Help TDS, also referred to as Disposable TDS, is a malicious traffic distribution service closely intertwined with the VexTrio cybercriminal ecosystem since at least 2017. It functions as redirection infrastructure that brokers web traffic from compromised websites and malware-driven campaigns to downstream scam, phishing, malware, and push-notification monetization flows. Security reporting has identified it as effectively the same service as Disposable TDS and as part of a broader cluster of commercialized malicious adtech and TDS operators with strong Russian infrastructure ties. Help TDS became especially prominent after disruption to VexTrio-linked monetization operations in November 2024, when multiple malware and website-compromise campaigns rapidly shifted their traffic from VexTrio to Help TDS. Campaigns associated with compromised WordPress sites and malware families such as DollyWay, Balada, and Sign1 have been observed using this redirection layer. The surrounding ecosystem uses DNS-based command-and-control mechanisms, server-side redirects, domain generation techniques, fake CAPTCHA lures, and browser push-notification abuse to route victims toward scams and malware delivery chains. Available reporting indicates that Help TDS shares code, scripts, images, and operational artifacts with VexTrio and related services, suggesting common development, shared operators, or a tightly integrated partnership rather than an independent platform. It has also been linked with other Russia-connected TDS and push-monetization operators including Partners House, BroPush, RichAds, and RexPush. After the November 2024 disruption, Help TDS was observed redirecting traffic onward to Monetizer, another monetization platform using TDS technology. Help TDS is best characterized as criminal enablement infrastructure rather than a conventional intrusion set: it supports large-scale malicious advertising, scam delivery, malware distribution, and abusive push-notification campaigns by monetizing traffic acquired through compromised websites and deceptive user-interaction lures. The dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Help TDS is a traffic distribution service closely linked to VexTrio, used to redirect web traffic to malicious destinations. It has a strong Russian nexus and has operated in an exclusive relationship with VexTrio until late 2024.
Help TDS is a traffic distribution system that took over much of the malicious traffic previously routed through VexTrio, distributing it to various scams and malware campaigns.
Help TDS is a traffic distribution system that has operated since at least 2017, closely linked to VexTrio. It is used by website malware actors to redirect victims to scams and malicious content, often via fake CAPTCHAs and push notification abuse. It shares code, infrastructure, and lure images with VexTrio and other TDSs.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.