Hidden in Plain Sight: Malware Campaign Uses YouTube and Fake Software to Infect Thousands
Security researchers at Unit 42 have uncovered a large-scale cybercrime campaign, tracked as CL-CRI-1171, that has operated undetected for at least two years. Rather than relying on sophisticated hacking techniques, the group succeeded by blending in: it disguised its malware distribution as ordinary gaming help content and search results, making it look unremarkable and easy to overlook.
The group ran a pay-per-install service, letting other cybercriminals distribute their malware widely through two main channels. The first was at least eleven YouTube channels with hundreds of thousands of followers, offering genuine gaming tips while also linking to malicious downloads. YouTube has since terminated these channels after being notified. The second channel used SEO poisoning to push trojanised software toward a more professional audience, resulting in infections on corporate systems, including critical infrastructure and government networks.
Researchers identified three distinct malware payloads delivered through the same loader between July 2025 and April 2026, including two previously unreported tools and a new variant of a backdoor now named the Insomnia RAT. This is likely only a small sample of the operation's true scale, with more than 10,000 unique loader samples identified so far, each capable of delivering different combinations of malicious payloads.