RexPush is a Russia-linked push advertising and traffic distribution ecosystem associated with malicious adtech operations. It has been identified as one of several Russia-based push monetization programs connected to the broader VexTrio and Help TDS ecosystem, alongside entities such as Partners House, BroPush, and RichAds. The operation specializes in monetizing web traffic through push advertising and affiliate-driven signups, particularly for scams and online dating schemes. RexPush has been associated with deceptive social-engineering techniques that trick users into enabling browser notifications, including adult-themed lures, robot CAPTCHA-style prompts, and fake CAPTCHA workflows. Once users subscribe, the infrastructure can be used to deliver persistent scam content and other malicious advertising. Reporting also places RexPush within an interconnected cluster of commercial adtech and TDS operators that share infrastructure, artifacts, and operational patterns with systems used to route phishing, malware, and scam traffic at scale. The actor is part of a broader criminal adtech environment with a strong Russian nexus and apparent overlap with organized cybercrime. High-confidence reporting supports RexPush’s role in malicious push monetization and deceptive notification-based traffic acquisition, but does not independently establish it as a distinct nation-state actor. Its dominant activity is consistent with financially motivated cybercrime rather than espionage or influence operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RexPush is a Russia-based push monetization program involved in affiliate-driven online dating scams and push notification abuse.
RexPush operates a push advertising affiliate network using adult-themed and robot CAPTCHA lures to subscribe users to malicious push notifications, which are then used for scams and potentially malware delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.