so they work hard to look legitimate, and their methods here are genuinely clever.

One approach is volume. They flood the platform with large numbers of videos across many throwaway accounts, so that no matter what someone searches for, one of their videos is likely to appear. Even if most get taken down, enough survive long enough to catch victims, and the sheer quantity lends a false sense of normalcy.

The more insidious approach is hijacking. Attackers take over established, legitimate YouTube channels that already have real subscribers and a history of genuine content, then repurpose them to push the malicious videos. To a viewer, a download promoted by a channel with a large, real following and years of history feels trustworthy. That borrowed credibility dramatically increases how many people click.

And here is the dark elegance of it. As you will see next, the malware they spread is exactly the kind of tool used to steal the credentials needed to hijack these channels in the first place. The scheme feeds itself.

The payload: information stealers

So what are you actually infected with? The overwhelmingly common payload in these campaigns is a category of malware known as information stealers, or infostealers, with families like Lumma, RedLine, and Vidar repeatedly showing up in reporting.

Their job is fast and brutal. The moment an infostealer runs on your machine, it sweeps through your system harvesting everything of value. That means the passwords saved in your browser, your autofill data, your cryptocurrency wallets, and critically, your session cookies. It bundles all of this up and sends it straight to the attackers, often within seconds, and then it may quietly delete itself. Many victims never notice anything happened until accounts start getting taken over.

Those stolen session cookies deserve special attention, because they are the crown jewels. A session cookie is what keeps you logged into a site without re-entering your password. If an attacker steals a valid session cookie, they can often import it and be logged in as you without ever needing your password, and in many cases without triggering multi-factor authentication, because the session is already authenticated. This is exactly how a victim’s own YouTube and Google accounts get taken over and turned into the next hijacked channel. The circle closes.

Part of a bigger poisoning of search and social

It would be comforting to think this is a YouTube-specific problem, but the video platform is really just one front in a wider campaign to poison the places people go to find software and answers. Understanding that broader picture helps you stay alert everywhere, not only on YouTube.

The same criminals who abuse video also abuse search. A technique often called search poisoning or malvertising involves getting fake download sites to rank highly in search results or appear as paid adverts, so that someone searching for a popular free program clicks a convincing counterfeit and downloads malware instead of the real thing. The fake sites look nearly identical to the genuine ones, which is exactly the point. Whether the victim arrived from a video description or a top search result, the destination and the outcome are the same.

Social platforms and messaging apps carry their own versions, with fake giveaways, cracked-app channels, and too-good-to-be-true offers spreading the same infostealers. And the arrival of easy content generation has made all of this cheaper to produce at scale, since convincing-looking tutorial videos and step-by-step guides can be churned out quickly to blanket every search term a victim might try. The comments beneath these videos are often seeded with fake enthusiasm, a chorus of accounts insisting the download worked perfectly and is completely safe, manufactured to quiet the doubts of anyone hesitating.

The unifying lesson is that the platform is not really the threat. The threat is the promise of getting something valuable for free combined with a small nudge to lower your guard, and that combination shows up on video, in search, in adverts, and in your messages. Learn to recognise the shape of the trick and you are protected wherever it appears.

If you make videos, protect your channel

There is a second audience for this warning, the creators whose channels get stolen and weaponised. Remember the self-feeding loop from earlier. The infostealers spread through these videos are the very tools used to hijack established channels, by lifting the creator’s saved logins and session cookies. If you run a channel of any size, you are a target, because your credibility is a resource criminals want to steal.

Protecting yourself is the same hygiene that protects everyone, applied with a little more urgency. Never store the passwords for your creator and email accounts in a way that malware can simply scoop up, and be extremely cautious about what you download and run on the machine you use to manage your channel. Turn on the strongest multi-factor authentication available, ideally a hardware or app-based method rather than text messages, since stolen session cookies are the main way attackers slip past weaker protection. And be suspicious of unexpected files sent to you as a creator, since attackers often pose as brands offering sponsorship deals, sending a malicious file dressed up as a contract or a product to review. A single careless download can hand over an audience you spent years building, so treat the account that controls your channel as the valuable asset it is.

How to protect yourself

The reassuring part is that defending against this does not require technical expertise. It requires a handful of habits and a healthy dose of suspicion.

Distrust free versions of paid things. The entire scheme runs on the lure of getting something for nothing. Cracks, keygens, cheats, and activators are among the most reliable malware carriers on the internet, and always have been. If a video offers you expensive software or premium features for free, assume it is bait until strongly proven otherwise.

Only download from official sources. Software should come from the developer’s official website or a legitimate app store, never from a link in a video description or a comment. A description link to some unfamiliar file host is a serious red flag on its own.

