D-Shortiez is a malvertising threat actor active since at least 2022 that specializes in forced-redirect advertising campaigns leading victims through malicious click-chains to online scam pages. The actor has been associated with large-scale delivery of malicious ad impressions, with activity heavily concentrated on U.S. audiences and additional reach into Canada and parts of Europe. iOS users, particularly Safari users, have been a predominant target in one of its better-documented campaigns. A defining tradecraft element is browser-based traffic redirection and user-trapping behavior. D-Shortiez payloads have used fingerprinting and tracking logic alongside redirect routines designed to maximize success across browsers. In Safari-focused activity, the actor abused browser history manipulation and popstate handling to hijack the back button, effectively trapping users on scam destinations in a browlock-like manner. This reflects strong capabilities in malicious ad delivery, client-side reconnaissance, and defense-evasive redirect optimization rather than traditional endpoint compromise. The actor has operated multiple scam themes. Earlier campaigns pushed victims to fake reward and giveaway flows impersonating major consumer brands, including survey funnels and fraudulent prize-claim pages designed to extract payment-card information or monetize victims through affiliate offers. By 2025, D-Shortiez also expanded into Microsoft Windows-themed tech support scams, using shared infrastructure and the Binom traffic distribution system to steer different victim devices to different scam experiences, including serving tech support scams to Windows users and reward scams to mobile users. Operationally, D-Shortiez has shown sustained campaign management, use of disposable domain infrastructure, and exposed internal testing and administrative pages that revealed pre-launch staging, ad-tag management, and campaign approval workflows. Evidence from infrastructure choices, Chinese-language comments in administrative resources, and use of the Chinese-language Baota/Pagoda hosting panel is consistent with Chinese-speaking operators. A later campaign cluster was linked to origin infrastructure in Hong Kong. High-confidence reporting supports classifying D-Shortiez as a financially motivated malvertising and scam operator rather than a state-sponsored espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
99 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Runs a persistent malvertising/forced-redirect campaign primarily targeting iOS Safari users. Uses a WebKit/Safari-specific back-button hijack via the popstate event and history.pushState() to trap users on scam pages, delivered at large scale through malicious ad impressions and click-chains.
Malvertising/forced-redirect operator running large-scale malicious ad impression campaigns that push victims through click-chains to scams, using browser history manipulation (pushState/onpopstate) for back-button hijacking; primarily targets iOS/Safari users.
Malvertising group operating a test platform used to stage/preview malicious ad campaigns; associated with large-scale malicious ad delivery activity.
Malvertising actor operating large-scale forced-redirect ad campaigns that route victims to scam landing pages. In 2025 they ran both fake reward/giveaway scams (Google-branded survey/affiliate funnels; Amazon-branded fake prize checkout collecting card data) and Microsoft Windows-branded tech support scams impersonating Windows Defender. They used Binom TDS to segment payload/scam type by device (Windows to tech-support scams; mobile to reward scams) and relied on Cloudflare to mask origin infrastructure; operational security failures exposed internal test pages and an admin panel used to manage campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.