logo

Inside a Malicious Push Network: What 57M Logs Taught Us

ID: 7e479734-4f75-5fdc-bb8e-5f1f21de62af

STIX ID: report--7e479734-4f75-5fdc-bb8e-5f1f21de62af

Feed Name: Infoblox Blog

Threat Score
50/100

Date Published: 2026-01-15

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This research details a large-scale push-notification malvertising campaign that used deceptive, multilingual notifications to deliver scam and adult-content lures worldwide; poor DNS hygiene (lame delegations) allowed researchers to claim abandoned domains and capture ~57M events revealing cleartext tracking, targeting metadata, low click-through rates, and a low-revenue CPM-based economy, with most victims in South Asia and no malware payloads observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.