
'mixseven' Affiliate Deploys Six Malware Families via Single PPI Tag
A single pay-per-install affiliate operating under the publisher tag 'mixseven' has coordinated the simultaneous deployment of at least six distinct malware families through a layered loader chain. Infrastructure provisioned in a single automated session in September 2021 — with two C2 domain certificates issued 56 minutes apart — reveals a technically capable operator running credential harvesting as a structured production pipeline.
A single pay-per-install affiliate operating under the publisher tag pub=mixseven has coordinated the simultaneous deployment of at least six distinct malware families — GCleaner, SmokeLoader, PrivateLoader, Socelars, Fabookie, RedLine Stealer, FFDroider, and Glupteba — through a layered loader chain whose network infrastructure was provisioned in a single automated session in September 2021.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read