{
  "id": 6874613,
  "title": "OfferLoader network spreads malware through YouTube searches",
  "url": "https://urgent.news/2026/09/12/offerloader-network-spreads-malware-through-youtube-searches",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-12T06:05:30.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/offerloader-network-spreads-malware-through-youtube-searches/"
  },
  "original_language": "en",
  "account": "Palo Alto Networks’ Unit 42 has uncovered a pay-per-install malware operation that spreads through YouTube gaming channels and poisoned search results, affecting more than 10,000 unique OfferLoader samples. The cybercrime network, tracked as CL-CRI-1171, uses gaming-related YouTube content and search-engine optimization poisoning to lure victims into downloading trojanised software. The infrastructure connects multiple hostnames with a two-word naming pattern across domains like .xyz, .cfd, .space, and .info. Among the three malware families identified in observed infections are Insomnia RAT, ARKTunnel, and Docro Hijacker. Insomnia RAT is a dual-agent backdoor, ARKTunnel is a WebSocket tunnelling tool, and Docro Hijacker is a Chrome-focused browser-hijacking technique. The operation has been active for at least two years, with payload tracking showing some malware combinations rotating between July 2025 and April 2026.",
  "summary": "Security researchers have mapped a pay-per-install malware operation using YouTube gaming channels and poisoned search results to distribute more than 10,000 distinct samples of a custom loader, exposing a cybercrime delivery network operating at substantial scale. Palo Alto Networks’ Unit 42 said the activity, tracked as CL-CRI-1171, funnels victims through two main routes: gaming-related…",
  "key_points": [
    "OfferLoader malware spreads via YouTube gaming channels and poisoned search results",
    "CL-CRI-1171 network uses gaming-related YouTube content and SEO poisoning",
    "Three malware families identified: Insomnia RAT, ARKTunnel, and Docro Hijacker"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}