Unit 42 researchers uncovered an extensive, two-year cybercrime scheme designated as CL-CRI-1171. The group responsible functions as a commercial pay-per-install marketplace that distributes diverse payloads for third-party adversaries. The operation funnels traffic through two deceptive avenues: manipulated engine results and influential gaming-focused YouTube channels. At the core of the entire infrastructure is OfferLoader, a trojanized setup package responsible for executing subsequent infections. This single delivery mechanism propagated three distinct malware strains: Insomnia RAT, an adaptable cross-platform backdoor compatible with Windows and macOS; ARKTunnel, a previously undocumented WebSocket tunneling tool; and Docro Hijacker, a browser-hijacking backdoor re-engineered against contemporary protections. Through these coordinated pipelines and rotating domains, the cluster quietly compromised vast numbers of consumer systems alongside sensitive enterprise and public-sector networks.
Symantec protects you from this threat, identified by the following:
Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.
Machine Learning-based
Observed domains/IPs are covered under security categories in all WebPulse enabled products
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
