Thursday, April 17, 2025
HomeCyber AttackApateWeb: Hackers Using 130,000+ Domains to Launch Cyber Attacks

ApateWeb: Hackers Using 130,000+ Domains to Launch Cyber Attacks

Published on

SIEM as a Service

Follow Us on Google News

A new large-scale campaign named “ApateWeb ” has been discovered, which uses over 130,000 domains to deliver scareware, potentially unwanted programs, and other scam pages. Threat actors use deceptive emails to lure victims into their malicious websites and redirect them to their infrastructure for delivering malware.

This particular campaign has a complex infrastructure with multilayered systems and several redirections between the entry point and the delivery of the final payload. The campaign has been active for the past three years, from 2022 to now. 

The potential impact of this campaign is massive as hundreds of these malicious attacker-controlled domains remain on the top list of 1 million websites, contributing to millions of unique visits every month.

- Advertisement - Google News
ApateWeb Campaign Infrastructure (Source: Unit 42)
ApateWeb Campaign Infrastructure (Source: Unit 42)
Document
Run Free ThreatScan on Your Mailbox

AI-Powered Protection for Business Email Security

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .

ApateWeb: 130,000+ Domains

According to the reports shared with Cyber Security News, the campaign has a complex workflow and infrastructure setup by threat actors for evading crawlers, bots, security defenders’ scans, and other research mechanisms. However, the campaign can be dissected into three layers.

The First Layer (Layer 1) consists of the entry point URLs distributed to victims through emails. From here, the traffic is routed through the second layer (Layer 2). A series of redirections are performed, including adware or anti-bot verification, and finally, the last layer (Layer 3) is served. 

This final layer delivers the malicious payload, which could be a scareware, PUP, or scam page. 93% of the attacker-owned domains resolve to only 10 IP addresses, which are 

  • 192[.]243[.]59[.]20
  • 192[.]243[.]59[.]13
  • 192[.]243[.]59[.]12
  • 192[.]243[.]61[.]227
  • 192[.]243[.]61[.]225
  • 173[.]233[.]139[.]164
  • 173[.]233[.]137[.]60
  • 173[.]233[.]137[.]52
  • 173[.]233[.]137[.]44
  • 173[.]233[.]137[.]36

Layer 1: Entry Point

The techniques employed in this layer include redirection to search engines, error message displaying for bots/crawlers, and abusing wildcard DNS to generate a large number of subdomains as a means of evading detection.

Moreover, this layer consists of the entry point URL and specific parameters. Failure of these URL parameters results in an error page or no content being served to the victim. Additionally, there is also an initial payload in this layer that can assign Unique identifiers to each visitor.

Layer 2: Intermediate redirections

This layer performs several intermediate redirections using random domains before routing to Layer 3. Moreover, the redirection includes additional parameters which, when examined, revealed that the campaign was able to be monetized by forwarding traffic to the adware.

In addition to this, there are also anti-bot verifications performed in this layer, some of which require human interaction, such as a CAPTCHA. In some cases, Layer 2 is skipped from redirection and directly Layer 3 is served.

CAPTCHA verification (Source: Unit 42)
CAPTCHA verification (Source: Unit 42)

Layer 3: Redirection to Final Payload

This is the final stage of the attack chain, which serves as a web page for downloading the malicious program. Their malicious payloads are found to be hosted on public cloud environments. In some cases, the malicious payloads were also found to be unwanted browsers and extensions.

Payload Delivery (Source: Unit 42)
Payload Delivery (Source: Unit 42)

The campaign has been published by Unit 42, which provides detailed information about the URLs used, methodologies, evasion tactics, and other information.

Indicators of Compromise

Campaign entry point example

  • featuresscanner[.]com

Domains part of centralized infrastructure to track victims

  • professionalswebcheck[.]com
  • hightrafficcounter[.]com
  • proftrafficcounter[.]com
  • experttrafficmonitor[.]com

IP addresses hosting campaign entry point

  • 192[.]243[.]59[.]20
  • 192[.]243[.]59[.]13
  • 192[.]243[.]59[.]12
  • 192[.]243[.]61[.]227
  • 192[.]243[.]61[.]225
  • 173[.]233[.]139[.]164
  • 173[.]233[.]137[.]60
  • 173[.]233[.]137[.]52
  • 173[.]233[.]137[.]44
  • 173[.]233[.]137[.]36

Traffic forwarded to adware

  • tracker-tds[.]info
  • jpadsnow[.]com
  • ad-blocking24[.]net
  • Myqenad24[.]com

PUP download example:

  • bd62d3808ef29c557da64b412c4422935a641c22e2bdcfe5128c96f2ff5b5e99
  • artificius[.]com

Other campaign domains:

  • hoanoola[.]net
  • allureoutlayterrific[.]com

Follow us on LinkedIn for the latest cybersecurity news, whitepapers, infographics, and more. Stay informed and up-to-date with the latest trends in cybersecurity.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

CISA Warns of Potential Credential Exploits Linked to Oracle Cloud Hack

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a public warning following reports...

Agent Tesla Malware Uses Multi-Stage Attacks with PowerShell Scripts

Researchers from Palo Alto Networks have uncovered a series of malicious spam campaigns leveraging...

Intel Sells 51% Stake in Altera to Silver Lake in $8.75 Billion Deal

Intel Corporation has announced the divestiture of a 51% stake in its Altera division...

Critical Flaw in PHP’s extract() Function Enables Arbitrary Code Execution

A critical vulnerability in PHP’s extract() function has been uncovered, enabling attackers to execute arbitrary code...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

CISA Warns of Potential Credential Exploits Linked to Oracle Cloud Hack

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a public warning following reports...

Agent Tesla Malware Uses Multi-Stage Attacks with PowerShell Scripts

Researchers from Palo Alto Networks have uncovered a series of malicious spam campaigns leveraging...

Intel Sells 51% Stake in Altera to Silver Lake in $8.75 Billion Deal

Intel Corporation has announced the divestiture of a 51% stake in its Altera division...