CSIDB logo
Threat actor

Rogue Advertiser

Attribution profile

Type
Criminal
Location
United States of America
Known incidents
2 incidents
First seen
2016-05-04
Last seen
2016-05-04
Updated
2026-07-30 18:51
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Rogue Advertiser operates under that alias and has been linked to activity originating from the United States of America. Public reporting identifies the actor as a malvertising-focused entity that leverages compromised advertising infrastructure to deliver malicious payloads. The actor’s known alias appears in multiple security analyses describing the same set of incidents. No additional names or affiliations have been publicly attributed to this actor. The location information is based on the actor’s use of U.S.-based services and the geographic focus of the observed attacks.

Targeting observed in the disclosed incidents centers on media organizations, specifically CBS-affiliated television stations that serve audiences within the United States. The actor’s method of initial access involves compromising accounts at a domain registrar, in this case GoDaddy, to create subdomains that are then used for malicious purposes. These subdomains are integrated into a legitimate ad network, namely the Taggify platform, allowing the actor to serve both clean advertisements and hidden iframes. The hidden iframes redirect visitors to the Angler Exploit Kit, which attempts to exploit browser vulnerabilities to install further malware. Evasion techniques include dynamically alternating between benign content for automated scanners and malicious payloads for genuine users, based on user‑agent strings and IP address checks.

The most publicly documented campaign took place on May 4, 2016, when the Rogue Advertiser used the described technique to expose visitors of two CBS-affiliated stations to the Angler Exploit Kit. The malicious subdomains, such as som.barkisdesign.com, were hosted on IP addresses associated with the compromised GoDaddy accounts and served alternating content to avoid detection by security scanners. Response to the incident involved cooperation between the affected television stations, the Taggify ad platform, and the domain registrar to remove the malicious subdomains and restore normal ad delivery. After the takedown, the actor’s infrastructure was reported as inactive, though no further attribution or arrest information has been released. This episode remains the primary concrete example of the Rogue Advertiser’s operational behavior in open‑source reporting.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB