Threat Intelligence

Weekly Threat Roundup: Gaming Videos and 'Trojanized' Software Used to Spread Malware

The Hacker News · 18 Sept 2026
Key Takeaway Train staff to be cautious with downloads from video platforms and search results, and keep endpoint protection and browsers updated to catch trojanized software before it takes hold.

Security researchers have uncovered a threat group, tracked as CL-CRI-1171, that has quietly operated a pay-per-install malware distribution service for at least two years. The group offers other cybercriminals two delivery channels: YouTube gaming videos that lure viewers into downloading malicious tools disguised as game-related content, and a search engine optimisation scheme that pushes trojanized software to a more professional audience, including corporate endpoints, critical infrastructure, and government targets.

Both delivery paths lead to a custom loader called OfferLoader, which has been used to install several dangerous payloads since mid-2025. These include a Chrome backdoor capable of bypassing modern browser security protections, a tunneling remote access trojan, and a newly identified cross-platform backdoor that can infect both Windows and macOS systems. More recently, the same infrastructure has shifted to distributing other malware families.

This case is part of a broader pattern highlighted in this week's roundup: attackers are not always relying on sophisticated new techniques, but are exploiting familiar weak points such as exposed services, outdated software, and trusted platforms like YouTube and search engines to gain a foothold.

malware YouTube scam SEO poisoning backdoor endpoint security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.