Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

Published September 9, 2026

A two-year-old cybercrime group called CL-CRI-1171 hid malware in fake YouTube gaming videos and fake search results. Their tools can take over computers, spy on users, and steal data from government and energy companies.

Report priority
High
Targets
Threat actor: CL-CRI-1171+2 more

How it works

  • The attackers run a fake YouTube gaming channel with hundreds of thousands of followers.
  • They also poison search results to trick corporate users into clicking links.
  • When clicked, these links install OfferLoader, a custom program that downloads and runs other malware.
  • The malware families Insomnia RAT, ARKTunnel, and Docro Hijacker can take over computers, spy on users, and hijack browsers.
  • The attackers use steganography to hide ARKTunnel inside images or videos, making it harder to detect.

What to do

If you clicked a link from a fake YouTube gaming channel or a fake search result in the last two years, check your computer for unusual programs like Insomnia RAT, ARKTunnel, or Docro Hijacker. Look for unexpected browser changes, hidden network connections, or unfamiliar processes running in Task Manager (Windows) or Activity Monitor (macOS). If you see any of these, disconnect it from the internet immediately.

Run a full scan with a trusted antivirus like Malwarebytes or Windows Defender. For corporate users, report suspicious activity to your IT team right away. If you're a gamer, avoid clicking links from unknown YouTube channels or search results. For government or energy workers, avoid clicking any unexpected software updates or links in search results.

Technical details

Affected software: Threat actor: CL-CRI-1171, Government, Energy

A young gamer clicks on a fake YouTube video link from a channel pretending to be a popular streamer. The video appears normal, but it secretly downloads OfferLoader, which then installs Insomnia RAT. The RAT starts spying on the user's keyboard and screen, sending data back to the attackers. Meanwhile, a corporate employee clicks a fake search result for a software update, which installs ARKTunnel hidden in an image file. The tunnel lets the attackers bypass firewalls to control the company's network.

A two-year-old cybercrime operation (tracked as CL-CRI-1171) leveraged a pay-per-install marketplace to distribute malware via YouTube channels with hundreds of thousands of followers and SEO poisoning, targeting young gamers and corporate endpoints, including critical infrastructure and government systems. The campaign used OfferLoader, a custom loader that delivers tailored payloads through layered gating mechanisms, deploying three distinct malware families: - Insomnia RAT, a cross-platform backdoor capable of remote command execution and data exfiltration on both Windows and macOS systems. - ARKTunnel, a WebSocket tunneling tool concealed via steganography to evade detection, enabling covert communication with attacker-controlled servers. - Docro Hijacker, a Chrome browser hijacker that alters search results and redirects users to malicious sites. Over 10,000 unique loader samples were identified, suggesting widespread deployment across global organizations. The threat actor's use of steganography and gating mechanisms demonstrates sophisticated evasion techniques to maintain persistence.