Inside Keitaro Abuse: A Persistent Stream of AI-Driven Investment Scams
ID: 78c07c50-1d9b-5666-88bf-eeb76bd8a73e
STIX ID: report--78c07c50-1d9b-5666-88bf-eeb76bd8a73e
Feed Name: Infoblox Threat Intel Blog
Infoblox and Confiant analyzed four months of data revealing extensive abuse of the Keitaro Tracker by criminal operators who deploy domain cloaking, conditional routing, AI-generated content and deepfakes to run large-scale investment scams, tech-support fraud, giveaway/phishing funnels, and other ad-driven scams; the research identifies thousands of malicious Keitaro instances (≈15,500 domains), named actor clusters (e.g., FaiKast, WickedWally, FishSteaks), common TTPs, and a curated set of IOCs used for remediation and takedowns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
