VexTrio, also known as VexTrio Viper, is a long-running financially motivated cybercriminal traffic-distribution-system (TDS) and malicious advertising-technology operation active since at least 2015. It brokers traffic from compromised websites—particularly WordPress sites—and other deceptive web sources to downstream scams, phishing, fake software updates, exploit kits, malware delivery chains, and fraudulent offers. Its principal scam ecosystem has included scareware, dating fraud, cryptocurrency scams, and deceptive VPN, ad-blocking, and system-optimizer applications. VexTrio uses traffic filtering based on geography, device attributes, and technical characteristics, including mechanisms intended to exclude security products and sandbox environments. It has used malicious JavaScript injections, DNS-based redirect infrastructure, smartlinks, and deceptive CAPTCHA lures that induce victims to grant browser push-notification permissions. These notifications can persist after a victim leaves the originating site and are used to deliver additional scam or malware content. The operation has also supplied traffic to other cybercrime operations, including SocGholish and ClearFake. The VexTrio ecosystem is associated with commercial-looking affiliate and adtech entities including Los Pollos, TacoLoco, Adtrafico, AdsPro/Aimed Global, and Teknology SA, as well as the Tekka Group corporate network. Investigations have identified extensive use of front companies, affiliate programs, rapidly changing domain infrastructure, and commercial adtech services to obscure the operation and scale traffic monetization. The operation has been linked to Help TDS and Disposable TDS, with reported infrastructure and operational connections to Russia and Belarus and a corporate presence spanning Switzerland and Central and Eastern Europe. VexTrio has been associated with more than 60 affiliates and tens of thousands of malicious domains.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Affiliate cybercrime traffic broker and traffic-distribution operation mentioned solely as context for other EtherHiding monetization models; the reference explicitly excludes an affiliation with HexMage.
Operates/controls a traffic distribution service ecosystem used to distribute scams and malware via compromised sites (WordPress referenced).
Operates large-scale traffic distribution system (TDS) infrastructure, with at least 100,000 domains identified globally and used in bulk domain-based operations.
Referenced as a comparable malvertising network to Vane Viper; no additional operational details provided in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.