Skip to content
skopnix
← adversaries
Unknown

ScamClub

misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

ScamClub is a threat actor involved in malvertising activities since 2018. They target the Mobile Web market segment, particularly on iOS devices, where security software is often lacking. ScamClub utilizes obfuscation techniques and real-time bidding integration with ad exchanges to push malicious JavaScript payloads, leading to forced redirects and various scams such as phishing and gift card scams.

Take it with you
References
Early access

Track ScamClub on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected