Two companies got infected the same way, one week apart. One user had downloaded a Bluetooth driver, the other WinDirStat. Both looked like the sort of commodity adware nobody escalates.
Rem Dudas of Palo Alto Networks Unit 42 escalated them anyway, and the resulting investigation describes a cybercrime operation that has been running under the radar for at least two years. Unit 42 tracks it as CL-CRI-1171. The best camouflage it found was not sophistication. It was being boring.
One dropper, several unrelated buyers
CL-CRI-1171 is not really a malware crew. It is an infection service, a pay-per-install marketplace: the operator compromises machines and auctions access to multiple buyers, each of whom pushes their own payload through the same dropper. A single infected endpoint can therefore be carrying several unrelated payloads at once, each with its own command server and its own goal. Because the loader is generic and disposable, it rarely attracts the scrutiny that would reveal what came in behind it.
That is what made the two cases match. Both machines ran an identical post-exploitation chain from an unnamed, untracked loader. Pivoting on the loader's infrastructure exposed over 200 unique hostnames following a distinctive two-word compound naming pattern, names such as bubbleslip, churchpail and dinosaursjam, rotating across the .xyz, .cfd, .space and .info top-level domains over an eight-month window. Unit 42 has now identified more than 10,000 distinct loader samples, each able to deliver a different combination of payloads.
Real gaming advice, with a download attached
Traffic reached the malware landing pages through two funnels. The first was a network of at least eleven YouTube channels with hundreds of thousands of followers between them, publishing genuine gaming content about improving frame rates, fixing game crashes and tuning platform settings, and interacting with viewers in the comments. The advice was real. The tools the videos told viewers to download were not. Unit 42 notified YouTube, which terminated the channels.
The second funnel was SEO poisoning, and it aimed higher up the age range. Poisoned search results promoted trojanized versions of ordinary software, which is how the infections landed on corporate endpoints, including at critical infrastructure operators and government entities. It is the same delivery logic as the loader that ties ClickFix scams to fake game downloads, and the fake GTA 6 demo sites pushing a password stealer: find an audience already looking for a download, then be the download.
Three payloads, two of them never reported
Between July 2025 and April 2026, Unit 42 identified three distinct payloads delivered by the shared loader. Two had never been publicly documented, a browser hijacker the researchers named Docro Hijacker and a tunnelling tool they call ARKTunnel. The third is a new variant of a backdoor that had not previously been named, which Unit 42 dubbed the Insomnia remote access Trojan. Unit 42 is explicit that these three represent a small sample of a much larger campaign, not its full inventory, and does not attribute the cluster to a known group.
Stop dismissing the commodity loader
The practical lesson lands on triage policy rather than on any one indicator. A generic loader that looks like adware is a live question about who bought the install, and closing the ticket at the dropper leaves whatever the buyers deployed still running. If an endpoint has ever executed a trojanized utility from a search result or a video description, hunt forward from that event rather than treating the detection as the end of it. Untrusted download sources are the entire distribution model here, and blocking them costs less than unpicking three unrelated payloads later.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.