Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors HookAds

Description

HookAds is a malvertising campaign that purchases cheap ad space on low quality ad networks commonly used by adult web sites, online games, or blackhat seo sites. These ads will include JavaScript that redirects a visitor through a serious of decoy sites that look like pages filled with native advertisements, online games, or other low quality pages. Under the right circumstances, a visitor will silently load the Fallout exploit kit, which will try and install its malware payload.

AI Analysis

· 1 week ago

Executive Summary

HookAds is a malvertising campaign targeting victims through low-quality ad networks. It redirects users to decoy sites and deploys the Fallout exploit kit to deliver malware payloads. The campaign primarily operates across various sectors, including adult websites and online gaming platforms, aiming to infect devices for malicious purposes.

Goals & Targeting

HookAds targets sectors with high ad traffic but lower security standards, such as adult content, online gaming, and blackhat SEO sites. The campaign likely seeks to maximize reach while minimizing detection by targeting platforms that are more susceptible to exploitation. Victims are typically end-users visiting these compromised websites, making the attack vector both broad and targeted in terms of user behavior.

Enhanced Description

HookAds is a sophisticated malvertising campaign that leverages cheap ad space on low-quality ad networks often frequented by adult websites and online gaming sites. The campaign uses JavaScript-based redirects to steer users through decoy sites designed to mimic legitimate content like native advertisements or online games. These redirects ultimately lead to the deployment of the Fallout exploit kit, which attempts to install malware on the victim's device. The primary goal appears to be distributing malicious payloads, likely for financial gain or data collection purposes. HookAds operates discretely by using multiple layers of redirection and low-quality sites, making it harder to trace back to its origins.

Key Capabilities

  • Malvertising campaigns
  • Browser exploit kits (e.g., Fallout)
  • Drive-by download attacks
  • Multi-stage redirects

MITRE ATT&CK Tactics

Exfiltration
Collection

ATT&CK Techniques

T1068.004
T1539.001

Software / Tooling

Fallout Exploit Kit

Campaigns & Victims

HookAds operates campaigns that involve distributing malicious ads across multiple ad networks. The campaign's operational tempo is focused on volume, targeting users with high susceptibility to such attacks. Past operations have shown a preference for redirecting users through layers of decoy sites before deploying the exploit kit. Notable campaigns include those using adult content and online gaming sites as entry points.

IOC Patterns

  • Malicious ad placements leading to redirection chains
  • JavaScript injection in legitimate-looking websites
  • Presence of known Fallout exploit kit components

Recommended Actions

  • Implement ad-blocking technologies and browser extensions for end-users
  • Monitor network traffic for unusual domains associated with adult websites or gaming platforms
  • Educate users on the risks of clicking on suspicious ads or pop-ups
  • Enforce strict software updates and patching schedules to reduce exploit success rates

Suggested Tags

malware
exploit_kit
malvertising
drive-by_downloads

Confidence Assessment

Confidence in the data is high for TTPs like malvertising and exploit kit usage. Limited information exists on the specific goals, targeting countries, or advanced capabilities beyond malware distribution. Additional intelligence gaps include detailed campaign timelines and exact geographic targeting patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

malware
exploit_kit
malvertising
drive-by_downloads

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.