Researchers linked the InstallCapital pay-per-install (PPI) operation to the delivery of multiple malware families through fake warez sites, a WordPress plugin, and a sprawling but centralized domain network. The installer fetched available offers from infrastructure referenced through Pastebin, then delivered second-stage payloads to victims who matched campaign conditions. Across 2017 to 2020, investigators observed more than 500 offers and nearly 200,000 domains tied to the operation, with testing showing distribution of Glupteba, Dreambot, and Legion Loader, the latter later dropping Raccoon Stealer.
One of the payloads, Glupteba, was documented as a modular malware platform spread via malvertising that expanded beyond a botnet into credential theft, proxy abuse, and resilient command-and-control. Its newer variants stole browser cookies, history, and credentials from Chrome, Opera, and Yandex; exploited MikroTik routers via CVE-2018-14847 to steal administrator credentials and convert devices into SOCKS proxies; and used encrypted communications plus Bitcoin OP_RETURN data to recover updated C2 domains. The combined reporting shows how adware-style PPI distribution can serve as an initial access channel for more capable malware that steals data, hijacks network infrastructure, and maintains durable access.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
During the third day of testing in January 2020, CSIS observed InstallCapital distributing Legion Loader from api-update1[.]biz. Legion Loader was then used to drop Raccoon Stealer.
In the same January 2020 testing period, InstallCapital was configured to drop the first-stage loader ImpulseLTD and then deliver the Dreambot banking trojan. The Dreambot sample was identified with bot group ID 1000, version 2.17.10.7, and both onion and clearnet command-and-control endpoints.
During testing in January 2020, CSIS observed InstallCapital delivering Glupteba via a second-stage payload URL. The article describes Glupteba as malware used mainly for cryptocurrency mining and lateral movement on local networks.
The Trend Micro article says a 2018 report found the Glupteba botnet may have become independent from Operation Windigo and shifted to pay-per-install adware distribution. This marked an earlier change in how the malware was being spread.
The CSIS analysis states that researchers observed nearly 200,000 domains associated with the InstallCapital pay-per-install operation between 2017 and 2020, all resolving to the same IP address. This documented the scale and centralized nature of the distribution infrastructure.
Trend Micro reported that a Glupteba malvertising campaign was distributing a variant with added browser-stealing and MikroTik router-exploitation components. The report also described Glupteba's ability to recover updated command-and-control domains from Bitcoin transaction OP_RETURN data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 45 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.