Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

VexTrio TDS Uses Adtech To Spread Malware

June 13, 2025
Reading Time: 2 mins read
in Alerts
VexTrio TDS Uses Adtech To Spread Malware

The threat actors behind the VexTrio Viper Traffic Distribution Service (TDS) have now been linked to other TDS services. These include Help TDS and Disposable TDS, indicating a sprawling enterprise designed to distribute a wide range of malicious online content. Infoblox has stated that VexTrio is a group of malicious adtech companies that distribute scams and harmful software via different advertising formats. Some of the malicious adtech companies under VexTrio Viper include Los Pollos, Taco Loco, and also the company known as Adtrafico. These companies operate a commercial affiliate network that connects malware actors with so-called “advertising affiliates” who offer various illicit schemes.

A notable component of these attacks is the compromise of many WordPress websites to inject malicious code that initiates the redirection chain.

These specific scripts redirect site visitors to various scam pages through the traffic broker networks that are associated with VexTrio. “These scripts redirect site visitors to various scam pages through traffic broker networks associated with VexTrio,” GoDaddy noted in a recent report. VexTrio’s operations suffered a significant blow around mid-November 2024 after a report revealed that Los Pollos was part of VexTrio. This exposure then caused Los Pollos to cease their push link monetization, which triggered an exodus of many different threat actors.

Infoblox’s analysis of 4.5 million DNS TXT record responses has revealed that the domains could be classified into two distinct sets.

Each of these sets maintained different redirect URL structures, even though they both originally led to VexTrio and subsequently to Help TDS. Further evidence has now uncovered that both Help TDS and Disposable TDS are actually one and the same service. They enjoyed an “exclusive relationship” with VexTrio until November 2024, when Help TDS then shifted its traffic to Monetizer. The Help TDS has a strong Russian nexus, with hosting and domain registration frequently done via various different Russian entities.

VexTrio is one among the many TDSs that have been outed as commercial adtech firms, with others being Partners House and RichAds. Many of these are geared towards push notification services by making use of Google Firebase Cloud Messaging or other custom-developed scripts. Hundreds of thousands of compromised websites around the world every year redirect victims to the tangled web of VexTrio. VexTrio and the other affiliate advertising companies know who the malware actors are, or they have enough information to track them. Many of these companies are registered in countries that require some degree of ‘know your customer’ or KYC compliance for their operations.

Reference:

  • VexTrio’s Vast Adtech Network Distributes Malware And Scams Globally
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityFIN6June 2025More Eggs
ADVERTISEMENT

Related Posts

BEARDSHELL and COVENANT Malware Uncovered

BEARDSHELL and COVENANT Malware Uncovered

June 24, 2025
New Malware Skims WordPress E-commerce Sites

New Malware Skims WordPress E-commerce Sites

June 24, 2025
Chinese Hackers Build Router Spy Network

Chinese Hackers Build Router Spy Network

June 24, 2025
Stealth Malware Targets Fortinet Firewalls

Spyware in App Stores Steals Your Photos

June 23, 2025
Stealth Malware Targets Fortinet Firewalls

Prometei Botnet Attacks Servers for Crypto

June 23, 2025
Stealth Malware Targets Fortinet Firewalls

Stealth Malware Targets Fortinet Firewalls

June 23, 2025

Latest Alerts

Chinese Hackers Build Router Spy Network

New Malware Skims WordPress E-commerce Sites

BEARDSHELL and COVENANT Malware Uncovered

Prometei Botnet Attacks Servers for Crypto

Spyware in App Stores Steals Your Photos

Stealth Malware Targets Fortinet Firewalls

Subscribe to our newsletter

    Latest Incidents

    Hacken Token Crashes 99 Percent After Hack

    Paraguayan Government Hit By Cyberattack

    Hackers Leak Saudi Games Athlete Data

    Aflac Hacked in Spree on Insurance Firms

    CoinMarketCap Doodle Hack Steals Crypto

    UK’s Oxford Council Legacy Systems Breached

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial