/
    Zpět na blog
    Security Sunday

    YouTube Ghost Network: How 3,000 Videos Stole Thousands of Passwords


    YouTube Ghost Network: How 3,000 Videos Stole Thousands of Passwords#### Imagine your child watching a YouTube tutorial on Roblox cheats with half a million views, thousands of likes, and 100% positive comments. They follow the video tutorial, download the file, turn off their antivirus, and lose all their passwords in the background.

    image

    Researchers from Check Point Research uncovered a massive campaign that exploited YouTube to distribute malware on an unprecedented scale. The network dubbed “YouTube Ghost Network” published over 3,000 malicious videos in recent months.

    The videos most commonly posed as tutorials for installing pirated software or cheats for popular games like Roblox. The target audience consisted primarily of younger users who often underestimate risks and are easily persuaded to disable antivirus protection. The key lure was high engagement — hundreds of thousands of views, positive comments, and “likes” that reinforced the content’s credibility.

    Behind this massive operation stands a group of attackers who divided their roles. Some handle video uploads, others manage community promotion, and still others artificially generate comments and reactions. The combination of hacked and newly created accounts created a robust infrastructure that was difficult to recognize even for YouTube’s security algorithms.

    Links in video descriptions often led to cloud storage services (Dropbox, Google Drive, MediaFire), where stealer-type malware was hosted — such as Lumma Stealer, Rhadamanthys, or RedLine. These tools specialize in stealing login credentials, sensitive data, or cryptocurrency wallets.

    The fundamental problem lies in users’ trust in legitimate platforms and engagement signals that are easily exploitable. When a video appears popular due to high view counts or positive reactions, many users lower their guard. Attackers actively exploit this psychological effect, thereby maximizing the campaign’s impact.

    73 Zero-Day Vulnerabilities: Hackers Breached Philips Hue and Galaxy S25

    Top security researchers participated in Pwn2Own Ireland 2025, where over three days (October 21–23) they earned a total of $1,024,750 for 73 successfully exploited zero-day vulnerabilities. Hacking occurred across eight categories: printers, NAS devices, messaging applications (WhatsApp), smart home devices, home networks, smartphones (iPhone 16, Galaxy S25, Pixel 9), and wearable technology (Ray-Ban Smart Glasses, Meta Quest 3/3S).

    Interesting moments included successful exploits on devices such as Philips Hue Bridge, Lexmark CX532adwe, Samsung Galaxy S25, Ubiquiti AI Pro, and QNAP TS-453E. Many attacks succeeded due to vulnerabilities such as path traversal, type confusion, hard-coded credentials, integer overflow, or flaws in authentication algorithms.

    This year, a record bounty of $1 million was announced for a zero-click exploit on WhatsApp, which was not publicly demonstrated because Team Z3 provided their research only to ZDI analysts and Meta engineers.

    All discovered vulnerabilities will be reported to manufacturers, who have 90 days to patch them before ZDI publishes them. The next Pwn2Own event will take place in January 2026 in Tokyo and will focus on the automotive sector — Tesla will be the main sponsor.

    Critical Vulnerabilities in TP-Link Omada Gateway

    TP-Link released patches for four vulnerabilities in Omada gateway devices commonly deployed in small business networks and households. Two critical flaws, CVE-2025–6542 and CVE-2025–7850 with a CVSS score of 9.3, garnered the most attention as they allow remote execution of arbitrary system commands.

    CVE-2025–6542 enables an attacker to control the device without requiring authentication. Through an unsecured administrative interface, a remote attacker can execute commands at the operating system level, modify configurations, or deploy malicious software.

    On the other hand, CVE-2025–7850 requires administrator access but allows command injection, for example, through WireGuard VPN settings. Researchers from Forescout also noted that this vulnerability arose due to an incomplete fix for the earlier vulnerability CVE-2024–21827. In some scenarios, this flaw can be exploited even without valid credentials.

    TP-Link published a list of affected models including ER8411, ER605, ER707-M2, ER7206, and others with recommendations to update firmware immediately.

    PolarEdge and GhostSocks: New Wave of Attacks on SMB Routers

    In recent months, the expansion of the PolarEdge botnet has caused alarm among security experts, as it specifically targets devices from popular brands like Cisco, ASUS, QNAP, and Synology. This malicious software exploits known vulnerabilities, such as CVE-2023–20118 in Cisco devices, to gain control over routers not only in corporate networks but increasingly in households as well. Infected devices are subsequently incorporated into an extensive botnet network that is rapidly spreading worldwide.

    PolarEdge is designed with emphasis on modularity and evading detection. The malware implements its own TLS server and binary communication protocol, utilizes techniques for masking running processes, and regularly checks its presence on the device. Another layer of protection is configuration data encryption, which significantly complicates analysts’ work in reverse engineering and detecting the threat in network traffic. Experts have already encountered more than two thousand unique IP addresses of infected devices.

    In addition to the PolarEdge botnet itself, malware designated as GhostSocks was also detected as part of this campaign. It transforms compromised routers into residential SOCKS5 proxy servers that are offered as a service on darknet forums.

    Worth mentioning is the vulnerability CVE-2023–20118 itself, which allows the botnet to remotely download and execute arbitrary code on vulnerable routers. This vulnerability was described back in 2023, but because the manufacturer announced end-of-life support for some devices, a significant number of easily exploitable devices remain in operation.

    © 2026 Patrik Žák. Všechna práva vyhrazena.