Stantinko
- First seen
- 2012-05-01 00:00:00
- Malware type
- trojan, botnet
- Family
- Malware family
- Profile updated
- 2026-07-07 12:59:24
Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications
Targeted regions: country_code:ru country_code:ua
Context
Stantinko is a sophisticated malware family that primarily conducts click fraud and various forms of adware distribution. Active since 2012, it is known for its ability to perform unauthorized advertising clicks and proxy services while targeting Russia and Ukraine.
Reports & references
- intezer.com — Top Linux Cloud Threats Of 2020 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Stantinko (report)
- ESET — Stantinko Massive Adware Campaign Operating Covertly Since 2012 (report)
- ESET — Stadeo Deobfuscating Stantinko And More (report)
- ESET — Stantinko Botnet Adds Cryptomining Criminal Activities (report)
- ESET — Stantinko New Cryptominer Unique Obfuscation Techniques (report)
- intezer.com — Stantinkos Proxy After Your Apache Server (report)