newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: How Vextrio and Affiliates run a global fraud network
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > How Vextrio and Affiliates run a global fraud network
Technology

How Vextrio and Affiliates run a global fraud network

June 12, 2025 5 Min Read
Share
How Vextrio and Affiliates run a global fraud network
SHARE

The threat actors behind the Vextrio Viper Traffic Distribution Service (TDS) are linked to other TDS services, such as Help TD and disposable TDS, indicating that sophisticated cybercrime operations are their own vast enterprises designed to distribute malicious content.

“Vextrio is a group of malicious Adtech companies that distribute fraud and harmful software through a variety of advertising formats, including SmartLinks and Push Notifications,” Infoblox said in a deep dive report that it shares with Hacker News.

Malicious Adtech companies under Vextrio Viper include Los Pollos, Taco Loco and Adtrafico. These companies operate what is known as commercial affiliate networks where users land and connect malware parties that connect websites illuminated by “advertising affiliates” with so-called “advertising affiliates” that provide various forms of illegal schemes, such as gift card fraud, malicious apps, phishing sites, and scams.

Put another way, these malicious traffic delivery systems are designed to redirect victims to their destinations through SmartLink or direct offers. According to DNS threat intelligence firm, Los Pollos involves malware distributors (aka affiliates) in their promise of high-paying offers, but Taco Loco specializes in pushnetization and is recruiting advertising affiliates.

Another notable element of these attacks is the compromise of WordPress websites injecting malicious code responsible for starting the redirect chain, which ultimately leads visitors to the Vextrio Scam Infrastructure. Examples of such injections include Balada, Dollyway, Sign1, and DNS TXT Records campaigns.

“These scripts redirect site visitors to various scam pages. The traffic broker network associated with Vextrio is one of the largest known cybercrime affiliate networks that leverage sophisticated DNS technologies, traffic distribution systems and domain generation algorithms to provide malware and fraud.

See also  Moving from monitoring alerts to measuring risk

Vextrio’s operations were hit around mid-November 2024 after Qurium revealed that Swiss and Czech Adtech Company Los Pollos is part of Vextrio. This has caused escapes, and now moves threat actors who rely heavily on the LOS Pollos network to alternative redirect destinations such as Help TDs and disposable TDs.

Changes in behavior over time from two independent C2 sets

An analysis of InfoBlox of 4.5 million DNS TXT record responses from compromised websites over six months revealed that domains that were part of the DNS TXT record campaign could be categorized into two sets, each with their own command and control (C2) servers.

“Both servers were hosted on infrastructure connected to Russia, but neither the hosting nor the TXT response was duplicated,” the company said. “Each set maintained a different redirect URL structure despite both being originally led by Vextrio and subsequently leading to HELT TDS.”

Further evidence has emerged that both the TDS and disposable TDs are identical, supporting the service enjoying an “exclusive relationship” with Vextrio until November 2024. HELTTDS has moved to Monetizer, a monetization platform where TDS, historically redirected to the Vextrio domain, uses TDS to connect to publisher affiliates.

“Help TDS has a strong Russian nexus, and hosting and domain registration is frequently done through Russian entities,” Infoblox said, describing the operator as perhaps independent. “There is no full-scale functionality of the Vextrio TDSS, and there is no obvious commercial connection beyond the creepy connection with Vextrio.”

Vextrio is one of many TDSs that have been out as a commercial ad tech company, others being Partner House, Blopsh, Richad, adm sin, and rexpush. Many of these are directed towards push notification services using Google Firebase Cloud Messaging (FCM). Alternatively, push an API-based custom development script to distribute links to malicious content via push notifications.

“Every year, hundreds of thousands of compromised websites around the world redirect victims to the intertwined web of vextrio and TDSS protecting vextrio,” the company said.

See also  How good is Real Research's AI agent? In the deep search bench report

“Vextrio and other affiliate ad companies know who the malware actors are, or at least have enough information to track them. Many companies are registered in countries that require a certain amount of “know your customers” (KYC), but even without these requirements, public affiliates are reviewed by customer managers. ”

Share This Article
Facebook Twitter Copy Link
Previous Article Khamzat Chimaev Mocks Dricus du Plessis and his team will be on social media as Bad Blood continues ahead of the UFC 319 showdown Khamzat Chimaev Mocks Dricus du Plessis and his team will be on social media as Bad Blood continues ahead of the UFC 319 showdown
Next Article Why LLMS is thinking too much about simple puzzles, but give up on hard puzzles Why LLMS is thinking too much about simple puzzles, but give up on hard puzzles
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

Chaos Rat Malware Targets Window and Linux via fake network tools download
Technology

Chaos Rat Malware Targets Window and Linux via fake network tools download

5 Min Read
Increased Gibride AI Images: Privacy Concerns and Data Risks
Technology

Increased Gibride AI Images: Privacy Concerns and Data Risks

10 Min Read
Malicious browser extensions will infect 722 users across Latin America since early 2025
Technology

Malicious browser extensions will infect 722 users across Latin America since early 2025

5 Min Read
Why traditional DLP solutions fail in the browser era
Technology

Why traditional DLP solutions fail in the browser era

4 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?