Skip to content

Security1 publisher2 min readPublished

Unit 42 pulled a two-year pay-per-install marketplace out of two dismissible adware tickets

Unit 42's CL-CRI-1171 sold installs to other criminals for at least two years, funneling gamers through YouTube and professionals through poisoned search results, while its loader stayed unnamed because nobody escalated it.

The Watch · Security desk

What happened

  • Unit 42 tracks a cluster it calls CL-CRI-1171 that sells infections to other criminals as a pay-per-install service, and says the operation has run for at least two years.
  • Traffic came from at least eleven YouTube gaming channels with hundreds of thousands of followers, which YouTube terminated after Unit 42 notified it, alongside an SEO-poisoning funnel pushing trojanized tools.
  • Between July 2025 and April 2026 the same loader delivered three separate payloads: Docro Hijacker and ARKTunnel, both previously unreported, and a backdoor variant Unit 42 named Insomnia RAT.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The pool of installs on sale includes corporate endpoints at critical infrastructure operators and government bodies, so the buyer, not the operator, decides what a gaming-adware ticket turns into.
  • capability Removing the family you identified can leave the other tenants in place: several unrelated buyers may be resident on one host with separate C2, so host cleanup ends one lease rather than the incident.
  • constraint A sample blocklist is chasing a set that regenerates at over 10,000 builds; the reusable artifacts are the post-exploitation chain and the rotating C2 domains, which auto-closed tickets seldom preserve.
  • decision Retention policy for non-escalated commodity alerts becomes the live choice, because keeping their domains and process trees is what lets one dismissed ticket be matched against another org's.

Two organizations, unrelated, each installed something they actually wanted: a Bluetooth driver at one, WinDirStat at the other. Both hosts then ran an identical post-exploitation chain, one week apart [11]. Neither ticket was worth a phone call on its own. Unit 42 says the activity it investigated would not normally require escalation or further inquiry [13], and the loader was unnamed, untracked and generic enough to file as commodity adware [12].

A pay-per-install operator does not care what runs after the install. It compromises machines and auctions access to several buyers, each dropping an independent payload through the same dropper, so one infection can carry implants from unrelated actors, each with its own C2 and its own objective [9]. Unit 42's read is that the disposability of the loader is the protection: generic droppers rarely draw the scrutiny that would surface what they delivered [10].

The named payload set is only a floor for what's out there. Unit 42 dates three families from the same loader to a window running July 2025 to April 2026 [7]. That is ten months against an operation it puts at two years or more, so fewer than half the known months have a named payload attached [16]. Against that, more than 10,000 distinct loader samples, each able to deliver a different payload combination [8], and the company's own note that the infections it examined are a small sample of the deployment campaign [17].

Infrastructure tied the cluster together: shared infrastructure across the YouTube and SEO funnels, the same loader throughout, and a rotational domain pattern followed over eight months [14]. Pivoting on the loader's C2 exposed the rotation [15]. Any SOC holding the domains and process chains from tickets it auto-closed can run that pivot. The cost is retention and cross-matching.

The material stops well short of a full picture. No victim is named, no endpoint count is given beyond the hundreds of infections observed [3], no marketplace pricing appears, and attribution ends at the cluster identifier [1]. The phrase "under the radar for at least two years" means the alerts were being tracked all along: they were seen and closed, and closing them produced no name for the loader until two chains matched by accident. For a buyer who wants a foothold inside a government network [6], the low-priority label is the product.

What to watch

  • Whether Unit 42 publishes further payload families from the 10,000-plus loader samples, which would show how many buyers the marketplace actually served.
  • Whether the terminated YouTube channels reconstitute under new handles feeding the same landing pages.
  • Whether any of the affected critical infrastructure or government organizations are identified, or the loader gets a public name others can pivot on.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories