DatalyMedia is an ad-fraud and affiliate marketing fraud actor associated with a long-running cookie-stuffing operation active since at least 2015. The activity has been linked to multiple legal entities, including Dataly Media, Just Media Group, Eficads, and Tredia Solutions. The actor has operated across multiple programmatic advertising platforms and uses large-scale display advertising to generate fraudulent affiliate clicks and conversions, with notable surges during high-value retail periods such as Black Friday. The operation relies on cloaking, hidden iframes, delayed execution, and intermediary publisher infrastructure to trigger affiliate tracking and advertiser landing-page loads without genuine user interaction. DatalyMedia launders fraudulent traffic through seemingly legitimate native-ad and made-for-advertising pathways so that invalid conversions resemble normal affiliate referrals. Its methods also cause unauthorized tracking pixels and affiliate cookies to execute in the context of publisher pages, creating privacy and consent-compliance exposure in jurisdictions governed by GDPR. The actor’s activity is financially motivated and centered on stealing affiliate revenue rather than deploying malware or conducting network intrusion. Observed behavior supports capabilities in spoofing and defense evasion through conditional content delivery and cloaking, as well as post-exploitation-style abuse of advertising and tracking ecosystems to monetize fraudulent traffic at scale. European countries have been a major focus of the campaign, accounting for most observed targeting in 2022.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.