Subscribe
Sign in
Home
Notes
Archive
About
Tracking Software Weaponized by Criminals
Inside four months of joint research with Infoblox Threat Intel on the abuse of Keitaro Software.
Mar 24
•
Confiant
2
1
Latest
Top
Analyzing a Live AiTM Attack Targeting Google Accounts via Malvertising
We captured a malvertising campaign delivering an Adversary-in-the-Middle (AiTM) kit. Here, we unpack a paradox— an advanced payload undermined by…
Published on Roshan
•
Mar 24
Malvertiser “D-Shortiez” abuses WebKit back button hijack in forced-redirect campaign
Over the last few years, as AdTech and browser security has continued to mature, many malvertisers have moved on from forced redirect campaigns that…
Mar 2
•
Confiant
and
Eliya Stein
Disrupting 59M Malicious Impressions: Inside D-Shortiez Testing Infrastructure and Campaign Management
Two clusters, one password, and the automated harvesting that blocked campaigns before deployment
Feb 24
•
Confiant
and
Michael Steele
3
4
The Curious Case Of MutantBedrog's Trusted-Types CSP Bypass
MutantBedrog is a malvertiser that caught our attention early summer ’24 for their highly disruptive forced redirect campaigns and the unique JavaScript…
Feb 3
•
Confiant
and
Eliya Stein
2
1
How One "Crypto Drainer" Template Facilitates Tens Of Millions Of Dollars In Theft
Crypto Drainers are phishing pages that lure victims into signing malicious transactions that allow the attacker to siphon their crypto and NFTs.
Feb 3
•
Confiant
and
Eliya Stein
3
1
A Whirlwind Tour Of Crypto Phishing
The post-pandemic world has seen cryptocurrencies and blockchain products in general catapult in valuation and adoption.
Feb 3
•
Confiant
and
Eliya Stein
3
1
How File Hashes Fail As A Malware Detection Heuristic
In this blog post we take a trip downstream from malvertising delivery mechanisms and take a close up look at a fake Flash update landing page that was…
Feb 3
•
Confiant
and
Eliya Stein
3
1
See all
Confiant
Field Intelligence for the Ad Economy
Subscribe
Recommendations
Roshan
Roshan
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts