How it works

Someone posing as a game publisher's partnerships team, often Gaijin or the War Thunder creator program, sends a warm first email about a paid deal and attaches an archive: a .zip, .rar, or .7z. Just below it they write the key, something like "password: WT2025". The archive holds the real payload, usually an information stealer built to scrape your browser for the YouTube session cookie and your Google login.

The encryption is the point. While the file sits in your inbox, your mail provider's scanner and your own antivirus cannot see inside an archive they do not have the password for. You supply the key by extracting it yourself, which moves the danger from the sender to you. The moment you unzip and run what is inside, the stealer copies your session cookies and the attacker signs into Studio as you. A live session cookie skips both the password prompt and 2FA, so a strong password does not save the channel here.

The tell-tale signals

What to do

Do not extract the archive. Real briefs arrive as a plain PDF or a link on the brand's own domain, never as an encrypted archive with the password sitting beside it. Verify the deal through Gaijin's published partnerships contact, not the address that mailed you. If you already extracted and ran the contents, treat your Google account as compromised: from a separate clean device, change your Google password, sign out of all sessions, revoke third-party app access, and check YouTube channel permissions and Studio for managers you did not add. Keep the email as evidence and report the sender.