logo

Inside a Malicious Push Network: What 57M Logs Taught Us

ID: 612e7cc0-53d0-546e-aee6-4eba7dc71d63

STIX ID: report--612e7cc0-53d0-546e-aee6-4eba7dc71d63

Feed Name: Infoblox Threat Intel Blog

Threat Score
50/100

Date Published: 2026-01-15

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Researchers exploited lame DNS delegations to claim abandoned domains used by a global push-notification affiliate ad network, passively collecting ~57M events and 60GB of JSON over ~15 days; analysis exposed large-scale deceptive/sCAM push notifications in 60+ languages, detailed subscriber metadata, the actor’s fraud mitigation and pricing practices, low effective CTRs and modest revenue, and confirmed that no malware payloads were delivered via the sampled network.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.