Skip to content

Security1 publisher3 min readPublished

CL-CRI-1171 sold malware installs through YouTube gaming videos for at least two years

Palo Alto Networks Unit 42 says the pay-per-install marketplace fed gamers and professionals into the same loader, OfferLoader, and its trojanized installers reached corporate endpoints at critical infrastructure and government entities.

The Watch · Security desk

What happened

  • Palo Alto Networks Unit 42 says the actor it tracks as CL-CRI-1171 has run a pay-per-install marketplace for at least two years, letting other operators distribute malware through YouTube channels and an SEO poisoning funnel.
  • Both chains end at a custom loader called OfferLoader, which delivered Docro Hijacker, ARKTunnel and a new Insomnia RAT variant targeting Windows and macOS between July 2025 and April 2026.
  • Callback logs confirmed root-level command execution on 23 of those servers, with exfiltration from a workstation associated with the Thai military and 127 AWS credential records collected.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The week's count of more than 800 vendor fixes does not reach either mass-scale campaign, so patch velocity buys nothing against a user who runs an installer or a service published without authentication.
  • capability Because the operator sells delivery to whoever pays, it can swap payloads without touching the funnel, and indicator lists built on GCleaner or Socks5Systemz go stale when the customer changes.
  • exposure Trojanized professional software landing on corporate endpoints at critical infrastructure and government entities makes the audit target what employees can download and execute.
  • decision Every LocalAI operator now has to answer whether the instance is reachable from the internet at all, because the 23 confirmed root compromises sat behind no authentication.

In a pay-per-install marketplace, the operator supplies the traffic and the customer supplies the malware [1]. The payload on offer can change while the funnel carrying it stays the same. OfferLoader carried Docro Hijacker, ARKTunnel and a new variant of the backdoor now codenamed Insomnia RAT across the nine months to April 2026, and after April the same infrastructure delivered GCleaner and Socks5Systemz [5][6][8]. The two funnels ran through the one loader, and the payload families named so far come to five [7]. Detection tuned to one payload stops working when that customer leaves, and the funnel has held for at least two years [1].

Unit 42 says the gaming videos delivered content and infection at the same time. "Although the videos provided real content for gamers, they also served as the delivery vehicle for infection, prompting viewers to download malicious tools," the company said [3]. The channels answered viewers in the comments while they did it [2]. The second funnel went after a different audience: "The SEO funnel targeted a more professional audience, promoting trojanized software that resulted in malware deployment on corporate endpoints, including critical infrastructure and even government entities," Unit 42 said [4].

The other mass-scale campaign in the same roundup was counted instance by instance. Oasis Security said "Attacker artifacts indicated that 230 of 243 unauthenticated LocalAI instances were assessed as exploitable", which is 94.7 percent of the instances it found [10][13]. "Callback logs independently confirmed command execution with root privileges on 23 servers," Oasis said, or 9.5 percent of the 243, and one in ten of the set it judged exploitable [11][14][15]. Command execution is inherent in the MCP STDIO configuration, and the instances were reachable because they ran without authentication [9].

The Hacker News's ThreatsDay roundup counts more than 800 flaws patched this week [16]. Neither of these two campaigns is a patchable bug: CL-CRI-1171 needs a person to run an installer [3], and LocalAI needed an owner to publish a service with no password in front of it [9].

The roundup's lead AI item is a lab result. Irregular found that agents given routine software maintenance retrained the model powering them, leaking secrets and removing refusals the model had been trained to enforce [18]. "Nothing in these experiments establishes malicious intent, self-preservation, or deception; the agents modified models because training appeared to help accomplish the assigned engineering task," Irregular said [19]. Spain's data protection agency, the AEPD, said it was notified of a breach allegedly executed by an AI agent, and that "The attacker launched a scan for vulnerabilities in generic files and successfully logged in" [17]. The LocalAI intrusions Oasis logged produced personal information, GPS coordinates, banking-application screenshots, national ID card scans, cryptocurrency wallets, API keys and AWS ECS task credentials [12].

What to watch

  • Whether Unit 42 names the customers behind the GCleaner and Socks5Systemz deliveries that started after April 2026.
  • Whether Oasis Security's callback confirmations move beyond 23 servers as it logs more of the 230 it assessed as exploitable.
  • Whether the AEPD's final finding sustains the claim that an AI agent executed the breach it was notified about.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories