Earlier this year, RiskIQ reported an eightfold increase in internet scam incidents, which deny the $83 billion digital advertising industry millions of dollars. Since then, we’ve identified a particularly prolific threat actor that’s built out wide swaths of infrastructure to deliver millions of scam ads, threatening consumers and undermining the digital advertising industry.
Based on the RiskIQ report released in April, NoTrove: The Threat Actor Ruling a Scam Empire, report author and RiskIQ Threat Researcher Ian Cowger and Technical Marketing Manager Benjamin Powell will walk you through how “NoTrove,” a scam actor named after its URI pattern and penchant for denying victims “troves” of rewards, uses its scam empire and advanced automation techniques to stay ahead of detection and takedown efforts.
Watch the Threatcast™ for a deep dive on:
How scams are becoming a lucrative and increasingly popular method for threat actors and why they’re bad news for the digital advertising ecosystem
What the different variants of NoTrove campaigns look like—software downloads, PUP redirections, and fake rewards downloads—and what the redirection sequence looks like when victims click and are redirected to unwanted places across the internet
How NoTrove domains are able to command so much traffic, many shoot well up into the Alexa top 10,000
How RiskIQ’s unique machine learning technology is able to detect scams, even as threat actor tactics evolve, to enable ad networks and publishers to block NoTrove infrastructure, even as it changes, evolves, and rotates