A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale.
The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed.
Rather than relying on a single advanced implant or an overtly targeted intrusion chain, the operators used trojanized installers, disposable domains, browser-based filtering and affiliate tracking to selectively deliver payloads to victims while avoiding automated analysis systems.
Unit 42 said the activity had operated for at least two years and functioned as an infection-as-a-service platform.
In a PPI model, access to compromised systems can be sold to multiple downstream actors, allowing one benign-looking installer to deploy unrelated malware families with separate command-and-control infrastructure, objectives and monetization models.
Researchers identified at least 11 YouTube channels associated with the operation.
The channels collectively had hundreds of thousands of subscribers and millions of views, publishing apparently legitimate content focused on gaming performance, frame-rate improvements, crash fixes and game-setting optimizations.
The videos delivered genuine gaming advice, but descriptions and linked pages directed users to malicious “optimization tools,” cheats, utilities or software packages.
The links often passed through intermediary Blogspot pages before routing users to the same PPI gate infrastructure used by the campaign’s SEO-poisoning operation.
YouTube was notified of the channels and terminated them, according to Unit 42.
A parallel SEO-poisoning funnel targeted users searching for legitimate tools and software. In investigated incidents, victims downloaded trojanized versions of a Bluetooth driver and the disk-usage utility WinDirStat.
The fake download pages used file-hosting lures and misleading virus-scan animations before providing ZIP archives containing malicious installers.
10,000+ Malware Loaders
Unit 42 said in a report shared with GBhackers, the campaign demonstrates how malware delivery infrastructure can remain largely unnoticed by appearing routine.

The attack chain used a gating mechanism to filter traffic. Tracker URLs included a Base64-encoded click_id parameter containing telemetry such as the visitor’s operating system, browser, referring domain, search term and public IP address.
Valid victim fingerprints were forwarded to the malware download, while crawlers, security scanners and researchers were reportedly served broken links or decoy pages impersonating legitimate WinRAR downloads.
The core delivery component, OfferLoader, is embedded in trojanized Inno Setup installers.
Its purpose is not to retain long-term access itself, but to act as a disposable deployment framework that launches separate malware “offers” supplied by PPI customers.
In one observed infection chain, an apparent windirstat.exe installer unpacked a temporary component that contacted a tracking server.
The server returned either “no,” which halted execution, or “ok,” which triggered the deployment of multiple child processes.
Those processes delivered separate malware payloads, enabling multiple independent criminal operations to coexist on the same infected endpoint.
Unit 42 traced more than 200 rotating infrastructure domains using a distinctive two-word naming convention across .xyz, .cfd, .space and .info top-level domains.
The rotational infrastructure, shared loader and overlapping delivery paths tied the YouTube and SEO campaigns to a single sustained cluster.
The April 2026 incidents delivered three malware families: Insomnia RAT, ARKTunnel and Docro Hijacker.

A later infection in June reportedly delivered different payloads, GCleaner and Socks5Systemz, underscoring that OfferLoader’s payload set is modular and can change between affiliates or campaigns.
Insomnia RAT combines Node.js and Python backdoors, providing redundant access paths.
The installer reportedly disables Microsoft Defender protections, adds C: as an exclusion and deploys runtime environments required to execute the implants.
It creates scheduled tasks masquerading as Windows components, including Maps Performance Task and OOBETaskScheduler, then communicates with command servers using the user-agent string insomnia/2023.4.0 Windows.
ARKTunnel is a previously unreported WebSocket-based tunneling RAT that uses least-significant-bit steganography to extract its payload archive from a bitmap image.
The implant supports TCP and UDP tunneling, file execution and service-based persistence, while using rotating fake corporate identities such as EarthKark and TamarkLark in its metadata.
Docro Hijacker targets Google Chrome. It modifies Chrome Secure Preferences by bypassing the browser’s HMAC-SHA256 integrity mechanism, enabling forced search-provider changes and installation of a Manifest V3 extension.
The extension can inject advertising, rewrite affiliate links and redirect search traffic through attacker-controlled infrastructure.
The campaign highlights the risk posed by “low-priority” detections involving adware-like loaders, suspicious installers and potentially unwanted software.
Security teams should investigate unsigned installers from search results, monitor recently registered domains, inspect scheduled tasks created after archive extraction, and detect browser preference modifications or unexpected Chrome extensions.
Organizations should also block downloads of pirated software, game cheats and unofficial optimization tools, especially from links promoted through video descriptions or search results.
The campaign’s strength is not a single exploit, but a scalable and selective distribution system built to make compromise look ordinary.
IOCs
| SHA-256 | File Name | File Type | Description |
|---|---|---|---|
7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c | windirstat.exe | PE32 executable; Inno Setup 6.7.1 installer | OfferLoader-trojanized WinDirStat installer distributed through an SEO-poisoning campaign. |
fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 | windirstat.tmp | PE32 executable; unpacked Inno Setup stage | Unpacked WinDirStat installation stage extracted from the trojanized installer. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
★ Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

