216.73.217.80

Inside Keitaro Abuse Part 2: One Platform, Many Threats

· Published 27/03/2026 08:46 · Modified 27/03/2026 09:59

Export JSON

Essential information

Published
27/03/2026 08:46
Modified
27/03/2026 09:59
Tags
2026-03-27 cloaking domain hijacking donutloader keitaro phishing rustystealer screenconnect stealc traffic distribution
Related entities
3 observables, 10 techniques (mitre), 4 malware, 100 others

Description

This analysis examines how threat actors abuse , an advertising performance tracker, for various malicious purposes. The report covers a wide range of threats, including malware delivery, , scams, and illegal content distribution. Key findings include the use of for and in malvertising campaigns, spam operations leveraging for cryptocurrency wallet draining, and the abuse of in investment scams. The report also highlights specific threat actors and their tactics, such as for adult content delivery and the use of fake arrests as clickbait for investment scams. Overall, the analysis demonstrates how 's features make it attractive to cybercriminals seeking to maximize their reach with minimal effort.

External references