logo

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

ID: e859fd64-45b1-59b7-a243-b1ef30e69d35

STIX ID: report--e859fd64-45b1-59b7-a243-b1ef30e69d35

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-09-11

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

Unit 42 details CL-CRI-1171, a large-scale pay‑per‑install distribution operation that used YouTube gaming channels and SEO‑poisoned download pages to deliver trojanized Inno Setup installers embedding a shared loader (OfferLoader) tied to 10,000+ samples; the modular loader enabled delivery of multiple malware families (Insomnia RAT, ARKTunnel, Docro Hijacker, etc.), used disposable domains, gating/telemetry to evade scanners, and functioned as infection-as-a-service for downstream criminal actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.