Cybercriminals are creating malware traps by using legitimate search queries and gaming videos as bait.

Indicators of Compromise (IoCs): - Type: Trojanized windirstat.exe - OfferLoader installer delivered through SEO poisoning - Type: windirstat.tmp - Unpacked OfferLoader stage - Type: eld0.exe, Insomnia RAT initial loader - Type: eld0.tmp - Unpacked loader stage - Type: a.dll, PowerShell downloader for Insomnia RAT stages - Type: t.ps1, Insomnia RAT PowerShell loader - Type: Python component of the Insomnia RAT dual payload - Type: aa.js, Node.js component of the Insomnia RAT dual payload - Type: eld1.exe, ARKTunnel steganography dropper - Type: procorTrex.zip - Archive extracted from the bitmap payload - Type: wscl.exe - ARKTunnel WebSocket tunneling RAT - Type: Resource icon shared across ARKTunnel samples - Type: eld2.exe - Docro Hijacker branch installer - Type: eld2.tmp - Unpacked Docro Hijacker stage - Type: Adblock.dll - Chrome Secure Preferences bypass DLL - Type: File name: windirstat.exe; windirstat.tmp; eld0.exe; eld0.tmp; a.dll; t.ps1; .py; aa.js - OfferLoader and Insomnia RAT files - Type: File name: eld1.exe; procorTrex.zip; wscl.exe - ARKTunnel delivery and payload files - Type: eld2.exe; eld2.tmp; Adblock.dll - Docro Hijacker installer and Chrome-hijacking components - Type: File path: C:\Users\Public\procorTrex.zip - ARKTunnel ZIP archive extraction location - Type: File path: %TEMP%\Adblock.dll - Chrome preference-bypass DLL location - Type: File path: C:\ProgramData\DocsHelper\docro - Docro Chrome extension installation path - Type: URL: hxxps[:]//stryper[. ]info/t.ps1 - Stage-two PowerShell installer for Insomnia RAT - Type: URL: hxxps[:]//stryper[. ]info/aa.js - Stage-three Node.js Insomnia RAT agent - Type: URL: hxxp[:]//aa.amazingshield[.

]xyz/33244556546.py - Stage-three Python Insomnia RAT agent - Type: URL: hxxps[:]//drelto[. ]info/farlix - Search-result injection script host - Type: Domain: stryper[. ]info; aa.amazingshield[. ]xyz; drelto[.

]info - Potential malicious domains - Type: Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking.