All Vendors
advertising

Exoclick

Exoclick is an advertising platform with a VRS of 80, combining Oracle (25), extreme Broker (90), and maximum Counselor (100) threats. The platform deploys defeat devices, behavioral biometrics, session recording, consent bypass, and fingerprinting to deliver targeted advertising across adult and mainstream inventory.

40 IOCs25 detections4% pre-consent24 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Exoclick discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

25 detections across 24 sites4% pre-consent activity
MEDIUM

Pre-Consent Activity

Exoclick was observed loading and executing before user consent was obtained on 4% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Unknown

Observed Behavior

Requires claims extraction via CDT

Customer Impact

What This Means For You

Marketing teams using Exoclick face catastrophic risk exposure: (1) Reputational damage if association with adult content inventory becomes public, (2) Data breach liability as session recordings and behavioral profiles create high-value PII targets, (3) Regulatory exposure from consent bypass and special category data processing creating maximum GDPR fines. The platform's aggressive tracking creates ongoing legal liability that far exceeds any advertising performance benefit.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Exoclick

  • Immediately audit all ad network integrations to identify Exoclick deployment
  • If discovered, execute emergency tag removal and data deletion request under GDPR Article 17
  • Conduct legal review of association risk and potential regulatory notification requirements
  • Implement ad network approval process requiring privacy and reputational risk assessment

If You're Evaluating Exoclick

  • Consider whether reputational risk of adult content association justifies any use case
  • Evaluate retargeting alternatives with mainstream-only inventory and privacy-first architectures
  • Assess whether behavioral targeting performance justifies extreme GDPR liability
  • Request executive stakeholder review before any future deployment given reputational risk

Negotiation Leverage

  • Exoclick VRS 80 = Broker (90) + Counselor (100) threat. Adult content association creates reputational risk that likely violates acceptable use policies.
  • Session recording (BTI-C07) on adult sites = extreme PII exposure. Regulatory investigation would focus discovery on this data processing.
  • Consent bypass (BTI-C09) = systematic GDPR violation demonstrating willful non-compliance. No technical remediation exists; platform architecture is non-compliant.
  • Behavioral profiles from adult browsing used for mainstream targeting = cross-context tracking violating user privacy expectations.
  • Ask: What is your data breach notification history? How is session recording data secured? What is the legal basis for special category data processing? Expect no satisfactory answers.
  • Recommendation: Contract termination. No amount of performance justifies the reputational and regulatory risk profile.
Runtime Detections

Runtime Detections

5 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

Impact: Tag-level deception allows Exoclick to present different tracking behavior based on detection of privacy tools, defeating consent management and creating regulatory exposure.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Mouse movements, keystroke patterns, and scroll behavior captured across adult content sites creates sensitive personal data profiles that enable invasive cross-site tracking.

BTI-C07Session Recording

Full session replay

Impact: Full session capture including page interactions and form inputs on adult sites creates extreme PII exposure and reputational risk if data breach occurs.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Tracking continues after consent rejection, creating per-violation GDPR fines and demonstrating systematic disregard for user privacy rights.

BTI-C10Fingerprinting

Device identification

Impact: Device fingerprinting creates persistent identifiers that track users across adult and mainstream sites, creating cross-context tracking that users cannot detect or control.

IOC Manifest

IOC Manifest

35 INDICATORS

Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.exoclick.com/ads.js*
Tracking script
TRACK
*www.exoclick.com/wp-content/themes/exoclick/js/dist/scripts.js*
Tracking script
TRACK
*www.exoclick.com/wp-includes/js/wp-emoji-release.js*
Tracking script
TRACK
www.exoclick.com/ads.js
Auto-extracted from scan
TRACK
www.exoclick.com/wp-content/themes/exoclick/js/dist/scripts.min.js
Auto-extracted from scan
TRACK
www.exoclick.com/wp-includes/js/wp-emoji-release.min.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Exoclick operates within the adult advertising ecosystem alongside TrafficJunky, JuicyAds, and mainstream retargeting platforms. Behavioral profiles are likely shared across the ad network to improve targeting accuracy, meaning user interactions on adult sites inform targeting on mainstream inventory. Integration with retargeting platforms creates data flow from adult browsing to mainstream campaign optimization.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

40 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details