Product
Keitaro
- First Reported
- May 21, 2026
- Latest Reported
- Sep 15, 2026
Reported Context (3)
- Every domain in the Canadian operation sits behind Keitaro, a commercial traffic distribution system (TDS). Silent Push Tracks a Large Phishing Operation Using Fast-Flux Infrastructure
- That is the distinction we did not draw clearly enough when this post first went out. Keitaro is a commercial traffic distribution system. Its presence on a network tells you the software is there. It does not tell you Hunt.io Maps 3,923 Potentially Malicious Infrastructure Endpoints Across Eastern Europe
- Many of the detections here are Threat Activity Enablers, tools like Tactical RMM, Keitaro, Gophish, Acunetix, Cobalt Strike and Sliver. Each one has legitimate, unwanted, and malicious use cases, and the balance Hunt.io Report Maps 1,357 C2 Servers Across 98 Middle Eastern Providers
CVE (5)
Malware (27)
People (4)
Threat Actors (18)
MITRE ATT&CK (17)
Vendors (47)
Products (18)
Tools (12)
Industries (13)
Countries (28)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.