VexTrio Viper is a long-running cybercriminal traffic distribution system (TDS) and malicious adtech ecosystem active since at least early 2020, with reporting indicating broader operations spanning nearly a decade. It operates one of the largest known affiliate-driven criminal traffic brokerage programs, routing compromised or fraudulently acquired web traffic to dozens of downstream partners for scams, phishing, malware delivery, fake applications, gambling, dating fraud, and other harmful content. Known associated entities include Los Pollos, a malicious advertising technology operation described as operating under the VexTrio Viper umbrella, and affiliates such as GoRefresh. Reporting also links the ecosystem to affiliates including SocGholish and ClearFake. A defining feature of VexTrio Viper is large-scale web traffic monetization through redirection chains, device and geolocation profiling, and push-notification abuse. The actor has been observed redirecting victims through multi-stage TDS infrastructure, often using fake CAPTCHA-style prompts to induce users to enable browser push notifications. Those notifications are then used to drive persistent scam traffic, including scareware, fake giveaways, fraudulent surveys, fake dating sites, fake applications, adware, disinformation, and occasional malware delivery. The infrastructure tailors payloads to the victim environment and can chain through multiple TDS layers to evade detection and maximize affiliate revenue. VexTrio Viper has also been tied to malicious mobile applications published through official Apple and Google app storefronts while masquerading as legitimate utility software. In addition, the actor has used compromised websites and hijacked domains to feed its TDS infrastructure. Since early 2020, VexTrio Viper has been observed exploiting the Sitting Ducks domain-hijacking technique to take over registered domains through weaknesses in DNS and hosting workflows, allowing the actor to repurpose legitimate domains for redirection, phishing, scams, and malware-related activity while benefiting from the trust and reputation of those domains. The ecosystem is notable for its scale, resilience, and service-based criminal model. It functions as a central broker of malicious traffic for a broad affiliate network rather than a single-purpose malware crew. Its operations emphasize initial victim acquisition, traffic filtering, redirection, scam delivery, and defense evasion through layered infrastructure and profiling. Available evidence supports a primarily financially motivated actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Umbrella ecosystem associated with malicious advertising/traffic distribution operations; includes Los Pollos as a component entity referenced in the content.
Developed and published fake mobile apps masquerading as VPNs, monitoring tools, RAM cleaners, dating services, and spam blockers in official app stores to conduct ad fraud, subscription scams, and personal data collection.
Referenced as another threat actor that adopts registered domain generation algorithm (RDGA) techniques for domain provisioning; no additional campaign details provided in the content.
Mentioned only as background comparison for another long-running malicious network using DNS and cloaking techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.