Win32/Boaxxe is a Windows click-fraud malware family active since at least 2010 and used to redirect victims to advertising websites for monetization. In the observed Win32/Boaxxe.G variant, infection occurred through exploit-kit delivery from compromised web infrastructure associated with Operation Windigo, with victims in English-speaking countries such as the United States, Canada, Australia, and the United Kingdom specifically receiving this payload. The malware was delivered as an installer that executed a DLL export and then manipulated web browsing activity through in-memory hooks in major browsers including Chrome, Firefox, and Internet Explorer rather than relying on browser extensions. Its primary purpose was ad redirection and click-fraud activity. Reporting assessed Win32/Boaxxe.G as an older branch of the Boaxxe family with more limited support for newer browsers, and also assessed that Windigo operators likely acted as an installation partner for a separate group operating Boaxxe rather than running the malware’s broader infrastructure themselves.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
web visitors accessing pages hosted on websites infected with Linux/Cdorked can be redirected to exploit kits. These exploit kits, if successful, install two different malware families, depending on the visitor’s geographic location. | Web servers infected with Linux/Cdorked redirect users to exploit kit servers, which in turn attempt to infect users with malware.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows click-fraud malware distributed through exploit kits reached via Linux/Cdorked redirections. It redirects users to advertisement websites through long redirection chains to generate affiliate revenue.
Win32/Boaxxe.G is a click-fraud/ad-redirect malware family delivered by exploit kits to English-speaking victims. It redirects users to advertisement websites using browser memory hooks and related redirection logic.
A Windows click-fraud malware distributed through exploit kits reached via Linux/Cdorked redirections. It redirects users to advertisement websites through long redirection chains to generate affiliate revenue.
Win32/Boaxxe.G is a click-fraud/ad-redirect malware family delivered by exploit kits to English-speaking victims. It redirects users to advertisement websites using browser memory hooks and related redirection logic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.