An inventive YouTube moderator phishing scam

Stu Sjouwerman | Jan 2, 2018

Full marks for inventiveness

YouTube_Phishing_Scam

If you have a YouTube channel, and have had your fill of sifting through the vile torrent of abusive comments left on your video masterpieces, you can invite other people to moderate them.

It's a simple process that requires you just to enter the URL of another YouTube channel - and a message will automagically be sent to its owner.

So far, so harmless.

But it turns out that it's a feature that can be used for spear-phishing by spammers and scammers. Spammers want to get their unwanted messages into your email inbox, but as anti-spam filters have improved their chances of getting your eyeballs on their messages have reduced over the years.

This inventive spammer has used the "Add comment moderator" feature of YouTube to send me a scam message, claiming that I have "win" (sic) an Apple iPhone X.

Oh, and yes, YouTube has now removed the offending channel.

If you receive similar messages, report them and the channel to YouTube so the user can be banned.

Tip 'o The Hat to Graham Cluley

 

Topics: Spear Phishing

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.