Skip to content
CL-CRI-1171 Cybercrime Operation Targets Gamers and Enterprises

CL-CRI-1171 Cybercrime Operation Targets Gamers and Enterprises

First seen 11 Sep 2026, 00:45 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 03:16 UTC

Unit 42 and Broadcom report on the CL-CRI-1171 cybercrime operation, a two-year scheme utilizing a pay-per-install marketplace to distribute malware targeting both young gamers and corporate networks. The operation leverages manipulated search engine results and popular gaming YouTube channels to deliver infections. The primary delivery mechanism, OfferLoader, has propagated three distinct malware strains: Insomnia RAT, ARKTunnel, and Docro Hijacker. The campaign has compromised numerous consumer systems and sensitive enterprise networks, with over 10,000 distinct loader samples identified. YouTube channels promoting gaming content were used as a delivery vehicle for malware, prompting their termination. The malware strains include a cross-platform backdoor, a WebSocket tunneling tool, and a browser-hijacking tool. Current protective measures include advanced URL filtering and DNS security from Palo Alto Networks and Symantec. The operation remains active, with ongoing risks for affected users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-07-01
CL-CRI-1171 campaign identified
Unit 42 began investigating the cybercrime operation that had been active for two years, targeting gamers and enterprises.
Unit42.Paloaltonetworks
2025-07-01
YouTube channels terminated
Unit 42 notified YouTube about channels promoting malware-laden gaming content, leading to their termination.
Unit42.Paloaltonetworks
2026-04-01
New malware strains identified
Unit 42 identified three malware strains delivered by the CL-CRI-1171 operation: Insomnia RAT, ARKTunnel, and Docro Hijacker.
Unit42.Paloaltonetworks
2026-09-09
Unit 42 report published
Unit 42 published a detailed analysis of the CL-CRI-1171 operation, revealing its extensive impact and methods.
Unit42.Paloaltonetworks
2026-09-10
Broadcom report published
Broadcom confirmed the findings of Unit 42, detailing the operation's methods and malware strains.
Broadcom

More articles in this cluster (2)

Following this threat?

Track ARKTunnel and YouTube in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed