Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Phlox Tempest

Also known as: DEV-0796

Description

Phlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious ads. They use ChromeLoader to infect victims' computers with malware, often delivered as ISO image files that victims are tricked into downloading. The attackers aim to profit from clicks generated by malicious browser extensions or node-WebKit installed on the victim's device. Microsoft and other cybersecurity organizations have issued warnings about this ongoing and prevalent campaign.

AI Analysis

· 1 week ago

Executive Summary

Phlox Tempest, also known as DEV-0796, is a threat actor conducting large-scale click fraud campaigns. They use ChromeLoader malware to infect users through malicious YouTube comments and ads, aiming to generate profit from fraudulent ad clicks.

Goals & Targeting

Phlox Tempest targets individuals across various sectors, particularly those in regions with high online advertising activity. Their focus is to maximize ad impressions through infected devices, leading businesses into financial losses and reputational damage due to click fraud.

Enhanced Description

Phlox Tempest operates a significant click-fraud campaign, exploiting users via malicious Chrome extensions and ISO files. Their primary vector involves distributing these files through compromised YouTube accounts and malicious广告. Infection leads to browser-based malicious activities aimed at generating fraudulent clicks for financial gain. The group's operations have been noted by Microsoft and other cybersecurity firms, highlighting the persistent nature of their campaigns.

Key Capabilities

  • Use of ChromeLoader malware
  • Social engineering via malicious YouTube comments
  • Malicious ISO file distribution

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Network Operations

ATT&CK Techniques

T1566
T1070
T1059

Software / Tooling

ChromeLoader

Campaigns & Victims

Phlox Tempest engages in sustained campaigns, leveraging weekends for increased activity. Targets include users globally but with higher focus on regions where online ads are prevalent.

IOC Patterns

  • Distribution of malicious ISO files via phishing
  • C2 communication via HTTP/HTTPS channels

Recommended Actions

  • Implement user education on phishing and suspicious links
  • Monitor network traffic for C2 patterns
  • Enhance endpoint detection with EDR solutions

Suggested Tags

Click Fraud
Malware

Confidence Assessment

High confidence due to clear evidence of activity. Technique details could be deeper.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Click Fraud
Malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.