logo

No Reach, No Risk: The Keitaro Abuse in Modern Cybercrime Distribution

ID: 49cd7edf-69b4-5015-8a9c-5490601d3620

STIX ID: report--49cd7edf-69b4-5015-8a9c-5490601d3620

Feed Name: Infoblox Threat Intel Blog

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Infoblox Threat Intel and Confiant analyzed widespread abuse of Keitaro, an all‑in‑one adtech/tracker, showing how diverse criminal actors leverage its tracking, cloaking, and TDS capabilities to run large-scale malvertising, phishing, wallet‑drainer and PII‑harvesting campaigns; the report documents malware (loaders and stealers), high-volume spam and programmatic ads, domain‑hijacking, and TTPs used to evade detection, and provides numerous indicators and infrastructure ties (e.g., AS214351, Cloudflare-fronted hosts).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.