Illustration of CL-CRI-1171 infrastructure | Image: Unit 42
At a Glance
Unit 42 researchers identified over 10,000 distinct samples of OfferLoader malware distributing dangerous payloads across enterprise systems. This cybercrime operation has remained active for at least two years. The operators rely on popular internet platforms to distribute secondary backdoors onto compromised endpoints. Therefore, simple infection alerts often hide severe corporate intrusions.
| Malware Family | OfferLoader (distributing Insomnia RAT, ARKTunnel, and Docro Hijacker) |
|---|---|
| Threat Actor | CL-CRI-1171 (Suspected cybercrime pay-per-install syndicate; official legal attribution remains unconfirmed) |
| Target or Victims | Gamers, enterprise workstations, critical infrastructure, and government entities |
| Delivery Vector | Trojanized installers distributed through YouTube gaming channels and search engine optimization poisoning |
| Key Capabilities | Chained payload deployment, defensive evasion, WebSocket tunneling, and browser search hijacking |
| Source | Palo Alto Networks Unit 42 |
TL;DR
Investigators uncovered an underground pay-per-install network distributing multiple backdoors through trojanized software downloads. The campaign relies on 11 popular YouTube gaming channels and poisoned search results to attract victims. Consequently, organizations face multi-stage compromises that deploy custom remote access Trojans and browser hijackers.
Delivery Channels and Lure Funnels
The group behind the campaign relies on two primary funnels to deliver malicious installers to victims. First, operators establish gaming optimization channels on YouTube to attract younger computer users. The researchers identified 11 channels connected to the operation, which accumulated hundreds of thousands of subscribers and millions of views.
These channels offer genuine advice on improving frame rates, fixing game crashes, and adjusting display settings. However, the video descriptions provide download links to external sites that host malicious utility packages.
Second, the threat actors deploy search engine optimization poisoning to snare professional users. Victims searching for legitimate tools such as Bluetooth drivers or disk management utilities encounter lure pages. According to Unit 42 researchers, “The group behind CL-CRI-1171 provides an infection service for other threat actors who want to spread their malware indiscriminately.”
Furthermore, the lure infrastructure inspects visitor details before serving files. The gate decodes visitor fingerprints, including browser types, operating systems, and search keywords. Therefore, automated security scanners only view benign decoy pages, while real users receive malicious archives.
The Infection Chain Architecture
The intrusion starts when a user opens an archive containing a trojanized installer. Inside the initial package, the OfferLoader malware extracts a temporary file to contact its gate server. If the server verifies the beacon, the installer spawns three separate child processes.
Unit 42 tracks each of these payload stages as a distinct offer. In addition, each child process functions as an independent attack campaign with unique command servers.
The first spawned process deploys Insomnia RAT to gain persistence on the victim system. Meanwhile, the second child process uses image steganography to unpack ARKTunnel. Finally, the third child process executes Docro Hijacker to modify the user’s web browser settings.
This modular architecture allows the network operator to swap payloads dynamically. Security teams can review the technical breakdown in Unit 42’s PPI network malware campaign analysis covering the OfferLoader malware campaign.
Command and Control Operations
Each delivered payload executes distinct commands and communicates with separate command servers.
Operation A deploys Insomnia RAT, which consists of twin Node.js and Python agents. The installer script disables Windows Defender protections and creates scheduled tasks disguised as standard system services. Furthermore, the backdoor connects to command servers using custom user-agent headers. The agent reports hostnames, operating system versions, and unique machine identifiers. This deployment aligns with earlier Node.js malware research published by Walmart Global Tech in 2025.
Operation B delivers ARKTunnel, a remote access implant extracted from bitmap images. The malware installs a Windows service configured for delayed startup. Afterward, it establishes WebSocket connections over TCP and UDP to execute remote commands. The developers rotated four fake corporate identities, including TamarkLark, across 50 collected samples.
Operation C installs Docro Hijacker, a tool targeting Google Chrome. The malware tampers with the browser Secure Preferences file to bypass integrity validation. This technique reflects research documented by Synacktiv in 2025. Consequently, the extension alters default search providers and injects unauthorized advertisements across more than 190 search engine domains.
Defense and Detection Guidance
Organizations must update their security controls to defend against multi-payload loader campaigns. Administrators should monitor environments for unexpected Node.js and Python runtimes executing from temporary directories. In addition, security teams must inspect newly created scheduled tasks for suspicious paths.
Network defenses should inspect outbound WebSocket traffic and block connections to unregistered hostnames. Moreover, administrators must restrict write access to browser preference directories. Defenders should treat every OfferLoader malware detection as a critical entry point rather than a routine infection.
As Unit 42 warns in their report, “Treating commodity loader infections as minor, routine events overlooks the dangerous payloads and campaigns that might be tied to them.” Applying strict application allowlisting and validating installer signatures will help organizations stop these threats before execution.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!