Low5 is a threat cluster associated with Android-focused ad fraud and malvertising activity. It has been linked to the use of HTML5-based cashout infrastructure, a monetization pattern also observed in related clusters such as SlopAds and BADBOX 2.0. The cluster is associated with fraudulent mobile advertising schemes in which seemingly benign Android applications are used to drive installs of additional actor-controlled apps that perform hidden ad activity through embedded web components and automated interaction techniques. Observed tradecraft includes malvertising-driven user acquisition, staged app delivery, hidden ad-request generation, anti-analysis measures, obfuscation, and blending with legitimate mobile ecosystem components to evade detection. Based on the available facts, Low5 is best characterized as a financially motivated mobile ad-fraud actor rather than a ransomware or espionage operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.