Executive Summary
Unit 42 has uncovered a significant cybercrime operation tracked as CL-CRI-1171, which has functioned as a Pay-Per-Install (PPI) marketplace for over two years. The group primarily targets young gamers through a network of YouTube channels and professionals via SEO poisoning. By using a custom, generic dropper dubbed OfferLoader, the group successfully delivers multiple independent malware families while remaining under the radar of traditional security monitoring.
The attack chain involves sophisticated gating mechanisms that fingerprint victims' browsers and search queries, ensuring that automated scanners and analysts are served decoy content while real targets receive malicious payloads. This infrastructure has been used to deliver previously undocumented tools, such as the WebSocket-based ARKTunnel and the cross-platform Insomnia RAT, alongside browser hijackers like Docro Hijacker. The scale of the operation is vast, with over 10,000 unique loader samples identified.
The business impact of CL-CRI-1171 is significant, as it provides a low-cost, high-volume infection funnel for various threat actors. Compromised endpoints include critical infrastructure and government entities, demonstrating that while the lures (such as gaming cheats) may seem low-priority, the resulting infections provide attackers with persistent, high-level access to sensitive environments.
