BRS is a malvertising threat actor designation associated with a tracked campaign in the online advertising ecosystem. The actor is linked to malvertising operations that abuse ad-tech infrastructure and real-time bidding workflows to place or deliver malicious advertising content to users. Reported tradecraft for this class of actor includes gaining initial access to the advertising supply chain through fake agencies or fraudulent ad creatives, using forceful redirects to execute malicious activity, maintaining campaign persistence within ad networks while evading detection, and applying cloaking techniques to selectively expose malicious landing pages based on fingerprinting or other filtering logic. Malvertising operations of this type can deliver drive-by downloads, exploit-kit activity, scams, or other malware-enabled follow-on effects, and may also involve defense evasion, browser exploitation, credential access, and broader impact such as financial loss or resource hijacking. No high-confidence attribution to a specific country, victim geography, or industry sector is currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor label used for a specific malvertising campaign (TI 950451017) represented in STIX 2.1, leveraging malvertising attack patterns mapped to Confiant’s Malvertising Attack Matrix.
Threat actor dubbed BRS associated with a malvertising campaign represented in Confiant's STIX v2.1 feed.
Threat actor dubbed BRS associated with a detected malvertising campaign in Confiant's feed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.