Tag Barnakle is a malvertising threat actor focused on mass compromise of Revive Adserver instances to abuse legitimate publisher advertising inventory at scale. Rather than purchasing ad placements, the actor compromises ad servers and appends obfuscated malicious JavaScript to live creatives and ad slots, enabling broad downstream distribution through publisher sites, ad platforms, media companies, and real-time bidding integrations. Observed Tag Barnakle activity uses multi-stage client-side and server-side filtering. Initial payloads perform anti-analysis checks, set cookies to limit repeat exposure, fingerprint victims using browser and WebGL characteristics, and request follow-on code only when targeting conditions are met. The actor uses cloaking and selective payload delivery to reduce visibility and detection. Later-stage activity has been linked to loading third-party advertising infrastructure and redirecting victims toward scamware, malware, or abusive mobile applications, including security, safety, or VPN-themed apps associated with hidden subscription or other deceptive monetization behavior. Reporting has tied Tag Barnakle to sustained campaigns dating back to 2019, with repeated observations across large numbers of compromised Revive instances and affected web properties. The actor has been observed targeting both desktop and mobile users, with later campaigns showing explicit mobile-oriented filtering for Android and iOS environments. Tag Barnakle is notable for persistence, large-scale abuse of ad-tech supply chains, and the use of fingerprinting, cloaking, and low-frequency exposure controls to maintain malvertising operations while evading detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
181 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malvertising threat actor associated with abuse of the advertising ecosystem to deliver malicious or deceptive content, typically via redirects and cloaking.
Malvertising threat actor identified by Confiant and tracked via the Malvertising Attack Matrix; associated with malicious advertising activity.
Named malvertising threat actor profile identified by Confiant and tracked via the Malvertising Attack Matrix.
Mass-compromises Revive Adserver instances to conduct malvertising campaigns, using client-side fingerprinting, server-side cloaking, and secondary payload delivery via Propeller Ads. The group has shifted toward mobile-targeted campaigns and uses low-frequency payload delivery via cookies to reduce detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.