Threat reportPhishingTL-2026-3048

Fake brand-sponsorship and "channel verification" phishing campaign targets YouTube creators (Hollyland, Nike, Spotify impersonation)

mediumACTIVE

Fake brand-sponsorship and "channel verification" phishing (TL-2026-3048), also tracked as MATCHY, is a medium-severity phishing campaign, first published 2026-10-08. It has no confirmed attribution, affects Google Google Account / YouTube channels (credential and OTP phishing, maps to 10 MITRE ATT&CK techniques (T1056.003, T1078.004, T1098), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-3048

Threat ID
TL-2026-3048
Also known as
MATCHY, SCOUTY, TUBIVE, Creoventura
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
news - media, content-creators, social-media
Target regions
Global, peru, japan
Detection rules
9
Indicators of compromise
15

How Fake brand-sponsorship and "channel verification" phishing works

ESET reports a modular phishing scheme in which scammers send personalized sponsorship emails impersonating brands (Hollyland; Nike and Spotify variants), then steer YouTube creators to a fake collaboration platform that prompts a Google sign-in framed as channel ownership verification. The captured password and one-time code give attackers access to Gmail, Drive and the YouTube channel; in one reported case the victim's recovery phone and email were replaced and new backup codes generated.

Scammers send personalized emails that reference the target creator's own videos and pose as a brand partnerships team. The primary lure impersonates Hollyland: a sender calling themselves "Brandi" from a supposed Creator Partnerships team offers a paid collaboration including a device and a long-term deal, from a sender domain unrelated to Hollyland. Nike and Spotify variants use near-identical sites. After the creator replies with their rates, the sender directs them to a fake collaboration platform to verify stats, the agreement and payment.

The platform is polished: it shows campaign metrics, major-company logos, an income calculator, and contract, joint-project and payment features. The creator submits their YouTube channel URL and the site pulls public channel data to personalize the experience. It then redirects to a Google sign-in step framed as verifying channel ownership. ESET describes an imposter login page that captures the password and the one-time code. The sites' social media icons link only to generic homepages, and the sites are built to pass a cursory inspection.

The operation is modular. Multiple branded fronts (MATCHY at joinmatchy[.]com and matchyjoin[.]com, SCOUTY at joinscouty[.]com, TUBIVE at mytubive[.]com) share favicons, meta descriptions and portions of source code, and domains and names were rotated repeatedly between June and August 2026. A further front, a fake agency called Creoventura (creoventura[.]com), was registered in August 2026 through Namecheap for one year with hidden ownership; it falsely lists AndaSeat, Hollyland and Maono as clients, and AndaSeat publicly stated it has no affiliation. The Creoventura name does not match the UK register entry ("Creoventure"), whose registered activities are IT and consultancy rather than influencer marketing.

Impact: access to the victim's Google account, including Gmail, Drive and the YouTube channel. One victim publicly reported that the attackers replaced her phone number and recovery email and generated new backup codes, locking her out. Victims have been reported in Peru (a journalist), Japan (YouTube support thread) and among English-speaking creators (Reddit). ESET names no actor, no kit and no malware, and does not state whether the capture is a live reverse proxy. Severity MEDIUM is an analyst judgment, not stated in the sources.

MITRE ATT&CK techniques used in TL-2026-3048

Credential Access

T1056.003 Web Portal Capture; T1111 Multi-Factor Authentication Interception

Initial Access

T1078.004 Cloud Accounts; T1566.002 Spearphishing Link

Persistence

T1098 Account Manipulation

Execution

T1204.001 Malicious Link

Impact

T1531 Account Access Removal

Resource Development

T1583.001 Domains

Reconnaissance

T1598.003 Spearphishing Link

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Fake brand-sponsorship and "channel verification" phishing

  • Google — Google Account / YouTube channels (credential and OTP phishing target)

Remediation for Fake brand-sponsorship and "channel verification" phishing

Immediate actions

  • Block the listed domains (joinmatchy.com, matchyjoin.com, joinscouty.com, mytubive.com, creoventura.com) at DNS, proxy and mail gateways
  • If a creator entered credentials on any of these sites, run Google Security Checkup, remove unrecognized devices, apps, recovery info and third-party connections, and change the password
  • If locked out or recovery details were changed, use Google's official account recovery page; revert attacker changes once access is restored

Workarounds

  • Do not return to the suspicious site to re-enter credentials
  • Review the permissions requested by any app or service and deny anything unneeded

Longer-term hardening

  • Enable 2-Step Verification with passkeys or security keys rather than SMS/OTP codes, which this campaign captures
  • Train creators to verify sponsorship offers through the brand's official contact details, not by replying to the email
  • Confirm any Google sign-in page is on accounts.google.com before entering credentials

Timeline of Fake brand-sponsorship and "channel verification" phishing

  • Month-level date: ESET reports the campaign's domains and names were rotated repeatedly between June and August 2026.
  • Month-level date (approximate, undated in source): creators begin reporting 'Paid collaboration opportunity' emails from a fake Hollyland 'Creator Partnerships' persona ('Brandi'), referencing their own videos; reports surface from Peru (journalist), Japan (YouTube Help thread), Reddit r/PartneredYoutube and a Facebook creator group.
  • Month-level date: creoventura[.]com, the fake influencer-marketing agency front, registered through Namecheap for one year with hidden ownership.
  • Month-level date: end of the June-August window in which ESET observed domain and brand-name rotation (MATCHY, SCOUTY, TUBIVE variants).
  • Undated in sources (placed at month level before the 7 Oct ESET report): Hollyland publicly warns about the campaign on Instagram and AndaSeat posts on X that Creoventura is NOT affiliated with it.
  • ESET WeLiveSecurity publishes 'Inside a brand deal scam targeting YouTube creators', documenting the Hollyland, Nike and Spotify lures and the channel-verification Google sign-in capture.
  • Help Net Security covers the ESET research, adding the Creoventura front and AndaSeat's disclaimer of affiliation.

Sources cited for Fake brand-sponsorship and "channel verification" phishing

Detection coverage for TL-2026-3048

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3048 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats