Security researchers reported that a cloaking platform called 1Campaign is enabling cybercriminals to run malicious Google Ads while evading Google’s ad review and many security scanners. The service uses cloaking to present a benign “white page” to reviewers, researchers, and automated analysis systems, while redirecting real users to attacker-controlled destinations such as phishing pages, fake software download sites, and cryptocurrency drainer scams. The platform has reportedly been active for at least three years and is operated by an individual using the handle “DuppyMeister,” with support and operations facilitated via Telegram channels.
Reporting describes 1Campaign as a packaged, user-friendly dashboard that lowers the barrier to entry for ad-based fraud by providing real-time visitor filtering and fraud/risk scoring, including blocking traffic associated with cloud providers and security vendors. Observed campaigns demonstrated extremely selective targeting (e.g., blocking ~99.4% of visitors in one case; another campaign processed 1,676 visitors while allowing only 10 through), and filtering based on geography, ISP, and device characteristics to keep campaigns live longer. The service also includes tooling intended to help launch Google Ads and impersonate legitimate brands, underscoring that static URL scanning is often insufficient against dynamic cloaking and that defenders should expect more victim-specific delivery in malvertising operations.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Varonis Threat Labs disclosed technical details on 1Campaign, describing how it shows benign pages to Google reviewers and automated scanners while redirecting real users to phishing, fake download, and crypto-drainer pages. The report highlighted the platform's dashboard, fraud scoring, bot filtering, and brand-impersonation capabilities that help malicious ads remain active for extended periods.
In an observed campaign tied to bitcoinhorizon.pro and labeled "Blockbyblockchain," 1Campaign was used to aggressively screen traffic and allow only a tiny fraction of visitors through to malicious content. Researchers said the system blocked 99.4% of 1,676 visitors, demonstrating highly selective targeting against intended victims while excluding researchers and security infrastructure.
The malvertising enablement platform 1Campaign was reported to have been active for at least three years, operated by a developer using the handle "DuppyMeister." It offered infrastructure for cloaking, visitor filtering, and Google Ads abuse to help threat actors evade review systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.