Dandelion Group is an ad-fraud operation associated with large-scale cloaking and ad stuffing in the programmatic advertising ecosystem. The group is known for inserting seemingly conventional ad tags that load intermediary content designed to resemble legitimate ad-tech behavior while actually redirecting traffic to monetized pages packed with advertisements. Its infrastructure has been characterized by the use of multiple related domains and frequent campaign turnover, indicating a persistent and scalable fraud operation. The group’s tradecraft centers on deceptive ad delivery and traffic redirection. It has used HTML-based intermediary content rather than standard ad creatives, suppressed referrer visibility, discouraged crawler indexing, and triggered hidden form-based redirects to destinations that render different content depending on access method. This cloaking allows the operation to present one experience to casual inspection while delivering ad-stuffed pages for monetization. The activity has been associated with repeated use of spoofing-like techniques to disguise the true source and nature of impressions and to evade straightforward detection. Dandelion Group primarily harms advertisers, ad platforms, and legitimate publishers by generating non-viewable or misrepresented impressions that siphon advertising spend and degrade inventory quality metrics. The operation has been described as persistent, with dozens of related domains observed and recurring campaigns over time. No high-confidence attribution to a nation-state or a specific country of origin is available. Known naming in reporting centers on Dandelion Group itself, with no corroborated sub-groups established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.