YouTubeTA is a designation for a likely single cybercriminal operator using the StealC malware-as-a-service ecosystem to conduct large-scale information theft and malware distribution. The actor is associated with campaigns throughout 2025 that used YouTube-themed StealC builds and abused the video platform to spread malware, primarily by promoting fake cracked versions of Adobe Photoshop and Adobe After Effects. Evidence indicates the actor likely hijacked older legitimate YouTube creator accounts using compromised credentials and then repurposed those channels to distribute malicious links, creating a self-reinforcing infection pipeline. Operational data tied to this actor showed more than 5,000 victim logs containing roughly 390,000 stolen passwords and over 30 million cookies. The actor also appears to have specifically prioritized access to YouTube creator accounts, including credentials associated with creator-management services, consistent with account takeover for further distribution. Observed victim activity and campaign identifiers support a distribution model centered on social engineering, including cracked-software lures and ClickFix-style fake CAPTCHA techniques. YouTubeTA operated as a StealC customer or affiliate rather than as the malware developer. Through StealC, the actor benefited from credential theft, session cookie theft, screenshot capture, and secondary payload delivery capabilities. The actor’s activity demonstrates credential theft, session hijacking, exfiltration, and initial-access tradecraft, with follow-on use of compromised accounts for persistence in distribution channels. Available fingerprinting and OPSEC evidence suggest an Eastern European operator, likely Russian-speaking, with a probable connection to Ukraine. This attribution remains limited to infrastructure-access observations rather than public legal attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A StealC customer/affiliate that distributes the stealer via YouTube-based lures advertising cracked software such as Adobe Photoshop and Adobe After Effects.
A StealC MaaS customer that distributes StealC via YouTube by promoting cracked software (e.g., Adobe Photoshop/After Effects), likely hijacking legitimate YouTube accounts to create a self-propagating distribution loop; also uses fake CAPTCHA lures to deliver the stealer.
A StealC operator involved in credential theft and cookie theft, apparently using compromised YouTube channels and stolen studio.youtube.com credentials to distribute StealC and expand malware distribution.
A StealC MaaS customer/operator running malware distribution campaigns via hijacked YouTube channels, using compromised credentials and malicious links to infect victims and steal credentials/cookies at scale.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.