Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
SlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally. The threat actors utilize steganography, hidden WebViews, and a mobile marketing attribution platform to execute their fraud schemes, which include generating fraudulent ad impressions and clicks. Their infrastructure comprises multiple C2 servers and over 300 related domains, indicating plans for expansion. The operation has been linked to 2.3 billion bid requests per day, with significant traffic originating from the United States, India, and Brazil.
Targeted Sectors
Executive Summary
SlopAds is a sophisticated ad fraud and click fraud operation characterized by its large-scale app distribution network, technical capabilities including steganography and hidden WebViews, and significant global impact. The actor's infrastructure, which includes multiple C2 servers and hundreds of domains, enables the generation of billions of fraudulent bid requests daily, primarily targeting the United States, India, and Brazil. This activity poses a substantial financial threat to advertisers and digital marketing ecosystems.
Goals & Targeting
SlopAds' strategic objectives appear to center around maximizing financial gain through large-scale ad fraud. The group targets sectors heavily involved in online advertising, such as digital marketing platforms and advertisers, leveraging their access to vast user populations via mobile apps. Their targeting of countries with high digital advertising activity, particularly the U.S., India, and Brazil, reflects a focus on regions with significant ad spend and where fraudulent traffic can be monetized effectively. The actor's victims are typically entities involved in mobile advertising ecosystems, including app developers, advertisers, and marketing platforms.
Enhanced Description
SlopAds represents a high-level ad fraud operation that leverages a network of 224 malicious apps, which have been downloaded over 38 million times globally. The group employs advanced techniques such as steganography and hidden WebViews to execute their schemes, which primarily involve generating fraudulent ad impressions and clicks through a mobile marketing attribution platform. This platform is used to mask the true origin of traffic, making it appear legitimate while directing revenue to fraudulent sources. SlopAds' infrastructure includes multiple command-and-control (C2) servers and over 300 related domains, indicating a robust operational capability and potential for expansion. The group's activities are linked to an estimated 2.3 billion bid requests per day, with significant concentrations of traffic originating from the United States, India, and Brazil. This level of activity suggests that SlopAds is not only a financially motivated threat actor but also one with a sophisticated understanding of how to exploit digital advertising ecosystems on a global scale.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SlopAds' campaigns exhibit a high volume of activity, with daily bid requests reaching over 2.3 billion, indicating a large-scale operation capable of affecting multiple industries globally. The group targets regions with high ad spend and digital marketing activity, such as the U.S., India, and Brazil, suggesting a strategic focus on maximising profitability. Notable campaign patterns include the use of legitimate-looking mobile apps to distribute malicious traffic, the employment of hidden WebViews to route ad revenue away from legitimate sources, and the deployment of botnets for generating fake impression and click data. The group's ability to expand its infrastructure, including C2 servers and domains, underscores its long-term strategic goals in dominating the ad fraud ecosystem.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the data regarding SlopAds is high, as their operations have been observed on a large scale and involve distinctive techniques such as steganography in mobile apps. However, gaps exist in understanding the exact affiliations or potential state-sponsored connections of the group. Additionally, the full extent of their campaign activities beyond the known IOC patterns remains unclear.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics