If a sponsor asks you to download, install or "test" their software before the deal is signed and paid, treat it as an attack, not an offer. The pattern is documented: Google's Threat Analysis Group described attackers who "lure their target with fake collaboration opportunities (typically a demo for anti-virus software, VPN, music players, photo editing or online games), hijack their channel, then either sell it to the highest bidder or use it to broadcast cryptocurrency scams" (Google TAG).
What it looks like
It starts as an ordinary sponsorship email to the business address on your channel. The company introduces itself, names a product, and agrees to your rate quickly. Once you say yes, the "product" arrives: a download link, a file on a cloud drive, or a PDF with a link in it. Sometimes the archive is password-protected, which stops email scanners from looking inside.
Google's report counted at least 1,011 domains registered for this campaign and around 15,000 attacker accounts, and noted that some sites imitated real software companies. So a professional-looking website proves nothing.
Why it works
The file does not need your password. It copies the session cookies your browser already holds, which lets an attacker use your logged-in accounts, including ones protected by two-factor sign-in. Google calls this "pass-the-cookie". You can do everything right about passwords and still lose the channel.
Red flags
- The deal needs you to run their file before any contract or payment.
- The download is an archive with a password sent separately, or a link inside a PDF or doc.
- The brand is a software product you have never heard of, with a new-looking site.
- They agree to your fee without negotiating and push to move fast.
- The sender's address is on a free mailbox or a domain that does not match the brand's own site.
What to do
- Do not open the file. Real sponsors send a brief, a contract and a product key or store link, not an installer.
- Check the company through its own website and social accounts, found by searching, not through links in the email.
- If you already ran it: from a different, clean device, sign out of all sessions and change passwords on your email, channel and payment accounts, then scan the computer. Google's report recommends 2-Step Verification on the account behind your channel.
- Report the email and the sender, and add the domain to the scam registry so the next creator sees it.
Questions people ask
Can a real sponsor ask me to try their app?
Yes, but through an official app store or a download from the brand's verified website, after you have confirmed who they are, and never as a file emailed to you in an archive.
I have two-factor sign-in. Am I safe?
Not from this. Session-cookie theft reuses a sign-in that already happened, so the attacker does not need your code. Signing out of every session on a clean device is what cuts them off.
How do I check a suspicious sponsorship quickly?
Paste it into the free scam checker. It flags download requests, mismatched senders and the other signs above.
Related patterns
Fake "Etsy Support" in your inbox
A message warns your Etsy shop will be suspended unless you verify or scan a code. How to tell real Etsy messages from fakes, using Etsy's own rules.
How to spot itThe "task" job
Paid to like videos or rate products, then asked to deposit money to unlock your earnings? That is a task scam. How it works and what to do.
How to spot itThe buyer who wants to leave Etsy
A buyer wants to pay outside checkout, move to email, or has you scan a QR code to "confirm" the sale. Why each is a scam sign, per Etsy.
How to spot it