Tuesday, 02 January 2024 12:17 GMT

Offerloader Network Spreads Malware Through Youtube Searches Arabian Post


(MENAFN- The Arabian Post) clearfix">Security researchers have mapped a pay-per-install malware operation using YouTube gaming channels and poisoned search results to distribute more than 10,000 distinct samples of a custom loader, exposing a cybercrime delivery network operating at substantial scale.

Palo Alto Networks' Unit 42 said the activity, tracked as CL-CRI-1171, funnels victims through two main routes: gaming-related YouTube content and search-engine optimisation poisoning that steers users towards trojanised software downloads. Both routes ultimately lead to the same pay-per-install infrastructure, where OfferLoader installs payloads chosen by separate malware operators.

The researchers identified more than 10,000 unique OfferLoader samples, a figure they said points to a distribution pipeline far broader than the individual compromises that first drew attention to the activity. The operation has been active for at least two years, while payload tracking showed some malware combinations rotating between July 2025 and April 2026.

MENAFN12092026000152002308ID1111654880



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story