OfferLoader network spreads malware through YouTube searches
Security researchers have mapped a pay-per-install malware operation using YouTube gaming channels and poisoned search results to distribute more than 10,000 distinct samples of a custom loader, exposing a cybercrime delivery network operating at substantial scale. Palo Alto Networks’ Unit 42 said the activity, tracked as CL-CRI-1171, funnels victims through two main routes: gaming-related…
Palo Alto Networks’ Unit 42 has uncovered a pay-per-install malware operation that spreads through YouTube gaming channels and poisoned search results, affecting more than 10,000 unique OfferLoader samples. The cybercrime network, tracked as CL-CRI-1171, uses gaming-related YouTube content and search-engine optimization poisoning to lure victims into downloading trojanised software.
The infrastructure connects multiple hostnames with a two-word naming pattern across domains like .xyz, .cfd, .space, and .info. Among the three malware families identified in observed infections are Insomnia RAT, ARKTunnel, and Docro Hijacker. Insomnia RAT is a dual-agent backdoor, ARKTunnel is a WebSocket tunnelling tool, and Docro Hijacker is a Chrome-focused browser-hijacking technique.
The operation has been active for at least two years, with payload tracking showing some malware combinations rotating between July 2025 and April 2026.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.