Never disable your security to install something. As covered above, this instruction is the clearest signal you are being attacked. Treat it as an immediate stop sign.

Watch for the small tells. Archives that require a password to open, generic or oddly enthusiastic comments that all sound the same, brand new accounts, and download links pointing to obscure hosts are all warning signs. Any one of them should give you pause, and several together should turn you away entirely.

Lock down your accounts in advance. Turn on multi-factor authentication everywhere, so that even a stolen password is not enough to hijack you. Be aware that stolen session cookies can sometimes bypass this, which is all the more reason to avoid infection in the first place, but multi-factor authentication still closes off a large portion of account takeover attempts.

If you think you have been hit

If you downloaded something from one of these links and ran it, act quickly and assume the worst, because infostealers move fast. Disconnect the device from the internet, run a reputable security scan, and then, from a different clean device, change the passwords on your important accounts, starting with your email since it is the key to everything else. Enable multi-factor authentication anywhere it is not already on, and log out all active sessions where a service allows it, which helps invalidate any stolen cookies. If you had banking or cryptocurrency accounts saved on that machine, treat them as being at immediate risk and secure them first.

It is also worth talking to the people in your life who are most likely to fall for this, because awareness spreads protection further than any single tool. Younger family members chasing game cheats, and anyone hunting for free versions of expensive software, are squarely in the target audience for these campaigns. A short conversation about the disable-your-antivirus red flag, and the simple rule that free versions of paid things are usually bait, can save someone you care about from handing over their passwords and savings. Security is partly technical and partly cultural, and the culture spreads one honest conversation at a time.

The broader lesson is one that applies far beyond YouTube. Attackers do not need to break through your defences when they can convince you to open the door yourself, and a trusted platform is the perfect place to do the convincing. The best protection is a simple, slightly cynical instinct. When something online offers you exactly what you wanted for free and asks you to lower your guard to get it, that is not luck. That is the trap.

#malware #youtube #infostealer #social engineering #cracked software #threat intelligence
Free newsletter

Liked this? I write one like it every week.

One practical security lesson in your inbox each week, explained the same simple way. Join 10,000+ readers. Unsubscribe anytime.

From the article

Need a security assessment?

HackproofHacks provides web application and API penetration testing — using the same techniques covered in this article, with your explicit authorisation.

Book a free scoping call

More on Research.

All articles →
FAQ

Questions about this topic.

How do cybercriminals use YouTube to spread malware?

They post videos that promise something desirable for free, such as cracked paid software, game cheats, or activation tools, and place a download link in the description or pinned comment. The link leads to information-stealing malware rather than the promised program. To look credible they often hijack established channels with real subscribers, or flood the platform with many videos, and pad the fake software with instructions to disable antivirus before running it.

What kind of malware is spread through YouTube?

The most common payload is information-stealing malware, often called infostealers, with families like Lumma, RedLine, and Vidar frequently reported. Once run, these programs harvest saved passwords, browser cookies, autofill data, cryptocurrency wallets, and other sensitive information from the victim's computer, then send it to the attackers. Stolen session cookies are especially prized because they can let attackers bypass passwords and log in as the victim.

Why do attackers tell victims to disable their antivirus?

Because their malware would otherwise be detected and blocked. The fake tutorials frame turning off antivirus as a normal step needed to make the cracked software work, claiming the security warning is a false positive caused by the crack. In reality the warning is correct and the victim is being talked into removing the one protection standing between them and infection. Any download that insists you disable security should be treated as malicious.

How do attackers hijack legitimate YouTube channels?

Often through the very infostealers described here. By stealing a creator's saved credentials and session cookies, attackers can take over their Google and YouTube accounts, then repurpose the established channel, with its existing subscribers and credibility, to push more malicious videos. This creates a self-feeding cycle where each compromised channel helps infect new victims, some of whom become the next hijacked channels.

How can I tell if a YouTube download is malicious?

Be suspicious of anything offering paid software, games, or premium features for free, especially cracks, keygens, cheats, and activators, which are classic malware lures. Warning signs include links to unofficial file hosts, passwords required to open the archive, instructions to disable your antivirus, and comments that seem generic or artificially positive. When in doubt, only download software from the official source and never from a video description.

What should I do if I downloaded malware from a YouTube link?

Assume your saved passwords and session data are compromised. Disconnect the device from the internet, run a reputable security scan, and from a clean device change the passwords for your important accounts, especially email, banking, and anything with saved logins. Enable multi-factor authentication everywhere, and log out all active sessions where possible to invalidate stolen cookies. If financial or cryptocurrency accounts were saved on the machine, treat them as at immediate risk.