DCCBoost is a malvertising threat actor associated with large-scale advertising abuse campaigns that use malicious ad creatives and redirect chains to send victims to scam content, including gift card and lottery fraud pages. The actor operates within the online advertising ecosystem and has been tracked as part of broader malvertising activity abusing real-time bidding and ad-delivery workflows. DCCBoost has used sophisticated JavaScript-heavy payloads embedded in ad content, including staged execution chains in which encoded content is decrypted client-side and then evaluated to launch subsequent stages. Reported tradecraft includes extensive fingerprinting of the victim environment, such as device and operating system checks, canvas-based checks, and identification of ad-tech or security-related environments before deciding whether to continue execution. The actor has also used cloaking and server-side targeting logic to selectively deliver later-stage payloads only to clients that match campaign criteria. Observed DCCBoost activity shows strong emphasis on defense evasion and anti-analysis. Techniques include obfuscation, custom encryption for client-server communications, dynamic construction of infrastructure references, conditional termination of execution when analysis conditions are detected, and use of alternate communication mechanisms such as WebSockets in some variants. Final-stage payloads have been delivered through injected and executed JavaScript that ultimately redirects users to scam landing pages. DCCBoost is best characterized as a financially motivated malvertising actor focused on fraudulent monetization rather than ransomware or destructive operations. No high-confidence country of origin, specific national targeting pattern, or sector-specific victimology is established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malvertising threat actor operating through ad networks/RTB, associated with malicious ad delivery techniques such as redirects and cloaking.
Malvertising threat actor identified by Confiant and tracked via the Malvertising Attack Matrix; associated with malicious advertising activity.
Named malvertising threat actor profile identified by Confiant and tracked via the Malvertising Attack Matrix.
Malvertising actor conducting forceful redirects from ad banners to gift card and lottery scam pages, using sophisticated JavaScript obfuscation, client/server fingerprinting, encrypted payload delivery, dynamically built domains and URLs, and occasional WebSocket communications.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.