logo

Inside Keitaro Abuse: A Persistent Stream of AI-Driven Investment Scams

ID: 417199f9-79c5-5276-9878-9ee3d5cd81bd

STIX ID: report--417199f9-79c5-5276-9878-9ee3d5cd81bd

Feed Name: Infoblox Blog

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This joint Infoblox–Confiant report analyzes widespread criminal abuse of the Keitaro Tracker to perform domain cloaking and conditional traffic routing for large-scale ad-driven fraud and malware delivery. Over a four-month window the teams observed thousands of malicious Keitaro instances and roughly 15,500 domains used in scams and distribution, with prominent use of AI (deepfakes, AI‑generated content) to amplify investment scams, tech‑support fraud, and phishing; the report catalogs TTPs, sample indicators, actor clusters (FaiKast, WickedWally, FishSteaks, TA2726), and vendor takedown outcomes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.