FILEMembers
FILE

'mixseven' Affiliate Deploys Six Malware Families via Single PPI Tag

A single pay-per-install affiliate operating under the publisher tag 'mixseven' has coordinated the simultaneous deployment of at least six distinct malware families through a layered loader chain. Infrastructure provisioned in a single automated session in September 2021 — with two C2 domain certificates issued 56 minutes apart — reveals a technically capable operator running credential harvesting as a structured production pipeline.

Jun 12, 2026, 07:28 (UTC+9)Last seenJun 12, 2026Severity77ByCTX TeamActorSmoky SpiderBariumIOC40MITRE64

A single pay-per-install affiliate operating under the publisher tag pub=mixseven has coordinated the simultaneous deployment of at least six distinct malware families — GCleaner, SmokeLoader, PrivateLoader, Socelars, Fabookie, RedLine Stealer, FFDroider, and Glupteba — through a layered loader chain whose network infrastructure was provisioned in a single automated session in September 2021.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence