<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ppi - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/ppi/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 09 Sep 2026 12:46:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/ppi/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CL-CRI-1171 Pay-Per-Install Infrastructure and Malware Campaign</title><link>https://feed.craftedsignal.io/briefs/2026-09-cl-cri-1171-ppi-campaign/</link><pubDate>Wed, 09 Sep 2026 12:46:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cl-cri-1171-ppi-campaign/</guid><description>The CL-CRI-1171 threat actor operates a large-scale pay-per-install marketplace, leveraging SEO poisoning and YouTube gaming lures to deploy a persistent multi-payload loader used to distribute malware including Insomnia RAT and ARKTunnel.</description><content:encoded><![CDATA[<p>CL-CRI-1171 is a cybercrime group operating a pay-per-install (PPI) marketplace that facilitates the distribution of diverse malware payloads to enterprise and home networks. The group has been active since at least 2024, utilizing a shared loader infrastructure to deploy various secondary payloads, including the previously unreported Docro Hijacker, ARKTunnel, and the Insomnia RAT. The delivery infrastructure is highly evasive, employing a gate mechanism that fingerprints potential victims using parameters like operating system, browser, and referring URL. Requests that do not match expected criteria are served decoys, effectively blinding automated security scanners and analysts. This infrastructure facilitates the rotational deployment of unrelated malware families, ensuring the operator can monetize access to thousands of compromised endpoints, ranging from consumer gaming PCs to government and critical infrastructure workstations. The campaign is notable for its use of SEO poisoning and high-follower YouTube gaming channels, which provide a consistent stream of human traffic to the malicious delivery funnels.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker establishes a funnel via YouTube gaming channels and SEO-poisoned pages for legitimate software like WinDirStat or Bluetooth drivers.</li>
<li>Victim navigates to a malicious landing page, triggering a fake virus-scan animation to build credibility.</li>
<li>The landing page gate performs client-side fingerprinting and validates the victim environment via a click_id parameter.</li>
<li>Upon validation, the gate serves a generic, trojanized installer (the OfferLoader) to the victim.</li>
<li>The installer executes and reaches out to rotational C2 domains to fetch additional payloads.</li>
<li>The loader drops secondary stage agents, such as PowerShell scripts or DLLs, designed to facilitate further persistence and download multi-stage agents (Node.js/Python).</li>
<li>Final stage payloads (e.g., Insomnia RAT, ARKTunnel) initiate C2 communication to exfiltrate data or establish remote access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The campaign has resulted in at least 10,000 distinct loader deployments, affecting organizations across government and critical infrastructure sectors. Successful infections provide unauthorized remote access and the ability to deploy arbitrary additional malware, leading to potential data exfiltration, long-term persistence, and the sale of access to other malicious actors via the PPI marketplace.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the provided detection rules to identify suspicious process execution chains associated with generic installers and PowerShell-based staging.</li>
<li>Implement egress filtering to block the rotational C2 domain patterns and known bad domains identified in this brief at the DNS level.</li>
<li>Monitor for unsigned or inconsistently signed installers masquerading as legitimate utilities like WinDirStat, particularly those originating from non-official domains.</li>
<li>Investigate endpoints for the presence of PowerShell scripts downloading from external non-reputable domains, focusing on the file patterns identified in the technical analysis.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>ppi</category><category>malware</category><category>seo-poisoning</category><category>loader</category><category>remote-access-trojan</category><category>c2</category></item></channel></rss>