CashRewindo is a sophisticated threat actor known for global malvertising campaigns that redirect victims to investment scam sites.
Analyst brief
CashRewindo is a sophisticated threat actor leveraging aged domains in global malvertising campaigns to redirect victims to investment scam sites. They target a wide range of users across Europe, Asia, Africa, and the Americas through tailored campaigns using localized language and imagery. Their primary TTPs include flipping between scam ads and innocuous content, employing A/B testing to bypass time-based creative verification systems, and smuggling malicious code within common JavaScript libraries. Defenders should focus on scrutinizing aged domains, monitoring for sudden changes in ad content, and verifying the integrity of JavaScript libraries to detect anomalies in network traffic.
CashRewindo
unknown
CashRewindo is a sophisticated threat actor leveraging aged domains in global malvertising campaigns to direct victims to investment scam sites. The group employs TTPs such as flipping between scam ads and innocuous content, as well as A/B testing to exploit time-based creative verification systems. Their operations are characterized by tailored campaigns that utilize localized language and imagery across diverse regions, including Europe, Asia, Africa, and the Americas. Additionally, CashRewindo smuggles malicious code within common JavaScript libraries to enhance their effectiveness.