{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/windirstat-trojanized-versions/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["CL-CRI-1171"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WinDirStat (trojanized versions)"],"_cs_severities":["high"],"_cs_tags":["ppi","malware","seo-poisoning","loader","remote-access-trojan","c2"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eCL-CRI-1171 is a cybercrime group operating a pay-per-install (PPI) marketplace that facilitates the distribution of diverse malware payloads to enterprise and home networks. The group has been active since at least 2024, utilizing a shared loader infrastructure to deploy various secondary payloads, including the previously unreported Docro Hijacker, ARKTunnel, and the Insomnia RAT. The delivery infrastructure is highly evasive, employing a gate mechanism that fingerprints potential victims using parameters like operating system, browser, and referring URL. Requests that do not match expected criteria are served decoys, effectively blinding automated security scanners and analysts. This infrastructure facilitates the rotational deployment of unrelated malware families, ensuring the operator can monetize access to thousands of compromised endpoints, ranging from consumer gaming PCs to government and critical infrastructure workstations. The campaign is notable for its use of SEO poisoning and high-follower YouTube gaming channels, which provide a consistent stream of human traffic to the malicious delivery funnels.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes a funnel via YouTube gaming channels and SEO-poisoned pages for legitimate software like WinDirStat or Bluetooth drivers.\u003c/li\u003e\n\u003cli\u003eVictim navigates to a malicious landing page, triggering a fake virus-scan animation to build credibility.\u003c/li\u003e\n\u003cli\u003eThe landing page gate performs client-side fingerprinting and validates the victim environment via a click_id parameter.\u003c/li\u003e\n\u003cli\u003eUpon validation, the gate serves a generic, trojanized installer (the OfferLoader) to the victim.\u003c/li\u003e\n\u003cli\u003eThe installer executes and reaches out to rotational C2 domains to fetch additional payloads.\u003c/li\u003e\n\u003cli\u003eThe loader drops secondary stage agents, such as PowerShell scripts or DLLs, designed to facilitate further persistence and download multi-stage agents (Node.js/Python).\u003c/li\u003e\n\u003cli\u003eFinal stage payloads (e.g., Insomnia RAT, ARKTunnel) initiate C2 communication to exfiltrate data or establish remote access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign has resulted in at least 10,000 distinct loader deployments, affecting organizations across government and critical infrastructure sectors. Successful infections provide unauthorized remote access and the ability to deploy arbitrary additional malware, leading to potential data exfiltration, long-term persistence, and the sale of access to other malicious actors via the PPI marketplace.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided detection rules to identify suspicious process execution chains associated with generic installers and PowerShell-based staging.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering to block the rotational C2 domain patterns and known bad domains identified in this brief at the DNS level.\u003c/li\u003e\n\u003cli\u003eMonitor for unsigned or inconsistently signed installers masquerading as legitimate utilities like WinDirStat, particularly those originating from non-official domains.\u003c/li\u003e\n\u003cli\u003eInvestigate endpoints for the presence of PowerShell scripts downloading from external non-reputable domains, focusing on the file patterns identified in the technical analysis.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T12:46:11Z","date_published":"2026-09-09T12:46:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cl-cri-1171-ppi-campaign/","summary":"The CL-CRI-1171 threat actor operates a large-scale pay-per-install marketplace, leveraging SEO poisoning and YouTube gaming lures to deploy a persistent multi-payload loader used to distribute malware including Insomnia RAT and ARKTunnel.","title":"CL-CRI-1171 Pay-Per-Install Infrastructure and Malware Campaign","url":"https://feed.craftedsignal.io/briefs/2026-09-cl-cri-1171-ppi-campaign/"}],"language":"en","title":"CraftedSignal Threat Feed - WinDirStat (Trojanized Versions)","version":"https://jsonfeed.org/version/1.1"}