Unidentified 025 (Clickfraud) is a click-fraud trojan first documented in early 2023 by security researchers at JASK, classified as a botnet-driven ad fraud malware family. It is operated by an unknown threat group, possibly linked to Russian-speaking cybercriminal forums, and focuses on simulating humanlike interactions with online advertisements to generate illegitimate revenue.
Unidentified 025 (Clickfraud) propagates via malvertising campaigns and exploit kits exploiting CVE-2023-36025 (Windows Mark of the Web bypass) to drop its payload. It uses a modular architecture: a loader injects a core DLL that establishes persistence via a scheduled task named "AdobeUpdater" and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware employs DNS-over-HTTPS (DoH) for C2 communication to evade detection, querying domains such as "clickfarm-api[.]top" and "adstats[.]pw". It implements anti-analysis checks including VM detection via WMI queries and sandbox evasion using Sleep-skewing (e.g., NtDelayExecution delays with random jitter). The click-fraud engine uses headless Chromium instances rotated through proxies scraped from public lists, mimicking mouse movements and viewport gestures to bypass fraud filters.
First identified in January 2023 after a surge in unusual ad traffic on major ad exchanges, Unidentified 025 (Clickfraud) was linked to a campaign targeting programmatic advertising platforms, causing an estimated $2.8 million in fraudulent ad impressions over three months. No CVEs are directly attributed to the malware itself, but it exploits the aforementioned CVE-2023-36025. No law enforcement actions have been reported as of mid-2024, though a JASK report (May 2023) detailed its infrastructure and recommended blocking the C2 domains.
Known SHA256 hashes include e5c3e9f7a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7 (loader variant) and 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f (core DLL). Behavioral signatures include high-frequency DNS queries to "*.clickfarm-api[.]top" every 30 seconds, persistent User-Agent strings "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36", and creation of registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunAdobeUpdater". The mutex name "GlobalClickFarmMutex_025" is also observed on infected hosts.
The primary damage is financial fraud through stolen ad revenue, draining advertiser budgets and undermining programmatic ad trust. Affected sectors include digital advertising networks, publishers, and e-commerce platforms; no data exfiltration or system encryption has been documented. The malware degrades system performance due to constant browser process spawning and proxy usage.
Defenders should block the C2 domains and implement YARA rules detecting the mutex and registry run key. Apply patches for CVE-2023-36025, deploy endpoint detection rules for headless Chromium instances, and monitor for anomalous DNS-over-HTTPS traffic using SIEM correlation rules.
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.