Patterns, Pirates, and Provider Action: What We Learned Working with Keitaro
ID: 3d6056f1-b00a-57f5-827c-5d76be72c66f
STIX ID: report--3d6056f1-b00a-57f5-827c-5d76be72c66f
Feed Name: Infoblox Threat Intel Blog
This report analyzes large-scale abuse of the Keitaro self-hosted tracker as a traffic distribution system by multiple criminal actors. Using telemetry from Infoblox and Confiant (DNS, email, and ad-impression data), the authors document thousands of malicious domains, actor campaigns (including TA2726), extensive malvertising and spam-driven crypto wallet scams, techniques for cloaking and client-side substitution, cracked/stolen licenses, cookie collisions that complicate attribution, and the results of coordinated abuse reporting and takedown engagement with Keitaro.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
