unit42.paloaltonetworks.com 9 Sept 2026, 10:00 UTC

OfferLoader Campaign Hides Three Payloads Behind Fake Software Installers

OfferLoader Campaign Hides Three Payloads Behind Fake Software Installers
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

UNIT 42’s analysis tracks a pay-per-install (PPI) cybercrime operation dubbed CL-CRI-1171, active for at least two years and targeting a broad set of victims including young gamers, enterprise endpoints and government entities. The operation uses a single, disposable loader—OfferLoader—to drop multiple payloads across campaigns, obscuring activity behind a commodity installation package.

The loader is delivered via Inno Setup and is sometimes masqueraded as legitimate installers (for example, windirstat[.]exe) or trojanised windirstat installers, with a gating mechanism that returns either “ok” or “no” to determine whether further stages should unpack. The campaign leverages rotational domains (over 200 hostnames across .xyz, .cfd, .space and .info) and two main delivery funnels: YouTube gaming channels and an SEO-poisoning path that redirects victims to trojanised software.

Three payload families were observed between mid-2025 and April 2026, each delivered by the same loader. Operation A, Insomnia RAT, is a cross‑platform backdoor (Node[.]js plus a Python agent) targeting Windows and macOS, with persistence via scheduled tasks and C2 over HTTPS. Operation B, ARKTunnel, is a WebSocket tunneling RAT hidden in a BMP via LSB steganography, installed as a Windows service and communicating with a base C2 domain decoded from a config blob.

Operation C, Docro Hijacker, revives chrome-based hijacking, bypassing integrity protections to install a Chrome extension that injects scripts for SERP manipulation and monetisation. In total, more than 10,000 OfferLoader samples were identified, sustaining a large and evolving infection ecosystem that relies on a simple loader to conceal multiple, independent payloads. Palo Alto Networks emphasises vigilance across network gateways, DNS and XDR/XSIAM detection to disrupt the chain.

View full article

Article by CyberSIXT