{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "YouTube creator and corporate social media accounts are high-value targets for brand impersonation and scam distribution; hunting for these hijacking attempts early prevents permanent account loss and reputation damage."
      },
      "name": "YouTube Sponsorship Scam Redirection and Harvesting",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1566.002",
        "attack.t1528",
        "attack.t1098",
        "attack.t1190",
        "credential access",
        "initial access",
        "persistence"
      ],
      "related": [
        {
          "hunt": "spearphishing-outreach-campaigns",
          "reason": "This hunt starts at the link click; hunting for the initial email arrival requires email security Gateway logs which are handled in the spearphishing series.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "web": {
          "name": "Web server / proxy logs",
          "category": "siem",
          "telemetry": [
            "network"
          ]
        },
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        },
        "identity": {
          "name": "Identity / sign-in telemetry",
          "category": "identity",
          "telemetry": [
            "identity"
          ]
        }
      },
      "analysis": "A single rule could alert on the domain, but this hunt correlates the initial endpoint traffic with subsequent identity-plane modifications (recovery changes) to confirm a successful hijacking, providing the context an analyst needs to move straight to containment.",
      "coverage": [
        {
          "stage": "malicious-link-redirection",
          "steps": [
            "lead-web-traffic"
          ],
          "status": "covered"
        },
        {
          "stage": "credential-token-harvesting",
          "steps": [
            "google-auth-anomalies"
          ],
          "status": "covered"
        },
        {
          "stage": "account-recovery-manipulation",
          "steps": [
            "cloud-recovery-modification"
          ],
          "status": "covered"
        },
        {
          "stage": "spearphishing-outreach",
          "reason": "Not examined by this hunt; belongs to a separate hunt.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Spearphishing Email Outreach",
            "slug": "spearphishing-outreach",
            "tactic": "initial-access",
            "techniques": [
              "T1566.001"
            ],
            "observables": [
              "Sender name: Brandi",
              "Sender domain: unrelated to Hollyland",
              "Subject lines: Paid collaboration opportunity",
              "Content: Specific references to target YouTube videos"
            ]
          },
          {
            "name": "Redirection to Fake Collaboration Platform",
            "slug": "malicious-link-redirection",
            "tactic": "initial-access",
            "techniques": [
              "T1566.002"
            ],
            "observables": [
              "joinmatchy.com",
              "joinmatchy.com/hollyland",
              "Domains containing scouty"
            ]
          },
          {
            "name": "Credential and OAuth Token Harvesting",
            "slug": "credential-token-harvesting",
            "tactic": "credential-access",
            "techniques": [
              "T1556",
              "T1528"
            ],
            "observables": [
              "Requests for YouTube channel management permissions",
              "Fake Google sign-in pages capturing MFA codes",
              "Income calculator metrics on phishing site"
            ]
          },
          {
            "name": "Account Recovery and Persistence",
            "slug": "account-recovery-manipulation",
            "tactic": "persistence",
            "techniques": [
              "T1098",
              "T1556.006"
            ],
            "observables": [
              "Replaced recovery phone number",
              "Replaced recovery email address",
              "Addition of new backup codes"
            ]
          }
        ],
        "summary": "A modular spearphishing campaign targets YouTube creators with personalized sponsorship offers for brands like Hollyland, Nike, and Spotify. Victims are lured to fake collaboration platforms where they are prompted to sign in with Google, leading to the theft of credentials or OAuth tokens and subsequent hijacking of the account via modified recovery settings."
      },
      "severity": "medium",
      "rationale": "Limit the initial HTTP lead to devices used by marketing, PR, and content creation staff, as they are the specific targets of sponsorship lures.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An adversary impersonating a brand redirects a content creator to a fraudulent collaboration platform to harvest Google credentials and then modifies account recovery details to maintain permanent access.",
      "parameters": {
        "lookback_days": {
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "brand_keywords": {
          "type": "list[string]",
          "default": [
            "/hollyland",
            "/nike",
            "/spotify",
            "/scouty",
            "/collab",
            "/sponsorship"
          ],
          "description": "URL path segments associated with the brand-impersonation campaign."
