RichAds is a Russia-based push advertising and monetization program linked by security researchers to the broader malicious adtech and traffic distribution ecosystem surrounding VexTrio and related services such as Help TDS, Partners House, BroPush, and RexPush. It operates commercial-style advertising channels including push advertising, pop ads, native ads, and Telegram Mini Apps, while sharing infrastructure, artifacts, and operational characteristics with traffic distribution systems used to route victims toward scams, phishing, malware, and deceptive subscription flows. RichAds has been associated with an ecosystem that abuses compromised websites, server-side redirects, DNS-based command-and-control mechanisms, and fake CAPTCHA lures to trick users into enabling browser push notifications. Those notifications are then used for persistent scam delivery and other malicious monetization. Researchers have also linked this ecosystem to affiliate-driven schemes focused heavily on online dating signups and related fraud. Shared code, lure material, and infrastructure with other Russian-linked push monetization programs indicate either a common developer pool, shared lineage, or close operational partnership. RichAds is best understood not as an isolated malware family but as part of a commercialized adtech layer that enables cybercriminal traffic brokering at scale. The surrounding ecosystem has been tied to large volumes of malicious redirects from compromised websites and has been assessed as part of a broader Russian nexus in malicious advertising technology and organized cybercrime. High-confidence reporting supports RichAds’ role in push-based malicious traffic monetization and scam enablement, but does not by itself establish RichAds as a distinct nation-state intrusion group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RichAds is a Russia-based push monetization program that pays affiliates to drive traffic to online dating scams and other deceptive schemes via push notifications.
RichAds is a commercial adtech firm specializing in push advertising, pop ads, and native ads, and is part of the ecosystem that shares code and infrastructure with VexTrio and other TDSs. It is involved in distributing malicious content via push notifications and other ad formats.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.