eGobbler is a prolific malvertising threat actor linked to China and known for operating at very large scale through abuse of the online advertising ecosystem. The group gained access to demand-side advertising platforms through front companies and dummy campaigns, then used malicious creatives, artificial redirection chains, cloaking, and selective activation logic to deliver scams, forced redirects, session-hijacking activity, and later drive-by download payloads. It has been described as Asia-based and as having registered entities in Hong Kong before later creating U.S. entities with Chinese-named directors to improve credibility with ad platforms. The actor is notable for sophisticated browser-side targeting and evasion. eGobbler used JavaScript fingerprinting and later WebGL-based fingerprinting to distinguish real victim devices from scanners and spoofed environments, with geo-fencing and server-side cloaking to restrict payload delivery. It embedded malicious logic into HTML5 advertising components and obscured provenance through complex ad-tag redirect chains across multiple ad-tech intermediaries. The group also relied on reverse proxies and commercial CDN infrastructure to mask delivery paths. eGobbler became especially well known for exploiting browser vulnerabilities to bypass built-in protections against pop-ups, forced redirects, and iframe sandboxing. Public reporting tied the actor to exploitation of CVE-2019-5840 in Chrome on iOS and CVE-2019-8771 in Safari/WebKit during 2019. These techniques enabled session hijacking and forced navigation even inside sandboxed cross-origin ad iframes, contributing to extremely high-volume campaigns affecting hundreds of millions of user sessions and over a billion ad impressions. Operationally, eGobbler has shown strong temporal and geographic targeting. Its campaigns often surged around weekends and holidays, and by 2020 it reportedly ran campaigns almost exclusively during those periods. Early activity heavily targeted iOS and mobile users, while later campaigns shifted more toward desktop systems and, from mid-2020, toward U.S.-focused drive-by download operations. Observed lures included fake gift-card and carrier-branded scams as well as fake software-update pages. In 2020, eGobbler and the related malvertising actor Nephos7 were observed distributing nearly identical fake update flows that installed the same signed adware family known as Holcus Installer. Although the two actors maintained separate infrastructure, their tactics, payload evolution, and timing were closely aligned. eGobbler is therefore best understood as a major cybercriminal malvertising operator specializing in initial access through ad-tech abuse, browser exploitation, cloaking, session hijacking, and malware delivery at internet scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Detected by Confiant in 2019, CVE-2019–8771 and CVE-2019–5840 are browser vulnerabilities (Safari and Chrome) introduced by eGobbler and allowing them to bypass popup blocking and iframe sandboxing, which are protections against forced redirects.
Detected by Confiant in 2019, CVE-2019–8771 and CVE-2019–5840 are browser vulnerabilities (Safari and Chrome) introduced by eGobbler and allowing them to bypass popup blocking and iframe sandboxing, which are protections against forced redirects.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malvertising threat actor associated with malicious ad campaigns leveraging the ad-tech/RTB ecosystem to deliver malicious or fraudulent landing pages and payloads.
Malvertising-focused threat actor conducting large-scale forced-redirect and pop-up campaigns by exploiting browser vulnerabilities/logic flaws to bypass ad sandboxing and built-in pop-up/redirect mitigations, impacting programmatic ad impressions at very high volume across the US and Europe.
Malvertising-focused actor exploiting browser vulnerabilities/bugs to bypass protections and force pop-ups/redirects at scale.
Malvertising threat actor identified by Confiant and tracked via the Malvertising Attack Matrix; associated with malicious advertising activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.