        },
        "phishing_domains": {
          "from": {
            "ref": "https://www.welivesecurity.com/en/social-media/brand-deal-scam-targeting-youtube-creators/",
            "kind": "article",
            "observed": "2026-10-07"
          },
          "type": "list[domain]",
          "default": [
            "joinmatchy.com"
          ],
          "description": "Known phishing infrastructure domains from the report."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.welivesecurity.com/en/social-media/brand-deal-scam-targeting-youtube-creators/",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.welivesecurity.com/en/social-media/brand-deal-scam-targeting-youtube-creators/",
          "name": "Inside a brand deal scam targeting YouTube creators"
        }
      ],
      "blind_spots": [
        {
          "id": "missing-http-visibility",
          "risk": "The hunt depends on the HTTP lead to open the identity queries; if traffic is not visible, the whole chain is missed.",
          "stage": "malicious-link-redirection",
          "question": "whether a user visited the fraudulent domain on their primary workstation",
          "requires": "EDR HTTP logging or Forward Proxy logs (hb_http_activity)"
        },
        {
          "id": "cloud-logging-disabled",
          "risk": "The persistence mechanism remains invisible, allowing the attacker to maintain access even if the user changes their password on their own.",
          "stage": "account-recovery-manipulation",
          "question": "whether the attacker modified recovery email or phone settings in the SaaS platform",
          "requires": "Google Workspace / GCP Audit Logs (hb_cloud_api_activity)"
        }
      ]
    },
    "name": "YouTube Sponsorship Scam Redirection and Harvesting",
    "description": "This hunt targets a modular phishing campaign that impersonates audiovisual and global brands to target social media influencers. The campaign uses personalized emails to drive victims to bogus sites like joinmatchy[.]com, where it lures them into 'signing in with Google' to verify channel metrics. Once inside, the attacker replaces recovery phone numbers and email addresses to lock out the legitimate owner. The hunt uses a gated flow, starting with a broad lead on web traffic to known phishing domains or brand-specific paths, then opening expensive identity-plane queries to find evidence of account hijacking and persistence."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "coverage": [
          {
            "stage": "malicious-link-redirection",
            "steps": [
              "lead-web-traffic"
            ],
            "status": "covered"
          },
          {
            "stage": "credential-token-harvesting",
            "steps": [
              "google-auth-anomalies"
            ],
            "status": "covered"
          },
          {
            "stage": "account-recovery-manipulation",
            "steps": [
              "cloud-recovery-modification"
            ],
            "status": "covered"
          },
          {
            "stage": "spearphishing-outreach",
            "reason": "Not examined by this hunt; belongs to a separate hunt.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An adversary impersonating a brand redirects a content creator to a fraudulent collaboration platform to harvest Google credentials and then modifies account recovery details to maintain permanent access.",
        "blind_spots": [
          {
            "id": "missing-http-visibility",
            "risk": "The hunt depends on the HTTP lead to open the identity queries; if traffic is not visible, the whole chain is missed.",
            "stage": "malicious-link-redirection",
            "question": "whether a user visited the fraudulent domain on their primary workstation",
            "requires": "EDR HTTP logging or Forward Proxy logs (hb_http_activity)"
          },
          {
            "id": "cloud-logging-disabled",
            "risk": "The persistence mechanism remains invisible, allowing the attacker to maintain access even if the user changes their password on their own.",
            "stage": "account-recovery-manipulation",
            "question": "whether the attacker modified recovery email or phone settings in the SaaS platform",
            "requires": "Google Workspace / GCP Audit Logs (hb_cloud_api_activity)"
          }
        ],
        "scoping_notes": "Limit the initial HTTP lead to devices used by marketing, PR, and content creation staff, as they are the specific targets of sponsorship lures.",
        "beyond_detection": "A single rule could alert on the domain, but this hunt correlates the initial endpoint traffic with subsequent identity-plane modifications (recovery changes) to confirm a successful hijacking, providing the context an analyst needs to move straight to containment."
      }
    },
    {
      "id": "lead-web-traffic",
      "type": "query",
      "label": "Web traffic to campaign domains or paths",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, COUNT(*) as request_count, MIN(time) as first_seen, MAX(time) as last_seen FROM hb_http_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR instr(',' || '{{brand_keywords}}' || ',', ',' || LOWER(url_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_hostname, url_path",
        "surface": "hb_http_activity",
        "description": "Identify initial visits to known phishing domains or URLs containing campaign-specific brand keywords.",
        "expected_signal": "A row showing a device visiting a known phishing domain or a brand-specific partnership path. Silence proves no monitored host visited these specific URLs in the window."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Web traffic to campaign domains or paths",
        "reads": [
          "device_hostname",
          "url_hostname",
          "url_path",
          "time"
        ],
        "source": "hb_http_activity",
        "target": "web",
        "content": "SELECT device_hostname, url_hostname, url_path, COUNT(*) as request_count, MIN(time) as first_seen, MAX(time) as last_seen FROM hb_http_activity WHERE (instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(url_hostname) || ',') > 0 OR instr(',' || '{{brand_keywords}}' || ',', ',' || LOWER(url_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, url_hostname, url_path",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A row showing a device visiting a known phishing domain or a brand-specific partnership path. Silence proves no monitored host visited these specific URLs in the window.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "url_hostname"
          ],
          "rare_below": 5
        },
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "evaluate-lead",
      "type": "analytic",
      "label": "Evaluate lead quality",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "lead-web-traffic"
        ],
        "objective": "Determine if the web traffic observed in lead-web-traffic is consistent with a content creator visiting a fraudulent sponsorship platform.",
        "description": "Decide if the observed traffic matches the phishing campaign profile.",
        "max_iterations": 3,
        "expected_signal": "A suspiciousness verdict per host.",
        "success_criteria": "A verdict citing specific host visits to the suspicious domains or paths."
