Urgent.News

What's breaking now, across thousands of outlets.

Tech

OfferLoader network spreads malware through YouTube searches

Security researchers have mapped a pay-per-install malware operation using YouTube gaming channels and poisoned search results to distribute more than 10,000 distinct samples of a custom loader, exposing a cybercrime delivery network operating at substantial scale. Palo Alto Networks’ Unit 42 said the activity, tracked as CL-CRI-1171, funnels victims through two main routes: gaming-related…

Palo Alto Networks’ Unit 42 has uncovered a pay-per-install malware operation that spreads through YouTube gaming channels and poisoned search results, affecting more than 10,000 unique OfferLoader samples. The cybercrime network, tracked as CL-CRI-1171, uses gaming-related YouTube content and search-engine optimization poisoning to lure victims into downloading trojanised software.

The infrastructure connects multiple hostnames with a two-word naming pattern across domains like .xyz, .cfd, .space, and .info. Among the three malware families identified in observed infections are Insomnia RAT, ARKTunnel, and Docro Hijacker. Insomnia RAT is a dual-agent backdoor, ARKTunnel is a WebSocket tunnelling tool, and Docro Hijacker is a Chrome-focused browser-hijacking technique.

The operation has been active for at least two years, with payload tracking showing some malware combinations rotating between July 2025 and April 2026.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

Why Do We Still Need Microcontrollers?

Computers and smartphones are becoming more powerful every year. So I've been thinking about a simple question: Why do we still need small microcontrollers like Arduino, ESP8266, and ESP32?

  • Their compact size, affordability, and low power consumption make them ideal for many applications.
  • Edge AI and edge computing advancements may eventually reshape their role in embedded systems.

Understanding Cordis: The TypeScript Framework Built for Hot-Swapping Everything

Part 1 of the DeepSeek Harness: Kernel to Edge series: How the open-source (MIT) Cordis meta-framework enables zero-downtime plugin reloads and memory-leak-free architectures in TypeScript, backed by…

  • Cordis is an open-source TypeScript meta-framework enabling runtime dynamic composability.
  • Developed by Shigma and Koishi team for dynamic plugin updates in chatbot connections.
  • Formalized in academic paper establishing safe dynamic loading/reloading principles.

Is your Data Lakehouse actually a HIPAA liability?

Ninety-two percent of healthcare data breaches occur because of misconfigurations in the storage layer, yet most engineers I interview still think "encryption at rest" is the end of the conversation.

  • HIPAA compliance requires immediate PHI masking upon data ingestion.
  • God-mode service accounts with unrestricted access violate HIPAA standards.
  • Immutable audit trails and identity mapping enforce fine-grained access control.

More from Saturday 12 September →