Boaxxe is a Windows malware family associated with large-scale ad fraud operations. It has been documented as a payload delivered by exploit-kit activity in English-speaking countries and as one of the malware packages used by the 3ve botnet to infect PCs. In the 3ve ecosystem, Boaxxe was used alongside Kovter to build a large pool of compromised residential and corporate systems that generated fraudulent advertising traffic, including fake clicks and ad bid requests, while imitating legitimate desktop and mobile user behavior to evade detection.
Boaxxe has also been observed as a secondary payload downloaded and executed by the Sathurbot botnet. In that role, Sathurbot-infected systems could retrieve and launch Boaxxe in addition to other malware families, indicating Boaxxe’s use as a follow-on component within broader criminal distribution chains.
The available facts support Boaxxe as Windows malware used operationally in botnet-driven monetization schemes, particularly ad fraud. Its observed distribution includes exploit-kit delivery and installation via other malware that downloads additional executables. High-confidence details about Boaxxe’s internal functionality beyond its role in infection and ad-fraud ecosystems are currently not available from the supplied material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware package used by the 3ve botnet to infect PCs that were then used for ad fraud activity.
Boaxxe is mentioned as one of the additional payloads downloaded and executed by Sathurbot.
Windows malware sample referenced as an exploit-kit-delivered payload in English-speaking countries; incidental to the main Windigo/Ebury focus.
A Windows malware family mentioned as a payload dropped by the exploit kit in English-speaking countries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.