Massive Phishing Campaign Targets YouTube Creators, Hijacks Channels Using Fake Copyright Strikes

Cybersecurity threats are evolving rapidly, and content creators are now among the prime targets. A recent phishing campaign specifically targeting YouTube creators demonstrates just how advanced and dangerous these attacks have become. This is not your typical spam email scam—it’s a highly engineered operation designed to take over entire Google accounts and monetize stolen audiences.

The Anatomy of the Attack

The campaign begins with a convincing lure: a fake copyright strike notification. For YouTube creators, copyright violations are a serious concern, often tied directly to channel suspension or demonetization. Attackers exploit this fear by presenting a professional-looking interface that mimics YouTube’s branding.

The phishing site—such as dmca-notification[.]info—invites users to check their copyright status by entering their channel details. What makes this attack particularly dangerous is its personalization. The site dynamically pulls real data from YouTube, including the creator’s profile picture, subscriber count, and latest video. This creates a highly believable scenario that lowers suspicion and increases the likelihood of user interaction.

Once the user engages, the page generates a fake copyright complaint tied to their latest upload. It even includes dynamically created timestamps, making the claim appear authentic. The user is then pressured with warnings such as “Respond within three days or face enforcement actions,” pushing them toward immediate action.

The Credential Harvesting Mechanism

The attack escalates when the victim clicks on the “Login via Google” button. Instead of redirecting to a legitimate Google sign-in page, the site loads a fake login interface using a technique known as a Browser-in-the-Browser attack.

This fake window mimics a real browser pop-up, complete with a realistic URL and interface design. However, it is entirely rendered using HTML and CSS, meaning all entered credentials are directly captured by the attacker. The actual browser address bar still points to the phishing domain, but many users fail to notice this subtle detail.

To make detection harder, attackers use rotating domains for credential harvesting. If one domain is taken down, another is quickly deployed. This dynamic infrastructure ensures the campaign remains operational and resilient.

Phishing-as-a-Service: A New Threat Model

One of the most alarming aspects of this campaign is its scalability. The phishing kit operates as a shared platform, allowing multiple attackers to run independent campaigns. Each affiliate is assigned a unique tracking ID, enabling centralized monitoring of victims and attack performance.

This “phishing-as-a-service” model lowers the barrier to entry for cybercriminals and significantly increases the scale of attacks. It also explains the widespread targeting of creators across different regions and niches.

Why YouTube Channels Are Valuable Targets

A YouTube channel is more than just content—it is a digital business. It generates revenue through ads, sponsorships, and merchandise. More importantly, it is linked to a Google account that includes Gmail, Google Drive, and payment systems.

Once compromised, attackers can quickly rebrand the channel—often impersonating cryptocurrency companies—and use the existing audience to run scams via livestreams. The original creator is locked out, while their subscribers are exposed to fraudulent schemes.

Interestingly, the phishing kit avoids targeting channels with over three million subscribers. This appears to be a strategic decision to avoid drawing attention from high-profile creators who may have stronger security measures or direct support from YouTube.

IOCs

  • dmca-notification[.]info (primary phishing site)
  • blacklivesmattergood4[.]com (credential harvesting domain — active at time of capture)
  • dopozj[.]net (associated infrastructure — 502 at time of capture)
  • ec40pr[.]net (associated infrastructure — 502 at time of capture)
  • xddlov[.]net (associated infrastructure — 502 at time of capture)

How to Protect Yourself

Prevention is critical. Here are key steps creators should follow:

  • Only check copyright strikes through YouTube Studio
  • Avoid clicking login links from emails or external websites
  • Always verify the browser’s address bar before entering credentials
  • Be cautious of urgency-driven messages
  • Test suspicious pop-ups by dragging or minimizing them

If you suspect compromise:

  • Change your Google password immediately
  • Revoke active sessions
  • Review your YouTube channel for unauthorized activity

Our Opinion on This Campaign

This phishing campaign represents a significant shift in cybercrime sophistication. It highlights how attackers are no longer relying on generic tactics but are investing in highly targeted, psychologically engineered attacks. The use of real-time data personalization, combined with professional UI replication, shows a deep understanding of user behavior and trust patterns.

What stands out most is the operational maturity of this campaign. The affiliate-based structure and rotating infrastructure indicate that phishing is no longer an isolated activity—it is an organized ecosystem. This industrialization of cybercrime is concerning because it allows even low-skilled attackers to execute high-impact operations.

Additionally, the deliberate avoidance of large channels suggests strategic thinking. Attackers are optimizing for success while minimizing exposure, which reflects a business-like approach to cybercrime.

From a broader perspective, this case underscores the urgent need for stronger user education and platform-level safeguards. While technical defenses are improving, human factors remain the weakest link. Platforms like YouTube and Google must continue investing in proactive detection and user awareness initiatives.

Ultimately, creators must recognize that their digital assets are valuable and treat security as a priority, not an afterthought.