CL-CRI-1171: Two-Year Pay-Per-Install Network Spread Malware via YouTube Gaming Channels and SEO Poisoning
Palo Alto Networks Unit 42 tracked a pay-per-install cluster, CL-CRI-1171, that used 11 YouTube gaming channels and SEO-poisoned trojanized installers to push a shared loader (10,000+ samples) delivering Insomnia RAT, ARKTunnel, Docro Hijacker, GCleaner and…
Palo Alto Networks Unit 42 is tracking CL-CRI-1171, a cybercrime cluster operating a pay-per-install (PPI) / infection-as-a-service marketplace that has delivered multiple malware families for at least two years. The group abused at least eleven YouTube gaming channels with hundreds of thousands of followers, plus SEO poisoning promoting trojanized software such as a Bluetooth driver installer and WinDirStat, infecting gamers and corporate endpoints including critical infrastructure and government entities. A single shared loader — identified in GBHackers' coverage as OfferLoader, embedded in trojanized Inno Setup installers and delivering multiple payloads per infection — distributed Insomnia RAT, ARKTunnel, Docro Hijacker, and later GCleaner and Socks5Systemz between July 2025 and April 2026. More than 10,000 distinct loader samples and over 200 rotating C2 domains across the .xyz, .cfd, .space and .info TLDs were observed; per GBHackers, the infrastructure used gating filters that served broken links or decoy pages to scanners and researchers. Additional technical detail attributed to GBHackers: Insomnia RAT (Node.js and Python backdoors) disables Microsoft Defender and creates scheduled tasks masquerading as Windows components; ARKTunnel is a WebSocket-based RAT that uses least-significant-bit steganography to extract payloads from bitmap images; and Docro Hijacker is a Chrome browser hijacker that bypasses Chrome's HMAC-SHA256 Secure Preferences integrity check. YouTube terminated the malicious channels after Unit 42 notified the platform.
- Cluster tracked as CL-CRI-1171 by Palo Alto Networks Unit 42; operates a pay-per-install (PPI) / infection-as-a-service marketplace active for at least two years.
- Distribution used at least 11 YouTube gaming channels with hundreds of thousands of followers/subscribers, plus SEO poisoning promoting trojanized software including a Bluetooth driver installer and WinDirStat.
- A single shared loader delivered multiple payloads per infection; GBHackers identifies it as OfferLoader embedded in trojanized Inno Setup installers.
- Payloads delivered between July 2025 and April 2026: Insomnia RAT, ARKTunnel, Docro Hijacker, GCleaner and Socks5Systemz.
- Over 10,000 distinct loader samples and 200+ rotating C2 domains across .xyz, .cfd, .space and .info TLDs were identified.
- Per GBHackers: Insomnia RAT (Node.js and Python backdoors) disables Microsoft Defender and creates scheduled tasks masquerading as Windows components.
- Per GBHackers: ARKTunnel is a WebSocket-based RAT using least-significant-bit steganography to extract payloads from bitmap images; Docro Hijacker bypasses Chrome's HMAC-SHA256 Secure Preferences integrity check.
- Per GBHackers: C2 infrastructure used gating filters that served broken links or decoy pages to scanners and researchers.
Coverage timelineoldest first · each row is one article
- · 6d agoUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Palo Alto Unit 42· 47
Unit 42 exposes CL-CRI-1171, a pay-per-install network spreading malware like Insomnia RAT via YouTube channels and SEO poisoning for over two years.
- · 4d agoResearchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
GBHackers· 66
Unit 42 uncovers CL-CRI-1171, a two-year pay-per-install campaign distributing 10,000+ OfferLoader samples via YouTube and SEO poisoning.