Vane Viper, also known as Omnatuor, is a cybercrime threat actor associated with malicious advertising technology, traffic distribution, malvertising, and ad-fraud operations. The actor has been assessed as operating for at least a decade and functions as infrastructure and traffic brokerage for broader cybercriminal activity, including malware delivery, phishing enablement, scam monetization, and deceptive advertising campaigns. Reporting has linked Vane Viper to large-scale abuse of compromised websites, especially vulnerable WordPress sites, to build extensive redirector and distribution networks with rapid domain churn. Vane Viper has been tied to campaigns that distribute spyware, adware, riskware, and commodity malware including LummaStealer, and has also been associated with fake CAPTCHA and ClickFix-style social engineering flows. A notable technique is systematic abuse of browser push-notification permissions: victims are tricked into allowing notifications, after which service-worker-based persistence enables continued delivery of deceptive prompts, scareware, fraudulent ads, and redirects even after the original page is closed. The actor has also been linked to malicious ads and compromised web properties that redirect users toward malware, exploit-kit-style destinations, fake applications, survey scams, fraudulent shopping content, and other monetized scam pages. Vane Viper appears to operate primarily as an enabler within the cybercrime ecosystem, brokering traffic for malware droppers and phishers while potentially conducting its own campaigns. Activity attributed to the actor includes the DeceptionAds malvertising operation, which used fake verification pages to deliver LummaStealer at scale. The actor’s infrastructure has been described as extensive, with tens of thousands of domains, heavy DNS volume, and frequent bulk registrations designed to support resilience and evade disruption. High-confidence reporting also notes opaque corporate structures and shell-company usage intended to obscure ownership and accountability. Infrastructure and personnel ties have been reported with commercial adtech and hosting-related entities, as well as overlap with infrastructure linked to Russian influence-operation ecosystems, but the actor is principally characterized as a financially motivated cybercrime operation rather than a state-sponsored espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Systematic push notification abuse to serve ads and facilitate ClickFix-style social engineering campaigns.
Provides malicious adtech infrastructure supporting malvertising, ad fraud, and broader threat proliferation at scale (DNS-heavy infrastructure).
Vane Viper is a long-running cybercrime operation leveraging compromised websites and malvertising to distribute malware and exploit kits, with infrastructure linked to Russian diaspora in Europe and Cyprus.
Operates as (and behind) a malicious adtech/traffic distribution system enabling large-scale malvertising and ad fraud, brokering traffic for malware droppers and phishing, and sometimes running its own campaigns. Uses compromised WordPress sites and large volumes of short-lived domains to redirect victims to scams, malicious extensions, and malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.