Malvertising
Buying advertising to deliver the lure: a paid result above the real one, pointing at a page that looks like the software the visitor searched for. Distribution with a budget and a targeting console.
Why it matters to you
The victim searched for your product and clicked an ad. Brand monitoring that watches only domains misses the placement entirely.
Where we meet it
The lure themes rotate with whatever software is being searched for, and the crews trade those themes openly because they are recruiting. That rotation is readable ahead of the infections it produces.
Connected terms
Traffer
The distribution worker of the stealer economy: drives victims to infected downloads via malvertising, fake installers, cracked software and phishing. Organized into teams with quotas and payout shares.
Traffic distribution system (TDS)
A filtering layer in front of a malicious page that decides who gets to see it: the right country, the right browser, not a sandbox, not a crawler. Everyone else is sent somewhere harmless.
Lookalike domain
A domain registered to be misread as someone else's: a swapped character, an extra hyphen, a different suffix. The cheapest piece of infrastructure in this economy and the one most often pointed at a brand.
Where this term stops being vocabulary
Dragnet is where you watch it happen to you
Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.