logo

No Reach, No Risk: The Keitaro Abuse in Modern Cybercrime Distribution

ID: 589626f0-2160-5f93-8e75-abecf5517f7d

STIX ID: report--589626f0-2160-5f93-8e75-abecf5517f7d

Feed Name: Infoblox Blog

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report analyzes widespread abuse of the Keitaro ad-tech tracker by multiple criminal actors, documenting large-scale malvertising and spam campaigns, credential- and wallet-draining phishing, diverse malware delivery (including DonutLoader and StealC v2), domain hijacking and TDS-based routing, and provides actor profiles and a curated list of IOCs and infrastructure tied to bulletproof hosting (e.g., AS214351).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.