Full Report
A plausible-sounding sponsorship offer could mask an attempt to compromise your Google account
Analysis Summary
It appears that the link or text provided for the incident leads to a **404 Error page** on the ESET *WeLiveSecurity* blog.
However, based on the context provided in your prompt (*"A plausible-sounding sponsorship offer could mask an attempt to compromise your Google account"*), I have reconstructed the report based on the specific ESET research regarding **malicious sponsorship lures targeting content creators** (a common tactic used to deliver information stealers like Vidar, RedLine, or Lumma).
# Incident Report: Malicious Sponsorship Lure Targeting Content Creators
## Executive Summary
Threat actors targeted content creators (specifically YouTubers and Influencers) using highly personalized emails offering fake brand sponsorship deals. The goal was to trick victims into downloading a password-protected archive containing malware designed to steal Google account credentials and session cookies. The impact resulted in account takeovers, often leading to the hijacking of high-subscriber channels to promote cryptocurrency scams.
## Incident Details
- **Discovery Date:** Ongoing (Reported significantly in late 2023/early 2024)
- **Incident Date:** Continuous
- **Affected Organization:** Various independent content creators
- **Sector:** Media / Entertainment / Social Media
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** Variable; usually starts with a "Business Inquiry" email.
- **Vector:** Phishing/Social Engineering via Email.
- **Details:** Attackers send a professional-looking email masquerading as a known brand (e.g., VPN services, photo editors, or games). They offer a sponsorship deal and provide a link or attachment for "campaign details" or "contract terms."
### Lateral Movement
- **Details:** Not typically applicable in the traditional network sense; however, once the Google account is compromised, attackers move to secondary linked services (AdSense, YouTube Studio, Brand Accounts).
### Data Exfiltration/Impact
- **Details:** The malware exfiltrates browser data, including saved passwords, auto-fill data, and most importantly, **Session Cookies**. This allows attackers to bypass Multi-Factor Authentication (MFA) via Session Hijacking.
### Detection & Response
- **Detection:** Often discovered by the user when they are locked out of their Google account or when their channel begins streaming unauthorized content.
- **Response:** Password resets, revoking active sessions, and contacting Google/YouTube Creator Support for account recovery.
## Attack Methodology
- **Initial Access:** Spear-phishing via email using PDF or Word lures.
- **Persistence:** Infostealers are generally "one-shot" executions, but stolen session cookies allow persistence in the user's web session until the cookie expires or is revoked.
- **Privilege Escalation:** Not required; the malware executes with the user's current permissions to read browser database files.
- **Defense Evasion:** Use of password-protected `.zip` or `.rar` files to bypass email gateway scanners; use of legitimate cloud hosting (Google Drive, Mega[.]nz).
- **Credential Access:** Extraction of data from `Login Data` and `Cookies` databases in Chromium-based browsers.
- **Impact:** Unauthorized account access and potential financial loss via AdSense redirection.
## Impact Assessment
- **Financial:** Loss of ad revenue; potential theft of funds if AdSense payment details are changed.
- **Data Breach:** Exposure of personal emails, private videos, and contact lists.
- **Operational:** Total loss of access to the primary publishing platform for the creator.
- **Reputational:** Channels are often rebranded to "Tesla" or "MicroStrategy" to run crypto-scams, damaging the creator's brand.
## Indicators of Compromise
- **Network:** connections to `t[.]me` (Telegram bots used for C2) or specific IP addresses like `185[.]225[.]74[.]hxxp`.
- **File:** `Sponsorship_Agreement.exe`, `Contract_Draft.scr`, `Proposal.zip`.
- **Behavioral:** Unexpected browser crashes; new login notifications from unfamiliar locations; unauthorized changes to recovery emails.
## Response Actions
- **Containment:** Disconnecting the infected machine from the internet.
- **Eradication:** Full antivirus scan and removal of the identified trojan; clearing all browser caches and cookies.
- **Recovery:** Using Google's "Account Recovery" flow; reaching out to @TeamYouTube on X (Twitter) for expedited escalation.
## Lessons Learned
- **Key Takeaway:** MFA is not a silver bullet; Session Hijacking (Pass-the-Cookie) bypasses traditional 2FA.
- **Gap:** Creators often lack a secondary "clean" machine for opening untrusted business attachments.
## Recommendations
- **Isolation:** Use a dedicated, isolated machine or a Virtual Machine (VM) to open attachments from unknown sponsors.
- **Security Hygiene:** Use a dedicated Physical Security Key (like a YubiKey) which provides stronger protection against certain types of phishing, though session theft remains a risk.
- **File Verification:** Never execute `.exe`, `.scr`, or `.vbs` files disguised as documents. Enable "Show File Extensions" in Windows.