FizzCore is a named malvertising threat actor associated with abuse of the online advertising ecosystem to deliver malicious advertising activity. It has been tracked alongside other malvertising clusters such as Zirconium, eGobbler, ScamClub, DCCBoost, Tag Barnakle, and YoSec. FizzCore is linked to operations that exploit ad-tech infrastructure and real-time bidding workflows, including entry into advertising supply chains through fraudulent advertiser or creative activity, forceful redirects, cloaking, and delivery of malicious landing pages. Reported malvertising tradecraft in this ecosystem includes maintaining persistent campaigns while evading detection, selectively revealing payload infrastructure based on fingerprinting or other filtering logic, and using browser-focused exploitation and credential-access behaviors as part of broader attack chains. Malvertising actors in this cluster have also been associated with delivery mechanisms such as drive-by downloads, exploit-kit style activity, scams, and malware capable of establishing footholds in enterprise environments. Publicly available information in this context does not provide high-confidence attribution of FizzCore to a specific state sponsor, country of origin, or distinct sub-groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malvertising threat actor associated with campaigns in the advertising ecosystem, using redirects/cloaking to deliver malicious or scam content.
Malvertising threat actor identified by Confiant and tracked via the Malvertising Attack Matrix; associated with malicious advertising activity.
Named malvertising threat actor profile identified by Confiant and tracked via the Malvertising Attack Matrix.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.