VYPR
researchPublished Sep 9, 2026· 1 source

Cybercriminals Monetize YouTube and SEO for Malware Distribution via Pay-Per-Install Scheme

A large-scale cybercrime operation, tracked as CL-CRI-1171, is leveraging YouTube gaming lures and SEO poisoning to distribute multi-payload malware through a pay-per-install marketplace, targeting both gamers and enterprise networks.

Cybercriminals are operating a sophisticated, yet largely unnoticed, pay-per-install (PPI) marketplace that facilitates the distribution of various malware payloads. This operation, identified by Unit 42 and tracked as CL-CRI-1171, has been active for at least two years, utilizing a custom loader to deliver a range of malicious software to unsuspecting victims. The group behind this scheme acts as an infection service, enabling other threat actors to deploy their malware indiscriminately.

The campaign employs a dual-pronged approach to lure victims. One method involves a network of at least eleven YouTube channels, which collectively boasted hundreds of thousands of followers. These channels, promptly terminated by YouTube after notification, posted content related to improving gaming performance and fixing game-related issues. Embedded within this seemingly helpful content were links designed to trick viewers into downloading malware disguised as gaming tools.

Complementing the YouTube strategy, CL-CRI-1171 also utilizes SEO poisoning. This tactic targets a more professional audience by promoting trojanized software that, when downloaded, leads to the deployment of malware on corporate endpoints. The scope of this funnel is significant, with the investigation revealing that it has compromised critical infrastructure and even government entities.

The core of the CL-CRI-1171 operation is its custom loader, which is designed to be disposable and generic, making it difficult to detect and analyze. This loader is capable of delivering a variety of payloads, with Unit 42 identifying three distinct malware strains between July 2025 and April 2026: Docro Hijacker, ARKTunnel, and a new variant of a previously unknown backdoor dubbed Insomnia remote access Trojan (RAT). The flexibility of the loader means that a single infection can conceal multiple, unrelated payloads from different threat actors.

Tracing the loader's command and control (C2) infrastructure revealed a sprawling network of rotational domains. Over 200 unique hostnames were observed, following a consistent two-word compound naming pattern and rotating across various top-level domains such as .xyz, .cfd, .space, and .info. This dynamic infrastructure is part of the group's strategy to evade detection and maintain operational security.

The PPI ecosystem functions as an underground marketplace where compromised machines are leased to multiple buyers. Each buyer can then deploy their own independent payloads through the same dropper. This model allows for the widespread distribution of diverse malware families, as the loader itself is designed to be unremarkable, diverting attention from the subsequent, often more sophisticated, payloads it delivers.

The sheer scale of the operation is staggering, with researchers identifying over 10,000 distinct loader samples. Each sample is capable of delivering unique combinations of payloads, indicating a vast and ongoing distribution effort. The investigation into CL-CRI-1171 highlights a concerning trend where readily available commodity infrastructure and sophisticated social engineering tactics are combined to create a highly effective and profitable cybercrime enterprise.

Synthesized by Vypr AI