AdGholas is a financially motivated cybercriminal threat actor known for large-scale malvertising operations that silently profile visitors to legitimate websites and selectively redirect suitable victims into exploit-kit chains. The group is widely associated with the Stegano exploit kit, also known as Astrum, and had previously used Angler and Neutrino. Its campaigns relied on compromised or abused advertising infrastructure, smart filtering, anti-analysis checks, HTTPS delivery, and steganography to conceal malicious JavaScript inside advertisement images. Victims could be infected through drive-by exposure without clicking an advertisement. AdGholas campaigns gathered host and browser characteristics server-side, returned either benign or weaponized ad content, and redirected selected users to exploit infrastructure. Observed exploit activity targeted Internet Explorer and Adobe Flash vulnerabilities including CVE-2015-8651, CVE-2016-1019, CVE-2016-4117, CVE-2016-0189, and CVE-2016-0162. The exploit chain incorporated extensive sandbox, debugger, virtualization, packet-capture, and security-tool checks before delivering encrypted payloads disguised as image content and executing them through trusted Windows utilities such as regsvr32.exe or rundll32.exe. The actor has been linked to delivery of banking malware and ransomware. Observed payloads included Ursnif and Ramnit, indicating credential theft, keylogging, backdoor-style post-exploitation, and data theft capabilities, particularly against payment-related and banking targets. In June 2017, AdGholas activity was assessed as the infection vector behind ransomware incidents affecting multiple universities in the United Kingdom, with the Astrum chain delivering Mole ransomware. Reporting also assessed that banking trojans were likely delivered in other regions during the same broader campaign. Geographically, AdGholas activity has targeted users in Europe, North America, Asia-Pacific, and the United States, with documented focus including the United Kingdom, Canada, Australia, Italy, Spain, the Netherlands, the Czech Republic, Japan, Taiwan, Switzerland, Liechtenstein, Luxembourg, Monaco, and likely the United States. The actor is best characterized as an opportunistic but selectively filtered malvertising operator whose infrastructure and payload choices vary by region and campaign phase.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Known CVEs used by Astrum include CVE-2016-0189 [7], CVE-2016-1019 [6], and CVE-2016-4117 [8].
Known CVEs used by Astrum include CVE-2016-0189 [7], CVE-2016-1019 [6], and CVE-2016-4117 [8].
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
Using the known Internet Explorer vulnerability CVE-2016-0162, the encoded script attempts to verify that it is not being run in a monitored environment such as a malware analyst’s machine.
Known CVEs used by Astrum include CVE-2016-0189 [7], CVE-2016-1019 [6], and CVE-2016-4117 [8].
35 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting large-scale malvertising campaigns that redirect victims through an infection chain to the Astrum exploit kit, resulting in ransomware infections in the UK and likely banking trojan infections in other countries.
Malvertising campaign distributing the Stegano exploit kit via malicious ads on popular news websites, using steganography and multiple anti-analysis checks to redirect victims to exploit infrastructure and deliver payloads including banking malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.