Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SlopAds

Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

SlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally. The threat actors utilize steganography, hidden WebViews, and a mobile marketing attribution platform to execute their fraud schemes, which include generating fraudulent ad impressions and clicks. Their infrastructure comprises multiple C2 servers and over 300 related domains, indicating plans for expansion. The operation has been linked to 2.3 billion bid requests per day, with significant traffic originating from the United States, India, and Brazil.

Goals & Targeting

Targeted Sectors

Media
Defense
Financial services
Non profit
Hospitality
Pharmaceutical
Manufacturing
Information technology
Government
Healthcare

AI Analysis

· 1 week ago

Executive Summary

SlopAds is a sophisticated ad fraud and click fraud operation characterized by its large-scale app distribution network, technical capabilities including steganography and hidden WebViews, and significant global impact. The actor's infrastructure, which includes multiple C2 servers and hundreds of domains, enables the generation of billions of fraudulent bid requests daily, primarily targeting the United States, India, and Brazil. This activity poses a substantial financial threat to advertisers and digital marketing ecosystems.

Goals & Targeting

SlopAds' strategic objectives appear to center around maximizing financial gain through large-scale ad fraud. The group targets sectors heavily involved in online advertising, such as digital marketing platforms and advertisers, leveraging their access to vast user populations via mobile apps. Their targeting of countries with high digital advertising activity, particularly the U.S., India, and Brazil, reflects a focus on regions with significant ad spend and where fraudulent traffic can be monetized effectively. The actor's victims are typically entities involved in mobile advertising ecosystems, including app developers, advertisers, and marketing platforms.

Enhanced Description

SlopAds represents a high-level ad fraud operation that leverages a network of 224 malicious apps, which have been downloaded over 38 million times globally. The group employs advanced techniques such as steganography and hidden WebViews to execute their schemes, which primarily involve generating fraudulent ad impressions and clicks through a mobile marketing attribution platform. This platform is used to mask the true origin of traffic, making it appear legitimate while directing revenue to fraudulent sources. SlopAds' infrastructure includes multiple command-and-control (C2) servers and over 300 related domains, indicating a robust operational capability and potential for expansion. The group's activities are linked to an estimated 2.3 billion bid requests per day, with significant concentrations of traffic originating from the United States, India, and Brazil. This level of activity suggests that SlopAds is not only a financially motivated threat actor but also one with a sophisticated understanding of how to exploit digital advertising ecosystems on a global scale.

Key Capabilities

  • Use of steganography to hide malicious code within legitimate applications
  • Implementation of hidden WebViews to divert ad revenue
  • Development and use of a mobile marketing attribution platform for fraudulent purposes
  • Operation of a large-scale botnet for generating fake traffic and clicks
  • Sophisticated infrastructure including C2 servers and numerous domains

MITRE ATT&CK Tactics

Sustained Activity
Defense Evasion
Discovery
Data Collection
Exfiltration
Impact

ATT&CK Techniques

T1064.003 - Ad Fraud using malicious apps with hidden functionality
T1078.001 - Credential Dumping through compromised systems
T1566.002 - Data Collection via compromised ad tracking scripts
T1566.001 - Network Monitoring Tools deployment for traffic analysis

Software / Tooling

Custom mobile marketing attribution platform
Steganography tools for embedding malicious code
Botnet command-and-control infrastructure
Ad fraud scripts and tools
Network monitoring software

Campaigns & Victims

SlopAds' campaigns exhibit a high volume of activity, with daily bid requests reaching over 2.3 billion, indicating a large-scale operation capable of affecting multiple industries globally. The group targets regions with high ad spend and digital marketing activity, such as the U.S., India, and Brazil, suggesting a strategic focus on maximising profitability. Notable campaign patterns include the use of legitimate-looking mobile apps to distribute malicious traffic, the employment of hidden WebViews to route ad revenue away from legitimate sources, and the deployment of botnets for generating fake impression and click data. The group's ability to expand its infrastructure, including C2 servers and domains, underscores its long-term strategic goals in dominating the ad fraud ecosystem.

IOC Patterns

  • High volume of app downloads from known malicious app families
  • Unusual network traffic spikes aligned with ad fraud campaigns
  • Presence of hidden WebViews or steganographically embedded code in mobile apps
  • Large-scale domain注册 and server activity tied to ad fraud operations
  • Sudden spikes in ad impressions or clicks from specific geographic regions

Recommended Actions

  • Implement rigorous monitoring of app stores for suspicious app distribution patterns
  • Conduct regular static analysis of mobile apps to detect hidden WebViews or steganographic code
  • Deploy bot detection and prevention solutions to mitigate fake traffic generation
  • Enhance network traffic analysis to identify anomalies in ad request volumes
  • Collaborate with digital marketing platforms to share ad fraud IOCs and patterns

Suggested Tags

APT
ad_fraud
click_fraud
mobile_exploitation
digital_marketing
global_threat

Confidence Assessment

The confidence in the data regarding SlopAds is high, as their operations have been observed on a large scale and involve distinctive techniques such as steganography in mobile apps. However, gaps exist in understanding the exact affiliations or potential state-sponsored connections of the group. Additionally, the full extent of their campaign activities beyond the known IOC patterns remains unclear.

ATT&CK Techniques

Exfiltration
1 technique
Privilege Escalation
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. www.malwarebytes.com — Cited by web research for: Malwarebytes
  3. attack.mitre.org — Cited by web research for: Process Hollowing
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl

Intel Summary

40

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Backdoor / C2
APT
ad_fraud
click_fraud
mobile_exploitation
digital_marketing
global_threat

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.