ScamClub is a prolific malvertising threat actor operating in the programmatic advertising ecosystem. The group abuses real-time bidding integrations with ad exchanges to inject malicious JavaScript into advertising flows and force browser redirects from legitimate publisher sites to scam landing pages without meaningful user interaction. Its operations are designed to scam and defraud victims at scale, primarily through affiliate-driven fraud schemes. ScamClub commonly uses a multi-stage payload chain. A lightly obfuscated initial ad creative leads to a second-stage script that fingerprints victims and determines whether to continue, followed by a third-stage redirect component that sends users to ScamClub-controlled landing pages. The actor uses extensive obfuscation and anti-analysis measures, including layered JavaScript obfuscation, runtime string decryption, wrapper functions for identifiers and operators, and randomized first-layer encoding that complicates signature- and hash-based detection. Victim profiling has included attributes such as geography, language, ISP, operating system, browser, and screen characteristics, enabling selective delivery and cloaking. The actor’s landing pages have impersonated well-known brands including Google, telecom operators, and McAfee. Observed scam flows have included fake prize surveys, giveaway and gift-card scams, phishing-style lures, and scareware pages that falsely claim malware infection. ScamClub has also used anti-navigation JavaScript to interfere with refresh, back, and forward actions and to keep victims trapped in scam flows. Rather than owning all downstream monetization infrastructure, ScamClub has been observed funneling victims to third-party affiliate offer and payment pages, including misleading low-cost trial offers that convert into recurring subscription charges. Public reporting estimated the operation generated approximately $8.5 million in revenue during the first half of 2023. ScamClub has been tracked alongside other malvertising actors such as Zirconium, eGobbler, DCCBoost, Tag Barnakle, and YoSec. Available reporting ties ScamClub firmly to large-scale malvertising and online fraud, but does not establish a confirmed nation-state sponsor. References to tooling overlap with obfuscation seen among various Chinese threat actors do not, by themselves, support attribution of ScamClub to China.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
29 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ad-fraud/malvertising operation abusing programmatic advertising (RTB) to deliver multi-stage, heavily obfuscated JavaScript that fingerprints users/environments and then forces redirects to scam and phishing landing pages (e.g., gift card/giveaway scams). Uses a custom obfuscator (not publicly available) and employs anti-analysis techniques (string array encryption, operator/identifier wrapping) to hinder detection and reverse engineering.
Named malvertising threat actor focused on scam-oriented landing pages delivered through the ad-tech ecosystem (often via redirects and cloaking).
Malvertising actor using high-volume ‘bombardment’ to evade/overwhelm defenses and push dangerous ad demand through platforms.
Malvertising threat actor conducting affiliate fraud and scam campaigns via real-time bidding ad-tech abuse, forceful browser redirects, fake prize/giveaway surveys, carrier- and brand-impersonation pages, and scareware pages that funnel victims to third-party payment/subscription offers for profit.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.