Palo Alto Networks Unit 42 identified CL-CRI-1171, a long-running pay-per-install operation that uses its custom OfferLoader malware to distribute payloads for separate criminal operators. The group lures victims through SEO-poisoned fake software-download sites and at least 11 gaming-focused YouTube channels offering trojanized installers. The search-result campaign has affected corporate, government, and critical-infrastructure endpoints, demonstrating that commodity download lures can lead to enterprise compromise.
OfferLoader fingerprints victims and gates payload delivery to limit scanner visibility; researchers found more than 10,000 distinct loader samples and over 200 rotating domains. Payloads observed in 2026 included Insomnia RAT, ARKTunnel, and Docro Hijacker, followed by GCleaner and Socks5Systemz, enabling remote access, network tunneling, proxy services, and Chrome search and advertising hijacking. The operation illustrates the use of ATT&CK T1608.006 SEO poisoning, in which attackers manipulate search rankings and may use cloaking or redirects to steer targets to malicious infrastructure while evading inspection.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
A June 2026 infection using the same OfferLoader mechanism delivered GCleaner and Socks5Systemz rather than the payload bundle observed in April.
Two April 2026 intrusions used trojanized Bluetooth-driver and WinDirStat installers containing OfferLoader. The loader delivered Insomnia RAT, ARKTunnel and the Docro Hijacker Chrome hijacker.
The report published campaign-related domains, malicious URLs, SHA-256 hashes, and detection queries to help defenders identify and block CL-CRI-1171 infrastructure and associated files.
Unit 42 notified YouTube about at least 11 gaming-focused channels linked to CL-CRI-1171. YouTube subsequently terminated the identified channels.
Unit 42 tracked CL-CRI-1171 as a long-running pay-per-install operation distributing independently operated malware through the custom OfferLoader. The group used SEO-poisoned fake download sites and gaming-focused YouTube channels to distribute trojanized installers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 335 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcecyberveille.ch
Open sourcecommunity.gurucul.com
Open sourceunit42.paloaltonetworks.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.