DealPly is a Windows adware family associated with unwanted browser modification and affiliate-traffic monetization. It has been observed both as a standalone adware executable and as part of campaigns that install DealPly-related browser extensions. Early variants of the extension ecosystem appeared by late 2018, and infections have commonly been linked to loaders for pirated or cracked software obtained from untrustworthy sources.
Technical analysis shows that DealPly commonly uses a Delphi-based loader that, when invoked with parameters, unpacks an in-memory DLL payload. The unpacked DLL is responsible for command-and-control communication and contains encrypted configuration data and strings that are decrypted at runtime. The malware uses WinINet APIs to communicate over HTTP and HTTPS and supports both GET and POST requests. Decrypted strings indicate collection of host-identification and environment data, including system and language information, network-adapter details, and Windows installation identifiers such as MachineGuid. The malware also contains virtualization-awareness logic based on platform markers and MAC-address patterns.
DealPly includes persistence and lifecycle-management functionality. It can create scheduled tasks using native Windows task-scheduling utilities, manipulate registry settings, and maintain uninstall and update logic. DealPly-related extensions and associated components have been used to alter browser start pages and default search settings in order to redirect users to affiliate destinations. In observed extension-installation scenarios, the adware executable installs or reinstalls browser extensions through Windows registry-based mechanisms rather than relying on direct user installation.
Overall, DealPly is best characterized as adware with loader-like staging behavior, runtime string and configuration decryption, host profiling, command-and-control communications, persistence via scheduled tasks and registry changes, and browser-hijacking behavior aimed at advertising and affiliate abuse.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
decrypted string: schtasks.exe ... /create /F /tn ... /sc DAILY /ST ... /RU SYSTEM ... Tasks\ ... *.job ... at.exe
decrypted string: schtasks.exe ... /create /F /tn ... /sc DAILY /ST ... /RU SYSTEM ... Tasks\ ... *.job ... at.exe
decrypted string: Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ ... Hidden ... HideFileExt ... ShowSuperHidden
Once added to the browser, it mimics the harmless and standard-looking Chrome extension Google Translate.
decrypted string: cmd.exe /Q /D /c del " ... DeleteFileA ... cmd /d /c del
decrypted string: psapi.dll ... GetModuleFileNameExA ... EnumProcessModules ... OpenProcess
decrypted string: GetVersionExA ... ProductName ... \Software\Microsoft\Windows NT\CurrentVersion\ ... GetComputerNameA
The code at the f_decrypt_c2Url function will perform xor to decrypt ... All strings used by malware are encrypted and only decrypt when needed.
Cato researchers began by collecting traffic metadata from malicious Chrome extensions to their C&C services.
decrypted string: wininet.dll ... InternetOpenA ... InternetConnectA ... HttpOpenRequestA ... HttpSendRequestA ... POST ... GET ... Host: ... Accept: */*
86 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only in related content as adware that abuses Microsoft and McAfee services to evade detection.
Adware family delivered via the DealPly executable, often through hacked software loaders. It installs browser extensions, changes the start page and default search engine, analyzes queries, redirects users to partner sites, and maintains persistence via Windows registry extension update paths.
DealPly is described as adware with a Delphi-based loader that unpacks an in-memory DLL payload. The DLL handles C2 communications, decrypts embedded C2 URLs and strings at runtime, uses HTTP/HTTPS via WinINet APIs, gathers host and system identifiers, includes virtualization checks, supports install/update/uninstall logic, and establishes persistence through scheduled tasks and registry entries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.