Researchers from Confiant, Infoblox, and Netskope reported sustained criminal abuse of traffic distribution systems (TDSs) to filter, cloak, and route victims into scams and malware. Confiant and Infoblox found that attackers have extensively weaponized Keitaro, a self-hosted ad-tracking platform, across an ecosystem of roughly 15,500 malicious domains, including about 9,000 registered specifically for abuse. Their four-month analysis found traffic arriving from programmatic ads, spam, social media, and compromised websites, then being selectively redirected based on device, geography, IP address, and referrer. Investment fraud was the dominant use case, with clusters such as FaiKast using deepfake news-style cryptocurrency ads, WickedWally targeting U.S. seniors with fake benefits and debt-relief offers, and FishSteaks running giveaway scams impersonating consumer brands.
Netskope separately documented a parallel TDS-for-hire operation built around more than 12,700 fake CAPTCHA PDF files hosted on Webflow’s CDN and indexed by Google as benign upgrade guides. Those PDFs fed users into a custom Elixir/Phoenix routing platform that screened visitors through IP reputation, bot detection, geography, and device checks before sending qualified victims to malware or scam pages and diverting others to ad-arbitrage content. The downstream payloads included Legion Loader, a reseller TDS gate linked to yfdpco domains, and a Spanish-language premium-SMS fraud scheme. Researchers said the infrastructure has persisted for more than 14 months despite rotating lure domains, underscoring how commercial-style tracking and routing software is being repurposed at scale to industrialize online fraud and malware delivery.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Confiant and Infoblox began a four-month analysis of criminal abuse of Keitaro on October 1, 2025. The study later identified a large ecosystem spanning 15,500 malicious domains and multiple scam clusters.
Since August 2025, Confiant reported more than 100 domains tied to criminal abuse of the Keitaro tracker to Apliteni, the company behind Keitaro. Apliteni responded to each report and ultimately canceled more than a dozen threat actor accounts.
Netskope said the earliest directly analyzed samples from the FakeCaptcha PDF campaign were submitted in May 2025. These samples were part of clusters later tied to a large traffic-distribution operation.
In March 2025, Palo Alto Unit 42 documented berapt-medii[.]com serving a fake CAPTCHA that instructed victims to run a command that installed an MSI named Klio Verfair Tools, which dropped Legion Loader. Netskope later linked this site to the broader FakeCaptcha traffic-distribution operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcenetskope.com
Open sourceblog.confiant.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.