Vacant Viper is a cybercriminal threat actor associated with the 404TDS traffic distribution system and known for large-scale exploitation of the Sitting Ducks domain-hijacking technique since at least December 2019. The actor has been assessed as part of a broader Russian-nexus cybercriminal ecosystem and has reportedly hijacked thousands of domains over multiple years to support malicious infrastructure. Vacant Viper uses hijacked domains to augment 404TDS operations, route malicious traffic, conduct spam campaigns, establish command-and-control infrastructure for remote access trojans, and deliver malware including AsyncRAT and DarkGate. Reporting also links 404TDS activity to delivery of IcedID and other malware. The actor has been described as targeting high-reputation hijacked domains to reduce blocking and improve delivery success. Operationally, Vacant Viper is notable for abusing stolen or hijacked domains rather than relying solely on newly registered infrastructure. Its use of Sitting Ducks enabled domain takeover without compromising the legitimate owner’s registrar account, allowing the actor to repurpose trusted domains for malware delivery, redirection, and other post-compromise infrastructure functions. Vacant Viper has also been linked to malicious spam operations and to infrastructure used for RAT command-and-control. Known aliases are limited to Vacant Viper. The actor has been noted as affiliated with TA571 in reporting on malware delivery ecosystems. Overall, Vacant Viper is best characterized as a financially motivated cybercriminal operator specializing in traffic distribution, malware delivery, and abuse of hijacked domain infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Vacant Viper hijacks domain names and uses a custom traffic distribution system (404TDS) to deliver various remote access trojans (RATs).
Vacant Viper hijacks high-reputation domains using Sitting Ducks attacks to build a malicious traffic distribution system (404TDS) for spam, malware delivery, and C2 infrastructure.
Vacant Viper is a criminal group involved in DNS hijacking attacks, using compromised domains to distribute malware such as AsyncRAT and DarkGate.
Vacant Viper leverages Sitting Ducks domain hijacking to operate traffic distribution systems (TDS), run spam campaigns, deliver adult content, establish C2 infrastructure, and distribute malware including DarkGate and AsyncRAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.