Unmasking CL-CRI-1171: A Cybercrime Campaign Targeting Gamers
A recent investigation by Unit 42 has unveiled a significant cybercrime campaign, designated CL-CRI-1171, that has been operating under the radar for at least two years. This campaign primarily targets young gamers, utilizing seemingly innocuous methods to distribute malware through popular platforms like YouTube. The findings reveal that the most effective camouflage in cybercrime may not lie in sophisticated techniques, but rather in the unremarkable appearance of the threats themselves. The full analysis can be found in the detailed report by Palo Alto Networks here.
At the heart of this operation is a pay-per-install (PPI) marketplace that facilitates the distribution of malware to unsuspecting users. The campaign has leveraged at least eleven YouTube channels, each boasting hundreds of thousands of followers, to promote gaming content that is laced with links to malicious downloads. These channels provided genuine gaming advice, such as tips for improving frame rates and fixing game crashes, while simultaneously serving as conduits for malware delivery.
Mechanisms of Infection: YouTube and SEO Poisoning
The CL-CRI-1171 campaign employs two primary mechanisms to funnel traffic to its malware landing pages: a network of YouTube channels and search engine optimization (SEO) poisoning. The shared infrastructure between these channels and the SEO tactics indicates a coordinated effort to maximize infection rates. The investigation revealed that the malware was delivered through a custom loader, which has been responsible for deploying a variety of payloads, including the newly identified Insomnia remote access Trojan (RAT), ARKTunnel, and Docro Hijacker.
In a notable instance, two separate organizations were infected by the same unnamed loader delivering identical payloads within a week. This raised questions about the loader’s widespread use and effectiveness. Further analysis uncovered a vast network of over 200 unique hostnames, employing a rotational domain pattern that obscured the campaign’s true nature.
The PPI Ecosystem: A Hidden Marketplace
The PPI networks function as underground marketplaces where compromised machines are auctioned off to various buyers. Each buyer can deploy their own payloads through the same dropper, resulting in a single infection concealing multiple threats. This design minimizes scrutiny, allowing the loader to evade detection while facilitating a broad range of malicious activities.
Technical Insights: The OfferLoader and Its Payloads
The investigation identified three distinct malware strains delivered by the CL-CRI-1171 group between July 2025 and April 2026:
- OfferLoader: The primary delivery mechanism, a trojanized Inno Setup installer that sets up subsequent payloads.
- Insomnia RAT: A dual-payload backdoor targeting both Windows and macOS, utilizing Node.js and Python for its operations.
- ARKTunnel: A previously unreported WebSocket tunneling RAT that employs steganography to conceal its payload within bitmap images.
- Docro Hijacker: A Chrome backdoor that revives an old browser-hijacking technique, re-engineered to bypass modern security measures.
Each of these payloads operates independently, utilizing its own command and control (C2) infrastructure. The OfferLoader’s design allows it to deliver a wide array of malware families, with over 10,000 unique loader samples identified, indicating a much larger distribution pipeline than initially suspected.
Conclusion: The Implications of CL-CRI-1171
The CL-CRI-1171 campaign serves as a stark reminder of the evolving tactics employed by cybercriminals. By disguising their operations within seemingly benign content, these actors can effectively target vulnerable populations, such as young gamers. The investigation underscores the importance of vigilance and proactive measures in cybersecurity, particularly in recognizing that not all threats are overtly sophisticated. As the landscape of cybercrime continues to evolve, defenders must remain alert to the potential dangers lurking behind everyday digital interactions.
Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.



