AdGholas is a financially motivated cybercriminal group known for large-scale malvertising campaigns that distribute banking malware and ransomware. Its campaigns have exposed millions of users to malicious advertisements, including visitors to popular news websites, and have targeted countries across Europe, North America, and the Asia-Pacific region. Vulnerable users can be infected merely by loading an advertisement, without clicking it. The group's country of origin is not established. AdGholas combines steganography, selective visitor profiling, and extensive anti-analysis checks to conceal its infection chains. Malicious advertising images hide JavaScript in their alpha-channel values, while server-side filtering determines whether visitors receive benign or malicious advertisements. The group exploited browser information-disclosure vulnerabilities, including CVE-2016-3351 and CVE-2016-3298, to identify software configurations associated with researchers and analysis environments. Additional checks detect virtualization, packet-capture tools, debuggers, and security products before permitting exploitation or payload delivery. Its infrastructure has used encrypted communications, HTTPS, domain shadowing, and encrypted payloads disguised as images. The group used Angler and Neutrino exploit kits before adopting Stegano, also known as Astrum. Its exploitation chains leveraged Internet Explorer and Adobe Flash vulnerabilities and executed payloads through legitimate Windows utilities. Observed payloads included Ursnif and Ramnit, supporting credential theft, keylogging, surveillance, backdoor access, and information exfiltration, with a focus on banking and corporate payment services. AdGholas-associated Astrum infection chains also distributed Mole ransomware, a member of the CryptFile2/CryptoMix family.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Known CVEs used by Astrum include CVE-2016-0189 [7], CVE-2016-1019 [6], and CVE-2016-4117 [8].
On September 13, 2016 Microsoft released a security bulletin fixing the CVE-2016-3351 vulnerability, which included a patch for Internet Explorer and Edge browsers. Researchers found exploitation dating back to January 2014, including a malvertising chain leading to Angler EK and dropping Reveton.
Known CVEs used by Astrum include CVE-2016-0189 [7], CVE-2016-1019 [6], and CVE-2016-4117 [8].
The landing page loads a Flash file that is able to exploit three different vulnerabilities (CVE-2015-8651, CVE-2016-1019, CVE-2016-4117), depending on the version of Flash found on the victim's system.
Using the known Internet Explorer vulnerability CVE-2016-0162, the encoded script attempts to verify that it is not being run in a monitored environment such as a malware analyst’s machine.
2 more CVEs tied to this actor tracked in Mallory.
35 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting large-scale malvertising campaigns that redirect victims through an infection chain to the Astrum exploit kit, resulting in ransomware infections in the UK and likely banking trojan infections in other countries.
Malvertising campaign distributing the Stegano exploit kit via malicious ads on popular news websites, using steganography and multiple anti-analysis checks to redirect victims to exploit infrastructure and deliver payloads including banking malware.
A named malvertising campaign whose operators previously used Angler and Neutrino exploit kits before switching to Stegano, also known as Astrum. The analyzed wave, traced to at least October 2016, distributed malicious advertisements through popular websites, concealed JavaScript in banner images, and exploited vulnerable browsers and Flash installations without user interaction. Delivered payloads included Ursnif and Ramnit, supporting credential theft, surveillance, backdoor access, and financial-sector compromise. The report describes earlier Stegano activity targeting the Netherlands and Czech Republic, followed by targeting of Canada, Britain, Australia, Spain, and Italy.
Conducts malvertising campaigns using browser information-disclosure vulnerabilities to identify consumer systems and avoid exposing operations to security researchers, vendors, and sandboxes. The report documents CVE-2016-3298 exploitation code in its July 2016 campaign.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.