Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Tracked as CL-CRI-1171, in accordance with Unit 42’s attribution framework , the group behind this cluster has operated under the radar for at least two years, distributing an indeterminate number of payloads.

Tracked as CL-CRI-1171, in accordance with Unit 42’s attribution framework , the group behind this cluster has operated under the radar for at least two years, distributing an indeterminate number of payloads. The group behind CL-CRI-1171 provides an infection service for other threat actors who want to spread their malware indiscriminately. The SEO funnel targeted a more professional audience, promoting trojanized software that resulted in malware deployment on corporate endpoints, including critical infrastructure and even government entities. We provide an overview of the cybercrime cluster and its loader infrastructure, and a technical analysis of three recently delivered malware strains.
This is an evasion tactic used to ensure that only real targets are infected, and to protect the actor’s infrastructure: scanners, crawlers or analysts receive a decoy clone of the legitimate WinRAR download page or broken links.
The result is a single infection that conceals multiple payloads from unrelated threat actors on the same endpoint, each with its own C2 infrastructure and objectives.
The shared infrastructure between the YouTube and SEO funnels, consistent use of the same loader and a rotational domain pattern observed over an eight-month window all pointed to a single sustained operation, which we track as CL-CRI-1171. The loader was unnamed, untracked and generic enough to be dismissed as commodity adware. Pivoting on the loader's C2 infrastructure revealed a sprawling network of rotational domains — over 200 unique hostnames following a distinctive two-word compound naming pattern (including bubbleslip , churchpail , dinosaursjam ), rotating across .xyz , .cfd , .space and .info top-level domains (TLDs). Our investigation revealed three malware strains delivered by the group behind CL-CRI-1171 between June 2025 and April 2026.
What changed
The payloads delivered through CL-CRI-1171's infrastructure are not fixed, enabling the simultaneous delivery of unrelated malware families.
From this point forward, each child process operates as an independent malware campaign with its own infrastructure, C2 protocol and objectives.
Who is affected
Those links pass through intermediary sites, such as Blogspot, which contain social-engineering instructions that lead the victim to the same PPI gate infrastructure serving the SEO path.
Why this matters
This is an evasion tactic used to ensure that only real targets are infected, and to protect the actor’s infrastructure: scanners, crawlers or analysts receive a decoy clone of the legitimate WinRAR download page or broken links.
The technical picture
The result is a single infection that conceals multiple payloads from unrelated threat actors on the same endpoint, each with its own C2 infrastructure and objectives.
How organizations are responding
The shared infrastructure between the YouTube and SEO funnels, consistent use of the same loader and a rotational domain pattern observed over an eight-month window all pointed to a single sustained operation, which we track as CL-CRI-1171.
The loader was unnamed, untracked and generic enough to be dismissed as commodity adware.
Pivoting on the loader's C2 infrastructure revealed a sprawling network of rotational domains — over 200 unique hostnames following a distinctive two-word compound naming pattern (including bubbleslip , churchpail , dinosaursjam ), rotating across .xyz , .cfd , .space and .info top-level domains (TLDs).
Our investigation revealed three malware strains delivered by the group behind CL-CRI-1171 between June 2025 and April 2026.
What to watch next
Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.