Charcoal Stork is a suspected pay-per-install (PPI) distribution cluster active since at least 2022. It is associated with malvertising and search-engine-optimization-driven lure delivery, using installers and archive-like downloads disguised as cracked software, games, fonts, wallpapers, movies, streaming-related content, and other popular downloads to drive victim execution. The cluster is notable for broad, high-volume distribution rather than a single malware family, and is assessed to function as a delivery affiliate or access broker for downstream payload operators. Charcoal Stork has been linked to delivery of multiple payloads, most prominently ChromeLoader, and also SmashJacker and VileRAT. This multi-payload pattern is a key reason it is tracked separately from any one malware family. Early activity used ISO and VBS-based delivery chains, while later campaigns used MSI and EXE installers. Across campaigns, the same underlying binaries were often repackaged under many different lure names, consistent with a scalable installer-distribution service. In ChromeLoader-related intrusions, Charcoal Stork-delivered installers led to staged execution involving PowerShell and NodeJS or NW.js-based components, persistence mechanisms, and installation of a malicious browser extension that hijacks and redirects search traffic. Reported behaviors associated with these delivery chains include persistence, post-exploitation activity in the form of browser manipulation, and exfiltration of harvested search data. Charcoal Stork has also been observed delivering SmashJacker, which used a trojanized archiver to install a malicious browser extension, and later VileRAT, a Python remote-access trojan reportedly associated with DeathStalker. The cluster has shown broad victimization across many organizations and industries, with especially heavy activity observed during parts of 2023. Its operational hallmark is mass distribution through deceptive installers and malvertising rather than narrowly targeted intrusion tradecraft. The dominant motivation is financial, based on its suspected role as a PPI provider monetizing malware installation at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A suspected pay-per-install provider responsible for large-scale initial access and malware delivery campaigns using SEO/malvertising and lure files masquerading as cracked software, games, wallpapers, and streaming content. It delivered multiple payloads including ChromeLoader, SmashJacker, and VileRAT, and was described as the most prevalent threat observed by the source in 2023.
A suspected delivery affiliate tracked separately from ChromeLoader that provides initial access and has delivered multiple payloads including ChromeLoader, SmashJacker, and VileRAT.
Suspected pay-per-install provider using malvertising to distribute installers disguised as cracked games, fonts, or desktop wallpaper.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.