Cybercriminals are creating malware traps by using legitimate search queries and gaming videos as bait.
Indicators of Compromise (IoCs): - Type: Trojanized windirstat.exe - OfferLoader installer delivered through SEO poisoning - Type: windirstat.tmp - Unpacked OfferLoader stage - Type: eld0.exe, Insomnia RAT initial loader - Type: eld0.tmp - Unpacked loader stage - Type: a.dll, PowerShell downloader for Insomnia RAT stages - Type: t.ps1, Insomnia RAT PowerShell loader - Type: Python component of the Insomnia RAT dual payload - Type: aa.js, Node.js component of the Insomnia RAT dual payload - Type: eld1.exe, ARKTunnel steganography dropper - Type: procorTrex.zip - Archive extracted from the bitmap payload - Type: wscl.exe - ARKTunnel WebSocket tunneling RAT - Type: Resource icon shared across ARKTunnel samples - Type: eld2.exe - Docro Hijacker branch installer - Type: eld2.tmp - Unpacked Docro Hijacker stage - Type: Adblock.dll - Chrome Secure Preferences bypass DLL - Type: File name: windirstat.exe; windirstat.tmp; eld0.exe; eld0.tmp; a.dll; t.ps1;
]xyz/33244556546.py - Stage-three Python Insomnia RAT agent - Type: URL: hxxps[:]//drelto[. ]info/farlix - Search-result injection script host - Type: Domain: stryper[. ]info; aa.amazingshield[. ]xyz; drelto[.
]info - Potential malicious domains - Type: Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking.












