A persistent cyber campaign dubbed CL-CRI-1171 is exploiting YouTube gaming channels and SEO poisoning to deliver remote access Trojans (RATs) and Chrome hijackers. Attackers publish gaming and optimization videos with drop links disguised as performance packs or tools, directing users through Blogspot redirects to malicious installers.
The operation includes two primary infection vectors. First, gaming-focused content offers advice like improving frame rates or fixing crashes, then prompts viewers to click download links in video descriptions. These links often funnel through Blogspot blogs that mask the real payload destination. Second, SEO poisoning targets users searching for legitimate utilities—such as Bluetooth drivers or WinDirStat—returning fake file-hosting pages that mimic scanner activity before delivering a trojanized archive.
What CL-CRI-1171 Delivers
At the heart of the campaign is OfferLoader, a loader disguised as typical adware whose real function is to distribute malware through distinct branches. Researchers encountered over 10,000 samples of OfferLoader, with 11 YouTube channels—each with large audiences—tied to the campaign before being shut down. YouTube videos help lend credibility to dangerous downloads, while SEO tricks boost visibility to those searching for safe software.
Once the malware installer passes verification checks—intended to fool automated scanners—it runs an Inno Setup file, launching three separate malware branches. One branch installs Insomnia RAT, a dual Node.js and Python backdoor that disables Microsoft Defender, excludes the entire C: drive from protection, and establishes scheduled tasks for persistence. Another branch deploys ARKTunnel, a RAT that hides payloads inside bitmap images, enabling tunneling of TCP/UDP traffic. The third introduces Docro Hijacker, which tampers with Chrome settings—modifying protected preferences, installing a stealth extension, redirecting clicks, altering affiliate links, and injecting content into search results.
Indicators & Protection
To aid detection, several SHA-256 hashes have been shared for each component—including the OfferLoader installer, the unpacked loader, and payload artifacts. A long list of malicious domains and the names of YouTube channels involved were also identified, many of which are now removed.
Users are advised to download software only from verified publishers, steer clear of cracks or gaming cheats, and always check file signatures. Organizations should be on alert for unfamiliar scheduled tasks, newly installed services, changes to browser preferences, and outbound traffic to odd domains. In case of suspected infection, isolate the device, preserve logs, reset exposed credentials from a clean environment, and perform a full security review.
Malware delivery through influencer-style content and SEO manipulation is not new—but CL-CRI-1171 stands out for its scale and the sophistication of its multi-branch payload system. It delivers stealthy RATs, undetected browser hijackers, and uses false credibility to ultimately compromise both gamers and corporate systems.
These threats matter because they exploit trust and visibility—elements most people rely on to stay safe. The deeper issue is where cybersecurity intersects with content platforms and search engines. What’s next: platform accountability, stricter creator verification, and stronger detection tools. Every link clicked and tool downloaded should be treated with caution.