Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
ID: e859fd64-45b1-59b7-a243-b1ef30e69d35
STIX ID: report--e859fd64-45b1-59b7-a243-b1ef30e69d35
Feed Name: GBHackers
Unit 42 details CL-CRI-1171, a large-scale pay‑per‑install distribution operation that used YouTube gaming channels and SEO‑poisoned download pages to deliver trojanized Inno Setup installers embedding a shared loader (OfferLoader) tied to 10,000+ samples; the modular loader enabled delivery of multiple malware families (Insomnia RAT, ARKTunnel, Docro Hijacker, etc.), used disposable domains, gating/telemetry to evade scanners, and functioned as infection-as-a-service for downstream criminal actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