      },
      "parents": [
        {
          "id": "lead-web-traffic"
        }
      ]
    },
    {
      "id": "gate-on-lead",
      "type": "checkpoint",
      "label": "Gate on lead traffic",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "The lead evaluation is suspicious or malicious for at least one host.",
        "condition": "The lead evaluation is suspicious or malicious for at least one host.",
        "blind_spot": "missing-http-visibility",
        "confidence": "high",
        "description": "Open expensive cloud and identity queries only when a suspicious redirection is confirmed.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "evaluate-lead"
        }
      ]
    },
    {
      "id": "google-auth-anomalies",
      "type": "query",
      "label": "Google authentication anomalies",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, status_detail, user_agent, time FROM hb_auth_signin WHERE provider = 'gcp' AND status_id = 2 AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_auth_signin",
        "description": "Identify authentication failures or unusual sign-ins in the Google environment following the web interaction.",
        "expected_signal": "Failed sign-in attempts that may represent MFA harvesting or brute force. Silence means no recorded Google sign-in failures occurred."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Google authentication anomalies",
        "reads": [
          "actor_user_name",
          "src_endpoint_ip",
          "status_detail",
          "time"
        ],
        "source": "hb_auth_signin",
        "target": "identity",
        "content": "SELECT actor_user_name, src_endpoint_ip, src_location_country, status_detail, user_agent, time FROM hb_auth_signin WHERE provider = 'gcp' AND status_id = 2 AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Failed sign-in attempts that may represent MFA harvesting or brute force. Silence means no recorded Google sign-in failures occurred.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "cloud-recovery-modification",
      "type": "query",
      "label": "Cloud account recovery modifications",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT actor_user_name, api_operation, api_service_name, target_user_name, status, time FROM hb_cloud_api_activity WHERE provider = 'gcp' AND (api_operation LIKE '%UpdateUser%' OR api_operation LIKE '%Recovery%' OR api_operation LIKE '%Password%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_cloud_api_activity",
        "description": "Detect changes to recovery information which indicates the attacker has successfully hijacked the account.",
        "expected_signal": "API calls modifying user attributes, recovery emails, or phone numbers. This is the durable indicator of a successful hijacking."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Cloud account recovery modifications",
        "reads": [
          "actor_user_name",
          "api_operation",
          "target_user_name",
          "time"
        ],
        "source": "hb_cloud_api_activity",
        "target": "endpoint",
        "content": "SELECT actor_user_name, api_operation, api_service_name, target_user_name, status, time FROM hb_cloud_api_activity WHERE provider = 'gcp' AND (api_operation LIKE '%UpdateUser%' OR api_operation LIKE '%Recovery%' OR api_operation LIKE '%Password%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "API calls modifying user attributes, recovery emails, or phone numbers. This is the durable indicator of a successful hijacking.",
        "verified": "dry-run",
        "verified_at": "2026-10-09"
      }
    },
    {
      "id": "triage-incident",
      "type": "analytic",
      "label": "Triage incident chain",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint",
          "identity",
          "web"
        ],
        "context": [
          "evaluate-lead",
          "google-auth-anomalies",
          "cloud-recovery-modification"
        ],
        "objective": "Determine if a user who visited the phishing domains subsequently experienced authentication failures or recovery information changes in their Google account.",
        "description": "Correlate the web traffic, authentication anomalies, and recovery changes into a single timeline.",
        "max_iterations": 6,
        "expected_signal": "A confirmed compromise timeline per host/user.",
        "success_criteria": "A detailed verdict citing the web visit, the authentication event, and the account change."
      },
      "parents": [
        {
          "id": "google-auth-anomalies",
          "kind": "merge"
        },
        {
          "id": "cloud-recovery-modification",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-triage",
      "type": "checkpoint",
      "label": "Route on triage",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "Triage confirms a successful hijack (web traffic followed by recovery modification) for at least one account.",
        "condition": "Triage confirms a successful hijack (web traffic followed by recovery modification) for at least one account.",
        "blind_spot": "cloud-logging-disabled",
        "confidence": "high",
        "description": "Direct confirmed hijackings to remediation and uncertain leads to review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-incident"
        }
      ]
    },
    {
      "id": "lock-and-secure-account",
      "type": "action",
      "label": "Lock and secure account",
      "config": {
        "target": "identity",
        "description": "Evict the attacker and prevent permanent loss of the account.",
        "instructions": "Force sign-out of all sessions, reset the user's password, and revert any recovery email or phone number changes to the known-good corporate standards.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-triage",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "manual-review",
      "type": "task",
      "label": "Manual analyst review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the nature of the partnership offer and update the hunt indicators.",
        "instructions": "Examine the email communications sent to the user. If a new domain or brand was used, update the parameters for the next hunt iteration and communicate the threat to the marketing and social media teams."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "default"
        },
        {
          "id": "gate-on-lead",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-triage",
          "branch": "default"
        },
        {
          "id": "route-on-triage",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-triage",
          "branch": "on_refutes"
        },
        {
          "id": "lock-and-secure-account"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize the hunt results.",
        "instructions": "Document the number of hits and the outcome of the remediations. If silence was observed, confirm that the HTTP and Cloud API sources are currently active."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_refutes"
        },
        {
          "id": "manual-review"
        }
      ]
    }
  ]
}