CL-CRI-1171 is a financially motivated cybercrime cluster operating a pay-per-install malware-distribution service since at least 2024. It uses gaming-focused YouTube channels, search-engine optimization poisoning, fake software-download pages, and trojanized installers masquerading as game-performance tools, drivers, and legitimate utilities. The operation primarily lures gamers but has also affected enterprise, critical-infrastructure, and government endpoints. The cluster’s shared OfferLoader component is an Inno Setup-based loader that profiles prospective victims and uses gated delivery to distinguish likely targets from automated analysis systems. It can serve decoy content or nonfunctional downloads to scanners and researchers, while selectively deploying modular payloads to validated victims. This model enables the operator to monetize a compromised device through multiple downstream criminal customers and change payload bundles without replacing the initial lure. Observed OfferLoader payloads include Insomnia RAT, ARKTunnel, Docro Hijacker, GCleaner, and Socks5Systemz. Insomnia RAT is a Windows and macOS backdoor with Node.js and Python components that collects host information, receives commands, downloads files, returns execution output, impairs Microsoft Defender protections, and establishes scheduled-task persistence. ARKTunnel is a WebSocket-based remote-access tool that uses steganographic payload concealment, establishes service-based persistence, tunnels TCP and UDP traffic, and executes files. Docro Hijacker bypasses Chrome Secure Preferences integrity controls to alter search-provider settings and install a malicious browser extension capable of modifying search results, redirecting traffic, and manipulating affiliate links for monetization.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
335 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pay-per-install malware-delivery operation using YouTube gaming-channel lures and SEO-poisoned search results to distribute trojanized installers. Its OfferLoader component delivers multiple payload branches, including remote-access malware and a Chrome hijacker, to gamers and corporate or government endpoints.
Operates a pay-per-install malware-delivery service using compromised-appearing YouTube gaming channels, Blogspot redirect pages, and SEO poisoning for legitimate-utility searches. It delivers OfferLoader through trojanized installers and monetizes infections by providing multiple downstream malware payloads to other criminal customers.
Opération cybercriminelle PPI qui diffuse un loader trojanisé via de faux téléchargements de logiciels et des liens YouTube/SEO poisoning. Le cluster filtre les victimes à travers une gate PPI et délivre plusieurs charges utiles de RAT, de détournement de navigateur et de botnet, visant notamment des particuliers, entreprises, infrastructures critiques et entités gouvernementales.
A financially motivated cybercrime operation running a pay-per-install service. It uses YouTube gaming-content lures and SEO poisoning to distribute malware through a custom loader, targeting gamers as well as corporate, government, and critical-infrastructure victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.