PULSE NAME
AI-dvertiser: Multi-Stage Ad Fraud and ClickFix Network Impersonating Web3 Brands
WHITE QuetzalTeam 2026-05-07 Modified: 2026-05-11
46
IOCs
MEDIUM VOLUME
We identified a phishing domain impersonating Bitso that operates as part of a broader malicious advertising and traffic distribution network targeting fintech and Web3 users. The infrastructure chains together multiple redirectors, disposable domains and ad distribution services to deliver highly variable content. Observed payloads include AI-generated fake news websites featuring synthetic imagery, ClickFix-style landing pages designed to trick users into enabling browser push notifications for large-scale advertising spam, and fully AI-generated YouTube channels focused on music, philosophy and storytelling. In edge cases, the infrastructure redirects victims to low-visibility Spotify tracks that also appear to be AI-generated. We refer to this ecosystem as “AI-dvertiser”, an emerging model where generative AI is combined with ad fraud, social engineering and automated content farms to create scalable and low-cost malicious engagement infrastructure.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (3 / 46 total)
All IPv4 URL domain hostname FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 2621723d94b8a8d64645a265c9be3d96edb8c90d5d7e788c5dfca71d466da2c2 2026-05-11
FileHash-SHA256 5585c86abada1c547ab3a9ba8f735122b7f770c9d1428c9557fcc731fcaf3957 2026-05-11
FileHash-SHA256 73e92891b078e61a384ab3fccca55e17e7ebf2706c4a150f2d0460db6d8f6544 2026-05-11